SHINDO2

CINRA JOB

Unauthorized accessSize not disclosed

POSSIBLE LEAKSalary / Date of birthContained

Open in the live monitor ▶
Disclosed
Aug 27, 2026
Detected
Aug 18, 2026
Detection to disclosure
9 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactAddress, Phone number, Email address
Employment & HREducation and work history, Desired salary
Account dataQualifications
Transactions & activityApplication history
Communications & contentMotivation statements and self-promotion texts

Not leaked

  • Credit card information is not affected (per the article)

Who is affected

  • Members
  • Former members

Cause

Credentials kept on a cloud service were obtained and misused by a third party; they gave access to the member database and its backups

Timeline

  1. Detected
  2. First disclosure

Response

  • Revoked credentials
  • Access review
  • Patched

Revoked the credentials, removed related permissions and fixed the root cause

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources