SHINDO3

Kyoiku Software Co., Ltd.

Personal data4,627records

POSSIBLE LEAKMessages / email bodies / Full nameRansomware · Closed (final report)

Open in the live monitor ▶
Disclosed
Aug 17, 2026
Detected
Aug 17, 2026
Detection to disclosure
Same day
Leak
Leak possible
Type
Ransomware
Status
Closed (final report)
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
6010101000966

What leaked

UnspecifiedCustomer information
Account dataUniversity attended, Part of the student number
IdentityFull name
Communications & contentPast emails exchanged with customers and business partners

Not leaked

  • The company holds no credit card information, so none leaked

How many

  • Users of the self-scoring web service 4,627 records

Who is affected

  • Users of the web service (self-scoring system) that ran on the server up to 2016
  • Customers
  • Business partners

Cause

A third party broke into a dormant rental server the company had used in the past and encrypted it with ransomware; the entry point was not disclosed

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detection date not disclosed; the notice date is used as an upper bound
  4. First disclosure

Response

  • Forensic investigation
  • More monitoring

Outside investigation, decommissioned the server, stronger security audits and monitoring

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources