SHINDO4

Bonform Online Store

ID documents3,268people

POSSIBLE LEAKCard security code / Card numberUnauthorized access · Closed (final report)

Open in the live monitor ▶
Disclosed
Jan 28, 2026
Detected
Jan 16, 2026
Detection to disclosure
12 days
Leak
Leak possible
Type
Unauthorized access
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentCardholder name, Card number, Expiry date, Security code
ContactEmail address (logged-in users), Phone number (logged-in users)
CredentialsPassword (logged-in users)

How many

  • Customers who paid by credit card between 25 March 2021 and 8 November 2024 3,268 people
  • Of these, customers who used the store while logged in 735 people

Who is affected

  • Online store customers

Cause

Unauthorized access exploiting a site vulnerability altered the payment page's JavaScript to steal data

Timeline

  1. Exposure began
  2. Exposure ended
  3. System compromise by a third party found; site suspended
  4. Service suspended
  5. Security NEXT report date
  6. Investigation results announced; Security NEXT report date

Response

  • Service stopped
  • Forensic investigation
  • Phishing warning

Suspended the site and commissioned an outside investigation; asked card users to check statements for unfamiliar charges

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Change this password and every account that reused it now. Switch to a passkey where offered
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources