SHINDO4

Mitsui Fudosan

Personal dataup to55,000records

POSSIBLE LEAKFull name / Email addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 1, 2026
Detected
Aug 28, 2026
Detection to disclosure
4 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
6010001034957

What leaked

IdentityFull name, Display name
ContactEmail address
Employment & HRDepartment, Job title

How many

  • Officers/employees and external parties up to 55,000 records
  • Officers and employees up to 19,000 records
  • External parties up to 36,000 records

Who is affected

  • Officers and employees
  • External parties

Cause

Unauthorized access to some systems through misuse of credentials

Timeline

  1. Detected
  2. First disclosure
  3. Individuals notified
  4. Update published
  5. Reported to authority

Response

  • Revoked credentials
  • More monitoring
  • New detection
  • Access review
  • Config review

Revoked the credentials, account inventory and settings review, stronger monitoring, implemented unauthorized-access detection logic

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources