SHINDO6

Kobayashi

Personal records8,149records

LEAK CONFIRMEDPassport / My NumberMalware infection · Closed (final report)

Open in the live monitor ▶
Disclosed
Jan 23, 2026
Detected
Nov 4, 2025
Detection to disclosure
80 days
Leak
Leak confirmed
Type
Malware infection
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName, Date of birth
ContactAddress, Contact details, phone number
Financial & paymentBank account number, Tax return information
ID documentsPassport number, Health insurance card number, My Number (56 records)
Family & private lifeFamily information
Employment & HRBasic pension number

How many

  • Personal records 8,149 records
  • Job applicants 4,984 records
  • Employees, temporary staff and former employees 3,074 records
  • Advisers and business partners 91 records

Who is affected

  • Job applicants
  • Employees and temporary staff
  • Former employees
  • Advisers and business partners

Cause

A malicious program was placed on a server and the stolen data was published on an outside site

Timeline

  1. Found through contact from the police
  2. Reported to authority
  3. Publication on an outside site confirmed when the investigation was completed
  4. Notifications to affected people began
  5. Security NEXT report date

Response

  • Forensic investigation
  • Notified individuals

Investigated with outside help and notified affected people

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Watch for unexpected mail or invoices; your address is hard to change
  6. Expect targeted phishing posing as HR or interview contacts
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources