SHINDO3

Coop Ishikawa

Member records1,756records

POSSIBLE LEAKPostal address / Phone numberRansomware · Investigating

Open in the live monitor ▶
Disclosed
Apr 24, 2026
Detected
Apr 10, 2026
Detection to disclosure
14 days
Leak
Leak possible
Type
Ransomware
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName
ContactAddress, Phone number and other contact details
Transactions & activityGift order history and other transaction data

Not leaked

  • Bank account, credit card and My Number data are not held

How many

  • Member records 1,756 records
  • Recipient records 4,264 records

Who is affected

  • Co-op members
  • Gift recipients

Cause

The contractor's system was accessed from outside and infected with ransomware, encrypting server files

Timeline

  1. Detected
  2. Reported to authority
  3. First disclosure

Response

  • Notified individuals
  • Vendor review

Will notify individually after the investigation; requires the contractor to prevent recurrence

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Offline backups with restore drills; segment the network
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources