SHINDO2

JA Kyosai

MisconfigurationSize not disclosed

EXPOSEDPostal address / Date of birthClosed (final report)

Open in the live monitor ▶
Disclosed
Feb 5, 2026
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName, Date of birth
ContactAddress, Email address

Not leaked

  • No saving of the data at JAs was found, and any leak outside the JAs is denied

Who is affected

  • Policyholders, insured people and related people

Cause

A setting error in the sharing system run by the federation let JA administrators view other JAs' policyholder data

Timeline

  1. Exposure began
  2. Exposure ended
  3. First disclosure

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources