SHINDO4

Isesaki City Board of Education

Personal data3,789records

POSSIBLE LEAKPassword / Full nameRansomware · Contained

Open in the live monitor ▶
Disclosed
Sep 28, 2026
Detected
Aug 14, 2026
Detection to disclosure
45 days
Leak
Leak possible
Type
Ransomware
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
8000020102041

What leaked

Account dataSchool name, Grade
IdentityFull name, Name reading (furigana)
CredentialsAccount name, Password

How many

  • Student account records (23 elementary schools, 11 junior high schools and Yotsuba Gakuen) 3,789 records

Who is affected

  • Students

Cause

Ransomware attack on the internal system of Ryomo Systems, the contractor maintaining students' tablet devices. The system that was accessed contained information on the accounts students use. Ryomo Systems reported no damage to the education network

Timeline

  1. Detected at the contractor
  2. City received report of the unauthorized access from the contractor (no damage to the education network)
  3. Detected
  4. Notice sent to parents
  5. First disclosure

Response

  • Password reset
  • Notified individuals
  • Vendor review
  • Hotline

Passwords of the affected accounts were changed. Apology notices sent to parents. The city is checking and instructing the contractor on information handling and its management system. Ryomo Systems dedicated call center (0120-998-970)

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Offline backups with restore drills; segment the network
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources