SHINDO5

Ink Kakumei

ID documents24,166records

POSSIBLE LEAKCard security code / Card numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 29, 2026
Detected
Dec 9, 2025
Detection to disclosure
232 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Compensation offered

What leaked

Financial & paymentCard number, Cardholder name, Expiry date, Security code
IdentityFull name, Date of birth
ContactPhone number, Email address
CredentialsPassword hashes

How many

  • Credit card and personal data records 24,166 records

Who is affected

  • Customers who paid by credit card on Ink Kakumei

Cause

A third party exploited a system vulnerability and tampered with the payment application

Timeline

  1. Start of the period with possible leakage
  2. Detected
  3. Card payments suspended
  4. Intrusion stopped
  5. Reported to authority
  6. Reported to authority
  7. Malicious program removed
  8. The third-party forensic investigation finished on March 18, 2026

Response

  • Service stopped
  • Forensic investigation
  • More monitoring
  • Hotline

Card payments suspended and a third-party forensic firm investigated. Fraud monitoring with card companies. No card reissue fee for customers. Helpline (0120-761-109, 10:00-17:00, closed weekends and holidays)

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources