SHINDO2

Club Chapel Hotels

Unauthorized accessSize not disclosed

POSSIBLE LEAKPhone number / Full nameContained

Open in the live monitor ▶
Disclosed
Aug 17, 2026
Detected
Aug 6, 2026
Detection to disclosure
11 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName or nickname, Name or nickname
ContactEmail address, Phone number

Not leaked

  • Payment data such as card or bank account details is not held by the company

Who is affected

  • People who booked on the official website
  • Email members
  • Contact-form users

Cause

Unauthorized third-party access to the official website's booking system (vulnerability since fixed)

Timeline

  1. Detected
  2. First disclosure

Response

  • Patched
  • Blocked the entry point

Emergency security measures and vulnerability fixes

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources