SHINDO2

Expo 2025 Osaka, Kansai

PhishingSize not disclosed

POSSIBLE LEAKHR / labour records / Documents / filesContained

Open in the live monitor ▶
Disclosed
Aug 20, 2026
Leak
Leak possible
Type
Phishing
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Photos (image)
Employment & HRAffiliation, Job title, Work shifts and assigned duties
ContactEmail address
Communications & contentSpeech drafts and scripts
Business dataContact persons named in quotes and invoices

Not leaked

  • Personal data of general visitors is not included

Who is affected

  • Association contacts
  • Expo performers
  • Contractor employees

Cause

A subcontractor employee fell for a phishing attack and their Microsoft 365 account was accessed

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. First disclosure

Response

  • Blocked the entry point
  • Phishing warning
  • Vendor review

Blocked the access the same day; warned about contacts impersonating the association; demanded improvements from the contractor

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources