SHINDO2

01Bank

Customer companiesup to100organizations

LEAK CONFIRMEDEmail address / Member / user IDUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Aug 21, 2026
Detected
Aug 17, 2026
Detection to disclosure
4 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

Account dataCustomer identification data
ContactEmail address

Not leaked

  • Account numbers, balances, transaction history, login IDs, login passwords and one-time passwords (not listed among leaked items)

How many

  • Customer companies up to 100 organizations

Who is affected

  • Up to 100 companies

Cause

Third-party intrusion into the bank's systems (method not disclosed)

Timeline

  1. Detected
  2. First report
  3. Announced a confirmed leak and that the intrusion route had been blocked
  4. Intrusion route blocked (as of 8/27)

Response

  • Blocked the entry point
  • Forensic investigation

Blocked the intrusion route and continued investigating with outside experts. Consulted the police and reported to the relevant authorities

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources