SHINDO4

Aurora SMS

Personal data22,928records

LEAK CONFIRMEDEmail address / Business contact nameUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 14, 2026
Detected
Jun 24, 2026
Detection to disclosure
20 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

Account dataAccount ID
Business dataCompany or branch name, Contact person name
ContactPrefecture and postal code, Notification email address

Not leaked

  • Passwords, password hashes, API keys, authentication tokens, and payment and billing information
  • End users' phone numbers, names and SMS message bodies

How many

  • Records that may contain personal data 22,928 records
  • Total records in the leaked file 95,412 records
  • SMS messages sent without authorization 280 records

Who is affected

  • Contacts at client companies using the SMS system

Cause

A third party broke into the SMS system's management console, took part of the registered data, and sent unauthorized SMS from one client's account

Timeline

  1. Detected
  2. First disclosure

Response

  • Blocked the entry point
  • Forensic investigation
  • Governance / committee

Access route blocked and logs preserved; intrusion route and scope investigated with outside help. Recurrence prevention, management review and security hardening

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources