SHINDO6

Suruga-ya

ID documents29,932people

LEAK CONFIRMEDCard numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Dec 5, 2025
Detected
Aug 4, 2025
Detection to disclosure
123 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentCredit card information
UnspecifiedPersonal data entered at checkout

How many

  • Customers who paid by credit card during the period 29,932 people

Who is affected

  • Customers who paid by credit card

Cause

Unauthorized access exploiting a vulnerability in a monitoring tool led to tampering of the JavaScript used on the payment page

Timeline

  1. Intrusion began
  2. Detected
  3. Credit card payments stopped
  4. Credit card payments stopped
  5. Security NEXT report date; the date of the first notice was not checked

Response

  • Forensic investigation
  • Service stopped

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources