SHINDO2

Tanabe City

Personal data19people

EXPOSEDPostal address / Phone numberMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Sep 4, 2025
Detected
Aug 4, 2025
Detection to disclosure
31 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Occupation
ContactAddress, Phone number, Email address
Employment & HRWorkplace
Communications & contentReason for participating

How many

  • Participants in a 2023 disability welfare event 19 people

Who is affected

  • Event participants

Cause

Staff forgot that personal data in the file could be displayed with certain operations and posted it on the city website without removing it

Timeline

  1. Exposure began
  2. Found after a resident's report
  3. Removed from the website
  4. Correction in search engines confirmed
  5. Date of the Security NEXT report

Response

  • Data deleted
  • Notified individuals

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources