SHINDO4

Lashinbang

lashinbang.com

Unauthorized accessSize not disclosed

POSSIBLE LEAKID document (type not stated) / Bank accountContained

Open in the live monitor ▶
Disclosed
Oct 1, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
1011001032955

What leaked

IdentityFull name, Date of birth, Gender, Occupation
ContactPostal code, Address, Email address, Phone number
ID documentsID document type and number
Financial & paymentBank name, branch name, account number, account holder name, Amounts, Payment method
Transactions & activityItems purchased or sold to the store, Delivery address, Shipping date, Shipping slip number
Account dataMember ID, Points
Communications & contentImages of consent forms (image)

Who is affected

  • Members
  • Buyback customers

Cause

Unauthorized access by a third party (specific cause not disclosed)

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. First disclosure

Response

  • Blocked the entry point
  • Patched
  • Vulnerability testing

System fixes, security verification, blocking of unauthorized access, investigation of the cause and development of measures to prevent recurrence

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  4. Don't open links in emails from this company. The apology email itself may be fake
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Watch for unexpected mail or invoices; your address is hard to change
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources