SHINDO3

Tezukayama Gakuin University

Personal data~450people

POSSIBLE LEAKFull name / Email addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 12, 2025
Detected
Aug 2, 2025
Detection to disclosure
41 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactEmail address

How many

  • Current and former clinical psychology graduate students ~450 people

Who is affected

  • Current and former students

Cause

A public-facing web system was compromised and malicious files were placed on the server

Timeline

  1. Pointed out by an outside party
  2. Date of the Security NEXT report

Response

  • Service stopped
  • Forensic investigation
  • Notified individuals

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources