SHINDO2

International House of Japan Library

Personal data3accounts

POSSIBLE LEAKPassword / Company nameUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 29, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
1010405010617

What leaked

Business dataCompany name of corporate member A
CredentialsPassword of corporate representative member B, Initial password of former staff member C registered in the old system (not registered in the current system)

Not leaked

  • There is no trace of attempts to read users' email addresses, addresses, phone numbers or dates of birth, nor of bulk retrieval of user information
  • There is no trace of attempts to read users' email addresses, addresses, phone numbers or dates of birth, nor of bulk retrieval of user information
  • There is no trace of attempts to read users' email addresses, addresses, phone numbers or dates of birth, nor of bulk retrieval of user information
  • There is no trace of attempts to read users' email addresses, addresses, phone numbers or dates of birth, nor of bulk retrieval of user information

How many

  • User records that may have leaked (corporate member A, corporate representative member B, former staff member C registered in the old system) 3 accounts

Who is affected

  • Corporate member
  • Corporate representative member
  • Former staff member registered in the old system

Cause

Unauthorized external access to the library catalog search system (OPAC). A program fixing a vulnerability was applied as a countermeasure

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. First disclosure

Response

  • Password reset
  • Revoked credentials
  • Config review
  • Patched
  • Notified individuals
  • Phishing warning

Changed the IDs, passwords and other credentials of the affected accounts, restricted connection sources on the system side and applied a program fixing a vulnerability. Affected people are contacted individually. Warning about suspicious calls and emails. Contact: the library (03-3470-3213)

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources