SHINDO4

Kodansha

Contact recordsup to3,812records

LEAK CONFIRMEDFull name / Email addressPhishing · Contained

Open in the live monitor ▶
Disclosed
Aug 3, 2026
Leak
Leak confirmed
Type
Phishing
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

ContactEmail addresses and, for some people, names
IdentityEmail addresses and, for some people, names

How many

  • Contact records up to 3,812 records
  • Email addresses sent follow-on phishing 553 records

Who is affected

  • Contacts of the compromised employee

Cause

An employee clicked a link in a phishing email posing as a business partner and entered credentials on a fake login page

Timeline

  1. Intrusion began
  2. Attacker logged into the work email and sent phishing to 553 addresses
  3. Individuals notified
  4. First disclosure

Response

  • Password reset
  • Revoked credentials
  • Notified individuals

Changed the password, deleted existing sessions and notified affected people on July 31

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources