SHINDO2
Marutaka Kogyo
RansomwareSize not disclosed
POSSIBLE LEAKClosed (final report)
Open in the live monitor ▶- Disclosed
- Mar 13, 2026
- Leak
- Leak possible
- Type
- Ransomware
- Status
- Closed (final report)
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
UnspecifiedCustomer personal data
Who is affected
- Customers
Cause
The attacker entered the network through a VPN device, created a rogue administrator account, accessed several servers and encrypted data
Timeline
- Ransomware attack; the file server was encrypted
- First notice
- Investigation results published (entry via VPN device, 1.5 GB possibly leaked)
Response
- Blocked the entry point
- Forensic investigation
- Notified individuals
Disconnected the affected server and related equipment, and investigated the entry route and scope with outside help. Said it would contact affected people individually if a leak was found
What you should do
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Offline backups with restore drills; segment the network
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security Measures Lab Researcher · Mar 17, 2026
- Security NEXT News · Aug 13, 2026