SHINDO1

OneOffice

Unauthorized accessSize not disclosed

POSSIBLE LEAKMember / user IDInvestigating

Open in the live monitor ▶
Disclosed
Dec 22, 2025
Detected
Dec 18, 2025
Detection to disclosure
4 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

Account dataAccount information

Who is affected

  • Users of the corporate email service

Cause

A zero-day attack exploiting CVE-2025-20393 in Cisco email security products (Cisco Secure Email Gateway and Cisco Secure Email and Web Manager) compromised spam quarantine servers and authentication (LDAP) servers

Timeline

  1. Suspected intrusion into SPAM Filtering servers
  2. Detected
  3. Date of the Security NEXT report

Response

  • Forensic investigation

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources