SHINDO4

CMIC Healthcare Institute Co., Ltd.

Personal data1,940people

LEAK CONFIRMEDHealth / medical / treatment / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 24, 2026
Detected
Jul 11, 2026
Detection to disclosure
13 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityPatient names, Age, Gender, Physician names
ContactPhone number, Prefecture of residence, Email address
Special-care dataName of the patient's regular medical institution
Employment & HRMedical institution names, Branch office names

How many

  • Total (sum of the breakdown) 1,940 people
  • Medical professionals and physicians 1,535 people
  • Patients (email address only) 216 people
  • Staff of contracting organizations 113 people
  • Others 46 people
  • Patients (name and other details) 30 people

Who is affected

  • Patients
  • Medical professionals and physicians
  • Staff of contracting organizations

Cause

Files containing some personal information had been placed in the system's public web area and were accessed without authorization

Timeline

  1. Intrusion began
  2. Detected
  3. First disclosure
  4. Company issued an update

Response

  • Blocked the entry point
  • Revoked credentials
  • Forensic investigation
  • Access review
  • More monitoring

Access blocked and credentials reset. Outside security investigation started. Review of access control, monitoring and information-handling procedures planned

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources