SHINDO3

Le Ange Co., Ltd.

Account takeoverSize not disclosed

POSSIBLE LEAKDate of birth / Postal addressContained

Open in the live monitor ▶
Disclosed
Aug 6, 2026
Detected
Jul 15, 2026
Detection to disclosure
22 days
Leak
Leak possible
Type
Account takeover
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactAddress, Phone number, Email address

Not leaked

  • Credit card, bank account and My Number data were not handled on this platform

Who is affected

  • Some members
  • Employees

Cause

Most likely a brute-force attack on BAND, the communication tool used for business contact (exact cause unknown)

Timeline

  1. Intrusion began
  2. Detected
  3. Individuals notified
  4. First disclosure

Response

  • MFA
  • Notified individuals

Enabled two-step verification; notified affected people by August 5; reported to the PPC

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources