SHINDO3

Activity Japan

activityjapan.com

MisconfigurationSize not disclosed

LEAK CONFIRMEDDate of birth / Postal addressContained

Open in the live monitor ▶
Disclosed
Jul 28, 2026
Detected
Jul 23, 2026
Detection to disclosure
5 days
Leak
Leak confirmed
Type
Misconfiguration
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactPhone number, Address, Email address
Transactions & activityBooking details, booking date, plan name, booking number, number of participants
Communications & contentMessage history with activity operators
Account dataMember profile

Who is affected

  • Member customers

Cause

A settings change to speed up the site made other customers' information visible to some users (not an attack)

Timeline

  1. After a settings change made to speed up the site
  2. Found through a customer inquiry
  3. Fixed the same day and the site put into maintenance mode
  4. First disclosure

Response

  • Service stopped
  • Config review

Settings corrected the same day and the site put into maintenance. Logins of affected accounts restricted until checked, then restored step by step

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Never sit on a known defect. Test every change before production
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources