SHINDO2

Eraberu e-GIFT

Unauthorized accessSize not disclosed

POSSIBLE LEAKFull name / Login ID / usernameInvestigating

Open in the live monitor ▶
Disclosed
Aug 26, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, or either the family or given name
Business dataCompany name
Account dataCompany ID
CredentialsLogin ID
ContactPart of the email address

Who is affected

  • Staff at contracting companies

Cause

A third party accessed the management system of the corporate digital gift service, and some customers' gifts were fraudulently redeemed

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Individuals notified
  4. First disclosure

Response

  • Notified individuals

Individual contact with affected people from 8/24. Damage reported to the police and a report filed with the PPC

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources