SHINDO4

Daito Gas

Personal data~124,000records

POSSIBLE LEAKPostal address / Phone numberRansomware · Investigating

Open in the live monitor ▶
Disclosed
Sep 28, 2026
Detected
Sep 24, 2026
Detection to disclosure
4 days
Leak
Leak possible
Type
Ransomware
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
3030001056382

What leaked

IdentityFull name
ContactAddress, Phone number
Account dataBilling number, customer number
Device & networkGas meter number
Transactions & activityGas consumption
Financial & paymentGas charges

Not leaked

  • Bank account information and credit card information are not included
  • Bank account information and credit card information are not included

How many

  • Customers who used Daito Gas between November 2023 and April 2024 ~124,000 records

Who is affected

  • Customers who used Daito Gas between November 2023 and April 2024

Cause

Unauthorized access to the internal network of Ryomo Systems, the system service provider Daito Gas uses to manage customer information. Files with customer information handled in past work had remained inside Ryomo Systems' internal network. Daito Gas's own customer information system is separate, and no unauthorized access to it has been found

Timeline

  1. Report received from Ryomo Systems
  2. First disclosure

Response

  • Phishing warning
  • Hotline

Confirming the facts with Ryomo Systems and working to prevent recurrence. Warning about suspicious calls pretending to be the company or its contractor. Contacts: Daito Gas customer call center (0120-121-362) and Ryomo Systems (0120-998-970)

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Data outlived the contract. Always get proof of deletion and set retention limits
  3. Offline backups with restore drills; segment the network
  4. Don't keep ID or bank data: delete after checks or use a KYC provider
  5. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  6. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources