SHINDO2

Marutaka Kogyo

RansomwareSize not disclosed

POSSIBLE LEAKClosed (final report)

Open in the live monitor ▶
Disclosed
Mar 13, 2026
Leak
Leak possible
Type
Ransomware
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

UnspecifiedCustomer personal data

Who is affected

  • Customers

Cause

The attacker entered the network through a VPN device, created a rogue administrator account, accessed several servers and encrypted data

Timeline

  1. Ransomware attack; the file server was encrypted
  2. First notice
  3. Investigation results published (entry via VPN device, 1.5 GB possibly leaked)

Response

  • Blocked the entry point
  • Forensic investigation
  • Notified individuals

Disconnected the affected server and related equipment, and investigated the entry route and scope with outside help. Said it would contact affected people individually if a leak was found

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Offline backups with restore drills; segment the network
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources