SHINDO5

Skylark

ID documents2,270people

POSSIBLE LEAKCard security code / Card numberUnauthorized access · Closed (final report)

Open in the live monitor ▶
Disclosed
Jul 31, 2025
Detected
May 7, 2025
Detection to disclosure
85 days
Leak
Leak possible
Type
Unauthorized access
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth, Gender
ContactPhone number, Email address
Financial & paymentCard number, Expiry date, Security code

How many

  • Customers who registered a credit card during the exposure period 2,270 people

Who is affected

  • Takeout site customers

Cause

A vulnerability in the takeout site system was exploited; the outage was at first thought to be a programming error

Timeline

  1. Exposure began
  2. Outage occurred
  3. Detected
  4. Exposure ended
  5. Reported to authority
  6. Reported to authority
  7. Date of the Security NEXT report; the outage itself may have been announced in May

Response

  • Service stopped
  • Forensic investigation

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources