SHINDO5

Aiful Corporation

Personal data946,056records

LEAK CONFIRMEDCredit / debt data / Contract detailsInsider misuse · Contained

Open in the live monitor ▶
Disclosed
Aug 19, 2026
Detected
Aug 19, 2026
Detection to disclosure
Same day
Leak
Leak confirmed
Type
Insider misuse
Status
Contained
Security spend
Not checked yet
Compensation
Not announced
Corporate number
3130001000082

What leaked

UnspecifiedPersonal identification information
Transactions & activityContract details
Financial & paymentRepayment status, Outstanding balance

How many

  • Customer records, duplicates removed 946,056 records
  • Personal data records provided to Life Card (total, with duplicates) 880,824 records
  • Credit-bureau records analysed 171,032 records

Who is affected

  • Aiful customers

Cause

Credit data from a designated credit bureau may only be used to check repayment ability, but it was used to pick insurance sales targets and passed to group company Life Card. The company cites poor understanding of the rules on credit data and weak checks on how data may be used

Timeline

  1. Credit data analysed for an unauthorized purpose
  2. End of the period of provision to Life Card
  3. Date of discovery not given in the article
  4. First disclosure

Response

  • Data deleted
  • Staff training
  • Access review
  • Governance / committee

Life Card stopped using the customer data and deleted it. Review of how credit data is used, staff training across the group, clearer approval steps for data purpose, provision and receipt, and tighter access rights to credit data

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources