SHINDO2

Flower Nagai Line

Personal data1accounts

LEAK CONFIRMEDPassword / MFA seed / recovery codePhishing · Contained

Open in the live monitor ▶
Disclosed
Mar 12, 2025
Leak
Leak confirmed
Type
Phishing
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmployee's email address (obtained over the phone)
CredentialsLogin ID, Password, One-time password

How many

  • Corporate internet banking account used for the fraudulent transfer 1 accounts

Who is affected

  • Company employee (entered credentials after the call and email)

Cause

An automated call claiming to be from Yamagata Bank said a contract update was needed. A person posing as a bank employee got the staff member's email address, sent a phishing email to a fake login page where the ID and password were entered, then obtained the one-time password by phone and made the transfer

Timeline

  1. Automated voice call received in the morning; fraudulent transfer the same day
  2. Reported to Yamagata Prefecture in the evening
  3. Loss revealed at the prefectural assembly

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources