SHINDO3

Japan-China Economic Association

Suspicious emails sent565records

POSSIBLE LEAKMessages / email bodies / Email addressAccount takeover · Closed (final report)

Open in the live monitor ▶
Disclosed
Jun 5, 2026
Leak
Leak possible
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactAddresses the account had corresponded with
Communications & contentPersonal data in past email bodies

How many

  • Suspicious emails sent 565 records

Who is affected

  • People the account had exchanged email with

Cause

One staff email account was accessed by a third party and used to send suspicious emails

Timeline

  1. Intrusion began
  2. First disclosure

Response

  • Password reset
  • MFA
  • Staff training

Stricter password management, rolling out multi-factor authentication, renewed security training

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources