SHINDO4

Kota Co., Ltd.

Personal data109,147records

POSSIBLE LEAKPostal address / HR / labour recordsRansomware · Closed (final report)

Open in the live monitor ▶
Disclosed
Mar 30, 2026
Detected
Mar 27, 2026
Detection to disclosure
3 days
Leak
Leak possible
Type
Ransomware
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Gender, Age, Date of birth
ContactAddress, Phone number, Email address
Employment & HREmployee ID, Educational background, Workplace, Position
Account dataShareholder number
Financial & paymentNumber of shares held

How many

  • Records that may have been viewed (total of 8 categories; may overlap) 109,147 records
  • Shareholders 55,408 records
  • Service users 35,274 records
  • Business partners 16,133 records
  • Employees and former employees 591 records
  • Job applicants 684 records
  • IR event attendees 661 records
  • Stylist award participants 124 records
  • Product testers 272 records

Who is affected

  • Shareholders
  • Service users
  • Business partners
  • Employees
  • Former employees
  • Job applicants
  • IR event attendees, stylist award participants and product testers

Cause

Unauthorized access by a third party and ransomware (intrusion route not disclosed)

Timeline

  1. Detected
  2. First report
  3. Earnings release delayed by more than 50 days
  4. Fourth report
  5. Final report and notice on personal data

Response

  • Blocked the entry point
  • Forensic investigation
  • BCP review

Disconnected servers and internal PCs from the network and had an outside investigation. Rebuilt and strengthened the network and server environment and restored systems

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources