SHINDO3

Corona

Customersup to35,000people

POSSIBLE LEAKPostal address / Full nameUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Aug 28, 2026
Detected
Aug 24, 2026
Detection to disclosure
4 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress
Communications & contentInstallation-related documents

How many

  • Customers up to 35,000 people

Who is affected

  • Customers

Cause

An external cloud service used to manage installation records was compromised by a third party

Timeline

  1. Listed as "Corona Corporation" on the Metaencryptor leak site (ransomware.live)
  2. Detected
  3. First disclosure

Response

  • Revoked credentials
  • Forensic investigation

Disabled and reset user accounts on the external cloud service; investigating cause, entry route and scope with outside help; reported to the PPC

What you should do

  1. Watch for unexpected mail or invoices; your address is hard to change
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources