SHINDO3

Digital Agency

Personal data150people

LEAK CONFIRMEDFull name / Login ID / usernameMisdelivery · Closed (final report)

Open in the live monitor ▶
Disclosed
Aug 7, 2026
Detected
Jul 6, 2026
Detection to disclosure
32 days
Leak
Leak confirmed
Type
Misdelivery
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
CredentialsUser ID
Employment & HRCodes indicating affiliation

How many

  • Staff of qualification-administering bodies 150 people

Who is affected

  • Staff of qualification-administering bodies

Cause

Because the work manual was ambiguous, staff mistakenly created a file (login history) that included users from other qualification bodies and sent it to other ministries

Timeline

  1. File sent to other ministries
  2. Found when the receiving ministry's staff got in touch
  3. First disclosure

Response

  • Change process
  • Data deleted

Stronger checking and a review of the work manual. The file was not forwarded to anyone else and has been deleted

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Never sit on a known defect. Test every change before production
  2. Use DLP: recipient checks, send delay, automatic attachment protection
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources