SHINDO1

Mie Prefecture

Child1people

EXPOSEDDisability / Full nameMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Jun 27, 2026
Detected
Jun 22, 2026
Detection to disclosure
5 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityChild's name, Names of two staff
Special-care dataSupport details from an individual support plan

How many

  • Child 1 people
  • Childcare staff 2 people
  • Trainees who could view it 240 people

Who is affected

  • A child
  • Childcare managers

Cause

Hidden sheets were not checked and no second person reviewed the file before posting

Timeline

  1. Exposure began
  2. Exposure ended
  3. Found through a trainee's inquiry
  4. First disclosure

Response

  • Change process
  • Vendor review

Instructed the contractor to strengthen pre-posting checks and data handling

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources