SHINDO5
Aiful Corporation
Personal data946,056records
LEAK CONFIRMEDCredit / debt data / Contract detailsInsider misuse · Contained
Open in the live monitor ▶- Disclosed
- Aug 19, 2026
- Detected
- Aug 19, 2026
- Detection to disclosure
- Same day
- Leak
- Leak confirmed
- Type
- Insider misuse
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
- Corporate number
- 3130001000082
What leaked
UnspecifiedPersonal identification information
Transactions & activityContract details
Financial & paymentRepayment status, Outstanding balance
How many
- Customer records, duplicates removed 946,056 records
- Personal data records provided to Life Card (total, with duplicates) 880,824 records
- Credit-bureau records analysed 171,032 records
Who is affected
- Aiful customers
Cause
Credit data from a designated credit bureau may only be used to check repayment ability, but it was used to pick insurance sales targets and passed to group company Life Card. The company cites poor understanding of the rules on credit data and weak checks on how data may be used
Timeline
- Credit data analysed for an unauthorized purpose
- End of the period of provision to Life Card
- Date of discovery not given in the article
- First disclosure
Response
- Data deleted
- Staff training
- Access review
- Governance / committee
Life Card stopped using the customer data and deleted it. Review of how credit data is used, staff training across the group, clearer approval steps for data purpose, provision and receipt, and tighter access rights to credit data
What you should do
- Check the company's notice to see if you're affected
Lessons for companies
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Aug 19, 2026
- National Tax Agency Corporate Number Publication Site Registry