SHINDO3

JEMS Co., Ltd.

Personal data223records

LEAK UNCLEARPasswordAccount takeover · Closed (final report)

Open in the live monitor ▶
Disclosed
Mar 26, 2026
Leak
Unknown
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

CredentialsEmployee email account credentials

How many

  • Outside recipients of phishing emails 223 records

Who is affected

  • Business partners and clients

Cause

Credentials were possibly stolen; overseas sign-ins sent phishing emails posing as a cloud service

Timeline

  1. First disclosure

Response

  • More monitoring
  • Staff training

Strengthened monitoring of suspicious sign-ins and authentication; staff training

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources