SHINDO3

Ministry of Internal Affairs and Communications

Companies surveyed1,708organizations

EXPOSEDPhone number / Full nameMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Feb 10, 2026
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityContact name
ContactPhone number, Email address
Business dataCompany information

How many

  • Companies surveyed 1,708 organizations
  • Confirmed leaks 6 records
  • Possible leaks 43 records

Who is affected

  • Contacts at broadcasters and production companies

Cause

Subcontractor Cross Marketing, working for contractor MUFG Research and Consulting, set up login management wrongly when building the site

Timeline

  1. Security NEXT report date
  2. Contractor MUFG Research and Consulting published counts and cause

Response

  • Service stopped
  • Notified individuals

Closed the site the day it was found; apologized to the 1,708 companies and explained to those whose data was shown

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources