SHINDO5

2Rinkan

Personal dataup to3.5Mpeople

POSSIBLE LEAKPassword / Postal addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Apr 23, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth, Gender
ContactAddress, Phone number, Email address
Account dataMembership number, Point balance, App user ID, Vehicle information
CredentialsApp password

Not leaked

  • Credit card information (kept in a separate system)

How many

  • Point, mobile and app members (including former Driver Stand members) up to 3.5M people

Who is affected

  • Point, mobile and app members
  • Former Driver Stand members

Cause

Unauthorized access by a third party to the server holding member data

Timeline

  1. First report
  2. Second report (affected count published)

Response

  • Hotline
  • Phishing warning

Opened a dedicated hotline (May 1 to June 7, 2026). Urged users to change the password if reused elsewhere and to watch for suspicious messages posing as the company

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources