SHINDO4

Seiyu

Personal data30,508people

LEAK CONFIRMEDPassword / HR / labour recordsUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Nov 4, 2025
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
Employment & HRID, Employment category and attendance codes
Account dataHire date and work start date, Authority level
CredentialsInitial password

How many

  • Employees and former employees 30,508 people
  • Including date of birth 26,353 people
  • Including initial password 7 people

Who is affected

  • Employees
  • Former employees

Cause

Cyberattack on Blue Yonder in October 2024

Timeline

  1. Intrusion began
  2. Provisional count confirmed
  3. First disclosure

Response

  • Notified individuals
  • Vendor review
  • Governance / committee

Notification of and apology to affected people, demand that Blue Yonder strengthen security, system audits and review of vendor management

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources