SHINDO4

Yamagata University

ID documents313peopleof 2,637 people affected in total

POSSIBLE LEAKHealth / medical / treatment / Student ID cardPhishing · Investigating

Open in the live monitor ▶
Disclosed
May 27, 2025
Leak
Leak possible
Type
Phishing
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ID documentsStudent ID number
ContactEmail address, Phone number
Special-care dataHealth survey answers
Transactions & activityCounseling notes (password-protected)

How many

  • Students (sum of 2,306 + 313 + 12 + 6) 2,637 people
  • Names and student ID numbers 2,306 people
  • Student IDs, emails, dates of birth, phones, health survey answers, etc. 313 people

Who is affected

  • Students of Yamagata University's Faculty of Agriculture and graduate programs and of the Iwate University United Graduate School of Agricultural Sciences

Cause

A fake security warning appeared on a faculty member's PC and they were tricked into installing remote-access software (tech support scam). No money was lost

Timeline

  1. Intrusion began
  2. Date of the Security NEXT report

Response

  • Forensic investigation

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  4. Don't open links in emails from this company. The apology email itself may be fake
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources