SHINDO4

Fine Online Shop

Credit card records912records

POSSIBLE LEAKCard security code / Card numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 27, 2026
Detected
Jun 30, 2026
Detection to disclosure
27 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

Financial & paymentCardholder name, Card number, Expiry date, Security code

How many

  • Credit card records 912 records

Who is affected

  • Customers who paid by card in the online shop

Cause

A third party exploited a weakness in the web server environment, gained access and altered files (planted a malicious program)

Timeline

  1. Start of the possible leak period
  2. Pointed out by the Tokyo Metropolitan Police cybercrime unit
  3. Site shut down immediately
  4. Intrusion stopped
  5. First disclosure

Response

  • Service stopped
  • Forensic investigation
  • More monitoring

Old servers and system fully retired and replaced, infrastructure separated, operational monitoring strengthened. Helpline (03-3761-5144, weekdays 9:00-18:00)

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources