SHINDO4

Axcelead Drug Discovery Partners, Inc.

Personal data~7,000files

POSSIBLE LEAKMessages / email bodies / Trade secretsPhishing · Contained

Open in the live monitor ▶
Disclosed
Jul 22, 2026
Detected
May 22, 2026
Detection to disclosure
61 days
Leak
Leak possible
Type
Phishing
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

UnspecifiedPersonal data of officers, employees, customers and business partners
Business dataContract and business information
Communications & contentApprox. 7,000 emails

How many

  • Emails with traces of access ~7,000 files

Who is affected

  • Officers and employees of the company and group companies
  • Customers
  • Business partners

Cause

An employee entered credentials through a phishing email and a third party logged into the mailbox

Timeline

  1. An employee entered credentials via a phishing email
  2. Start of the unauthorized access window
  3. Intrusion stopped
  4. Unauthorized login by a third party confirmed
  5. First disclosure

Response

  • MFA
  • Staff training
  • More monitoring
  • New detection

Stronger email security, multi-factor authentication, staff training and monitoring

What you should do

  1. Expect targeted phishing posing as HR or interview contacts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources