SHINDO3

Hands Holdings Co., Ltd.

RansomwareSize not disclosed

POSSIBLE LEAKMy Number / Postal addressInvestigating

Open in the live monitor ▶
Disclosed
Jun 22, 2026
Detected
Jun 19, 2026 08:50 JST
Detection to disclosure
3 days
Leak
Leak possible
Type
Ransomware
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactAddress, Phone number, Email address
ID documentsMy Number (individual number)
Account dataDate of hire
Employment & HREmployee number, Other HR and labor management information

Who is affected

  • Employees
  • Former employees
  • Dependents

Cause

Internal systems were accessed from outside without authorization and infected with ransomware

Timeline

  1. Detected
  2. First disclosure
  3. Report No. 2 published

Response

  • Blocked the entry point
  • Forensic investigation

Disconnected suspected infected servers and PCs from the network and worked with outside security specialists on the cause and recovery. Plans to strengthen its security setup

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Watch for unexpected mail or invoices; your address is hard to change
  6. Expect targeted phishing posing as HR or interview contacts
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources