SHINDO4

KINDAL

Customers136,464people

LEAK CONFIRMEDPostal address / Date of birthPhishing · Contained

Open in the live monitor ▶
Disclosed
Aug 28, 2026
Detected
Aug 24, 2026
Detection to disclosure
4 days
Leak
Leak confirmed
Type
Phishing
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
2160002002472

What leaked

Account dataCustomer ID, Newsletter subscription status, Customer tag information, Points history
IdentityFull name, Date of birth
ContactAddress, Phone number, Email address
Transactions & activityNumber of orders
Financial & paymentPurchase amounts

Not leaked

  • Card numbers, security codes and online store login passwords are not included
  • Card numbers, security codes and online store login passwords are not included
  • Card numbers, security codes and online store login passwords are not included

How many

  • Customers 136,464 people

Who is affected

  • Customers

Cause

An employee entered credentials on a fake site after a phishing email posing as the e-commerce platform operator. The account had no two-step verification and a weak password

Timeline

  1. Intrusion began
  2. Bulk export
  3. Detected
  4. First disclosure
  5. Dedicated inquiry line set up

Response

  • Revoked credentials
  • MFA
  • Forensic investigation
  • Notified individuals
  • Hotline

Deleted the compromised account; made two-step verification mandatory for all staff accounts; investigated with the e-commerce platform operator; notified affected customers individually; set up a dedicated inquiry line on 9/2

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources