SHINDO3

ApplyNow

Unauthorized accessSize not disclosed

POSSIBLE LEAKMy Number / Bank accountContained

Open in the live monitor ▶
Disclosed
Sep 9, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityApplicant names (kana)
ContactEmail address, Phone number
Account dataUser information of client-company staff
ID documentsMy Number (ApplyNow Sign)
Employment & HRBasic pension number (ApplyNow Sign)
Financial & paymentBank account information (ApplyNow Sign)

Who is affected

  • Applicants
  • Client-company staff

Cause

Unauthorized access exploiting a vulnerability in a data analytics tool

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. First disclosure

Response

  • Blocked the entry point
  • Patched

Blocked the unauthorized access and applied security patches; plans to review security management

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  4. Don't open links in emails from this company. The apology email itself may be fake
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Expect targeted phishing posing as HR or interview contacts
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources