SHINDO4

LEAN BODY

lean-body.jp

Personal data~440,000accounts

LEAK CONFIRMEDDate of birth / Payment data (unspecified)Unauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Sep 15, 2026
Detected
Sep 8, 2026
Detection to disclosure
7 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced
Corporate number
8190001023288

What leaked

ContactEmail address
IdentityNickname, Gender, Date of birth, Height and weight
Transactions & activityUsage status, Contract and payment information
CredentialsEncrypted passwords
Financial & paymentContract and payment information

How many

  • Customers, including former members ~440,000 accounts

Who is affected

  • Members
  • Former members

Cause

Unauthorized access to the internal analytics tool "Metabase". Vulnerability information was not being checked regularly, and necessary updates had not been applied

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detected
  4. Contained
  5. Reported to authority
  6. First disclosure
  7. Individuals notified

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources