SHINDO2

i-NEX

Email addresses leaked373records

LEAK CONFIRMEDPhone number / Full namePhishing · Contained

Open in the live monitor ▶
Disclosed
Jul 1, 2026
Detected
Jun 24, 2026
Detection to disclosure
7 days
Leak
Leak confirmed
Type
Phishing
Status
Contained
Security spend
Not checked yet
Compensation
Not announced
Corporate number
8120001061798

What leaked

ContactEmail address, Mobile phone number (46 entries, possibly leaked)
IdentityFull name (46 entries, possibly leaked)

How many

  • Email addresses leaked 373 records
  • Of these, company employees 217 records
  • Of these, business partners' employees 112 records
  • Of these, employees of Asahi Broadcasting group companies 44 records
  • Name, mobile number and email address possibly leaked 46 records

Who is affected

  • Company employees
  • Business partners' employees
  • Employees of Asahi Broadcasting group companies

Cause

An employee responded to a phishing email posing as a business partner and entered login details on a phishing site; a third party then logged in to the email account and accessed the linked cloud services

Timeline

  1. Intrusion began
  2. Detected
  3. Password changed and sessions forcibly logged out
  4. First disclosure
  5. Second report: forensic results announced, with 373 email addresses leaked and 46 entries possibly leaked

Response

  • Password reset
  • Revoked credentials
  • Forensic investigation
  • Notified individuals
  • Staff training
  • Phishing warning

Password change and forced logout, forensic investigation by an outside specialist, contact with potentially affected people, review of ID and password management, stronger company-wide security training, warnings about phishing emails

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources