SHINDO5

Sompo Japan

Financial & payment1,638recordsof ~9M records affected in total

POSSIBLE LEAKBank account / Postal addressUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Apr 25, 2025
Detected
Apr 21, 2025
Detection to disclosure
4 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth (sales agents)
ContactAddress, Phone number, Email address
Transactions & activityPolicy number, Accident (claim) number
Financial & paymentPremium payment account details (1,638 records)
Account dataSales agent ID

How many

  • Personal data records that were accessible ~9M records
  • Records with name, address, phone, email and policy number ~3.4M records
  • Records with name and policy number ~1.9M records
  • Records without name but with address, phone, email, policy or accident number ~1.2M records
  • Records with name only, address only, etc. ~830,000 records
  • Agency-related records ~1.8M records
  • Records with premium payment account details 1,638 records
  • Insurance sales agents' names, agent IDs, dates of birth, etc. 9,366 records

Who is affected

  • Customers (policy-related people)
  • Agencies and insurance sales agents

Cause

A web-based subsystem used to manage performance indicators was compromised by an outside party exploiting a vulnerability

Timeline

  1. Exposure began
  2. Exposure ended
  3. Detected
  4. First disclosure
  5. Company issued an update

Response

  • Forensic investigation

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources