SHINDO2

Middle no Tenshoku

Unauthorized logins~2,500accounts

POSSIBLE LEAKProfile fieldsAccount takeover · Closed (final report)

Open in the live monitor ▶
Disclosed
Jun 5, 2026
Detected
Jun 2, 2026
Detection to disclosure
3 days
Leak
Leak possible
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

Account dataData on member information pages

Not leaked

  • No leak of IDs or passwords caused by the logins confirmed at announcement

How many

  • Unauthorized logins ~2,500 accounts

Who is affected

  • Middle no Tenshoku members

Cause

Credential stuffing using email addresses and passwords apparently obtained elsewhere

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detected
  4. Reported to authority
  5. Reported to authority
  6. First disclosure

Response

  • Blocked the entry point
  • Password reset
  • Hotline

Blocked source IP addresses, reset passwords and opened an inquiry desk

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources