SHINDO3

Kyorin University

Personal data~2,500people

POSSIBLE LEAKPostal address / Full namePhishing · Investigating

Open in the live monitor ▶
Disclosed
Jul 8, 2026
Leak
Leak possible
Type
Phishing
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress
UnspecifiedNames, addresses, etc.

How many

  • Students, faculty and staff, academic society members, etc. ~2,500 people

Who is affected

  • Students
  • Faculty and staff
  • Academic society members

Cause

A faculty member mistakenly clicked a scam site and, following fake support instructions, let a third party control the PC remotely (tech-support scam)

Timeline

  1. A faculty member working from home clicked a scam site and allowed remote control
  2. First disclosure

Response

  • Notified individuals
  • Forensic investigation
  • Staff training

Individual notices being prepared; forensic investigation by an outside firm planned; information security training for all staff and stricter handling rules

What you should do

  1. Watch for unexpected mail or invoices; your address is hard to change
  2. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources