SHINDO4

e+

eplus.jp

Personal data1,463records

LEAK CONFIRMEDBank account / Postal addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 29, 2026
Detected
Sep 15, 2026
Detection to disclosure
14 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
2010701011796

What leaked

ContactEmail address, Postal code, Address
IdentityFull name (katakana), Full name
Transactions & activityPerformance information (title, venue, date/time)
Financial & paymentFinancial institution name, Branch name, Account type, Account number, Account holder name (katakana)

How many

  • Refund applications (bank transfer 751; card refund 644; postal transfer 68) 1,463 records

Who is affected

  • Smachike e-ticket refund applicants

Cause

Unauthorized access by a third party to the refund management system for the "Smachike" e-ticket service (2026/9/11 19:58 to 9/12 2:44). Detailed method not disclosed

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detected
  4. Security settings corrected
  5. Update published
  6. Individuals notified
  7. First disclosure

Response

  • Blocked the entry point
  • Vulnerability testing
  • Config review
  • Staff training

Review of security settings, inspection of the entire system, shorter security assessment cycles, stronger employee training

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources