SHINDO6

Medica Shuppan Co., Ltd.

Personal data~641,000people

POSSIBLE LEAKBank account / My NumberRansomware · Recovering

Open in the live monitor ▶
Disclosed
Mar 2026
Leak
Leak possible
Type
Ransomware
Status
Recovering
Security spend
Measures, no amount
Compensation
Not announced

What leaked

Account dataID
IdentityFull name, Title
ContactEmail address, Address (incl. prefecture), Phone number
Employment & HRWorkplace, Performance reviews and resume contents
Financial & paymentBank account
Communications & contentSubmitted images (image)
ID documentsMy Number (some registrants), Passports (third-party data), Residence cards (third-party data)
CredentialsIDs and passwords (third-party data)
Special-care dataHealth records (third-party data)

How many

  • People in scope in the final report (may include duplicates) ~641,000 people
  • Records that may have leaked as of the third report ~772,000 records

Who is affected

  • Medica ID users
  • General customers
  • Authors and outside contributors
  • Third parties
  • Employees
  • Job applicants

Cause

A third party entered the internal network with legitimate account credentials and ran ransomware. How the credentials were obtained was not determined

Timeline

  1. Exact date of the first report not confirmed. Security Measures Lab's May roundup lists the disclosure date as March 13
  2. Attack date (Security Measures Lab)
  3. Status update
  4. Third report
  5. Investigation completed and reported to the PPC
  6. Investigation findings and prevention measures

Response

  • Phishing warning
  • MFA
  • More monitoring
  • Access review
  • Staff training

Strengthened authentication and security, audited the network and improved monitoring. Plans layered defenses, a stronger authentication base and staff training by September 2026. Warned about suspicious emails

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  4. Change this password and every account that reused it now. Switch to a passkey where offered
  5. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  6. Don't open links in emails from this company. The apology email itself may be fake
  7. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  8. Watch for unexpected mail or invoices; your address is hard to change
  9. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  10. Expect targeted phishing posing as HR or interview contacts
  11. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Offline backups with restore drills; segment the network
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources