SHINDO5

Hosokawa Micron Corporation

Total~1,700records

LEAK CONFIRMEDMy Number / Date of birthAccount takeover · Closed (final report)

Open in the live monitor ▶
Disclosed
Mar 27, 2026
Detected
Feb 2, 2026
Detection to disclosure
53 days
Leak
Leak confirmed
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth, Gender
ContactAddress, Phone number, Email address
ID documentsMy Number (one person)

How many

  • Total ~1,700 records
  • Customers and business partners 257 records
  • Employees (including former employees) 1,470 records
  • Employee family member (including My Number) 1 records

Who is affected

  • Customers and business partners
  • Employees
  • Former employees
  • Employee family member

Cause

Unauthorized logon to one account on a cloud storage service the company used as a supplementary tool

Timeline

  1. Unauthorized access detected; a ransomware group claimed the attack the same day
  2. Everest claimed theft of 30 GB on its leak site
  3. Publication of the data confirmed
  4. First-notice date not given in the article; final report on March 27
  5. Final report

Response

  • More monitoring

Strengthened system security and monitoring based on outside experts' advice

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Watch for unexpected mail or invoices; your address is hard to change
  6. Expect targeted phishing posing as HR or interview contacts
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources