SHINDO4

Asoview Inc.

Total~14,000records

LEAK CONFIRMEDBank account / Postal addressAccount takeover · Contained

Open in the live monitor ▶
Disclosed
May 28, 2026
Detected
May 20, 2026
Detection to disclosure
8 days
Leak
Leak confirmed
Type
Account takeover
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

Business dataCompany name and store name
ContactAddress and billing address, Phone number, Email addresses
IdentityNames of representatives and billing contacts
Financial & paymentBank account information
Communications & contentInvoices and payment notices

How many

  • Total ~14,000 records
  • Partner accounts accessed without authorization 111 accounts
  • Other partner records ~14,400 records

Who is affected

  • Partner businesses using the booking-management system

Cause

Unauthorized logins by a third party using authentication credentials

Timeline

  1. Suspicious access detected
  2. Reported to the Personal Information Protection Commission
  3. Passwords reset between May 20 and 26
  4. Official announcement

Response

  • Password reset

Reset partner account passwords

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources