SHINDO5

Asahi Kasei Therapeutics

Personal data1,940people

LEAK CONFIRMEDHealth / medical / treatment / Phone numberMisconfiguration · Contained

Open in the live monitor ▶
Disclosed
Aug 21, 2026
Detected
Jul 11, 2026
Detection to disclosure
41 days
Leak
Leak confirmed
Type
Misconfiguration
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Age, Gender
ContactPrefecture of residence, Phone number, Email address
Special-care dataRegular medical institution
Employment & HRMedical institution name, Sales office name

How many

  • Patients, healthcare workers and contractor staff (total) 1,940 people
  • Healthcare workers 1,535 people
  • Patients (email addresses) 216 people
  • Patients (names etc.) 30 people
  • Contractor employees 159 people

Who is affected

  • Patients
  • Healthcare workers
  • Contractor employees

Cause

At contractor CHI's patient-support program system, files containing personal data sat in a web-accessible area and were accessed. Data handling and access-control practices were flawed and oversight was insufficient

Timeline

  1. Unauthorized access to the contractor's system
  2. Contractor found personal data involved
  3. First disclosure

Response

  • Access review
  • Notified individuals

Fixed the access-control flaws and contacted affected people

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Expect targeted phishing posing as HR or interview contacts
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources