SHINDO4
CMIC Healthcare Institute Co., Ltd.
Personal data1,940people
LEAK CONFIRMEDHealth / medical / treatment / Phone numberUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Jul 24, 2026
- Detected
- Jul 11, 2026
- Detection to disclosure
- 13 days
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityPatient names, Age, Gender, Physician names
ContactPhone number, Prefecture of residence, Email address
Special-care dataName of the patient's regular medical institution
Employment & HRMedical institution names, Branch office names
How many
- Total (sum of the breakdown) 1,940 people
- Medical professionals and physicians 1,535 people
- Patients (email address only) 216 people
- Staff of contracting organizations 113 people
- Others 46 people
- Patients (name and other details) 30 people
Who is affected
- Patients
- Medical professionals and physicians
- Staff of contracting organizations
Cause
Files containing some personal information had been placed in the system's public web area and were accessed without authorization
Timeline
- Intrusion began
- Detected
- First disclosure
- Company issued an update
Response
- Blocked the entry point
- Revoked credentials
- Forensic investigation
- Access review
- More monitoring
Access blocked and credentials reset. Outside security investigation started. Review of access control, monitoring and information-handling procedures planned
What you should do
- Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Cybersecurity-jp.com News · Jul 27, 2026