SHINDO4
JAEA Nuclear Science Research Institute, JRR-3
Japan Atomic Energy Agency
ID documents200files175 people affected
LEAK CONFIRMEDDriver's licence images / My Number imagesUnauthorized access · Investigating
Open in the live monitor ▶- Disclosed
- Oct 1, 2026
- Detected
- Sep 25, 2026
- Detection to disclosure
- 6 days
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Investigating
- Security spend
- Measures, no amount
- Compensation
- Not announced
- Corporate number
- 6050005002007
What leaked
ID documentsOfficial photo ID (driver's license images) (image), Official photo ID (My Number card images); My Numbers included for 6 people (image), Official photo ID (passport images) (image), Official photo ID (residence card images) (image)
Special-care dataSpecial medical check (radiation work) results
Communications & contentRadiation worker certificates (documents submitted by users' institutions)
Not leaked
- Research support site users' account information (IDs, passwords, names entered in the registration form, etc.) did not leak
- Research support site users' account information (IDs, passwords, names entered in the registration form, etc.) did not leak
How many
- Users whose personal data leaked 175 people
- Files containing personal data 367 files
- Files illegally downloaded (total) 2,419 files
- Images of official photo ID 200 files
- Special medical check (radiation work) results 146 files
- Radiation worker certificates 21 files
- Including My Number 6 people
Who is affected
- Research support site users (external users of the JRR-3 facility)
Cause
Unauthorized external access to the research support site for the JRR-3 research reactor, run on a cloud platform contracted by the agency. 2,419 registered files were illegally downloaded. The site is separate from the agency's internal business network and other systems were not affected
Timeline
- Detected
- Service suspended
- Leak of personal data confirmed
- First disclosure
Response
- Service stopped
- Notified individuals
Stopped external access to the research support site. Individual notices and apologies to the people whose data leaked. Reported to and consulted the PPC, the relevant ministries and the police. The cause will be investigated and prevention measures taken
What you should do
- ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
- Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
- Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
- Check the company's notice to see if you're affected
Lessons for companies
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Japan Atomic Energy Agency Official notice · Oct 1, 2026
- National Tax Agency Corporate Number Publication Site Registry