SHINDO2

CEC Co., Ltd.

RansomwareSize not disclosed

LEAK UNCLEARRecovering

Open in the live monitor ▶
Disclosed
Aug 2026
Leak
Unknown
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

Not leaked

  • The attacked area is separate from the systems and data held for customers

Cause

Ransomware attack (type and entry route identified but withheld for security reasons)

Timeline

  1. Disclosed by August 21 (per the article)
  2. Tokyo Second Data Center accessed without authorization

Response

  • Blocked the entry point
  • Forensic investigation
  • BCP review

Isolated the attacked area and blocked the entry route; restored services in alternate environments; recovering encrypted data and analyzing communication logs; third-party investigation

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources