SHINDO4

JAEA Nuclear Science Research Institute, JRR-3

ID documents200files175 people affected

LEAK CONFIRMEDDriver's licence images / My Number imagesUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Oct 1, 2026
Detected
Sep 25, 2026
Detection to disclosure
6 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
6050005002007

What leaked

ID documentsOfficial photo ID (driver's license images) (image), Official photo ID (My Number card images); My Numbers included for 6 people (image), Official photo ID (passport images) (image), Official photo ID (residence card images) (image)
Special-care dataSpecial medical check (radiation work) results
Communications & contentRadiation worker certificates (documents submitted by users' institutions)

Not leaked

  • Research support site users' account information (IDs, passwords, names entered in the registration form, etc.) did not leak
  • Research support site users' account information (IDs, passwords, names entered in the registration form, etc.) did not leak

How many

  • Users whose personal data leaked 175 people
  • Files containing personal data 367 files
  • Files illegally downloaded (total) 2,419 files
  • Images of official photo ID 200 files
  • Special medical check (radiation work) results 146 files
  • Radiation worker certificates 21 files
  • Including My Number 6 people

Who is affected

  • Research support site users (external users of the JRR-3 facility)

Cause

Unauthorized external access to the research support site for the JRR-3 research reactor, run on a cloud platform contracted by the agency. 2,419 registered files were illegally downloaded. The site is separate from the agency's internal business network and other systems were not affected

Timeline

  1. Detected
  2. Service suspended
  3. Leak of personal data confirmed
  4. First disclosure

Response

  • Service stopped
  • Notified individuals

Stopped external access to the research support site. Individual notices and apologies to the people whose data leaked. Reported to and consulted the PPC, the relevant ministries and the police. The cause will be investigated and prevention measures taken

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources