SHINDO3

Chibagin Shoten

cbmnet.co.jp

Personal data~192people

POSSIBLE LEAKBank account / Postal addressUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Sep 17, 2026
Detected
Sep 3, 2026 13:00 JST
Detection to disclosure
14 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced
Corporate number
4040001118395

What leaked

IdentityFull name (including gift recipient names and cardholder names)
ContactAddress (including delivery addresses), Email address, Phone number
Account dataUser name
Financial & paymentBank account information (only about 31 customers who entered the 1,000 yen cashback campaign)
Transactions & activityApplication number (applicant)

Not leaked

  • Credit card information, passwords and similar information were not stored on the affected server
  • Credit card information, passwords and similar information were not stored on the affected server

How many

  • Individual customers (Chibagin Shoten notice) ~192 people
  • Corporate customers (Chibagin Shoten notice) ~722 organizations
  • Customers with an email address only ~7,670 people
  • Individual GIFT SELECTION applicants (Chiba Bank notice) ~722 people
  • Corporate GIFT SELECTION applicants (Chiba Bank notice) ~1,616 organizations

Who is affected

  • Individual customers
  • Corporate customers
  • GIFT SELECTION applicants
  • Gift recipients

Cause

A third party gained unauthorized access to the corporate website server, and online casino content appeared on the site. The cause is being investigated with an outside specialist firm

Timeline

  1. Detected
  2. First disclosure
  3. Parent company Chiba Bank announced the impact on GIFT SELECTION applicants

Response

  • Forensic investigation
  • Service stopped

Took the corporate website offline. Consulted the police and reported to the relevant authorities; checking the cause and scope with an outside specialist firm

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources