SHINDO2

Alps Alpine Co., Ltd.

Unauthorized accessSize not disclosed

POSSIBLE LEAKFull name / Email addressInvestigating

Open in the live monitor ▶
Disclosed
Apr 27, 2026
Detected
Apr 3, 2026
Detection to disclosure
24 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

CredentialsLogin ID
IdentityName
ContactCompany email address
Employment & HRPosition, Department
Account dataSystem ID

Not leaked

  • Passwords (encrypted)
  • Credit card information
  • Bank account information
  • My Number

Who is affected

  • Officers and employees
  • Former employees
  • Contractor staff

Cause

Outsiders accessed the external VPN system; employee data stored for system authentication may have been viewed

Timeline

  1. Detected
  2. Server intrusion confirmed; internal system users' data may have been viewed
  3. First disclosure

Response

  • Service stopped
  • Config review
  • Forensic investigation
  • More monitoring
  • Governance / committee
  • Staff training

Stopped systems and reviewed security settings; outside technical investigation; stronger VPN monitoring; revised data-handling rules; staff training

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources