SHINDO3

Money Forward Business Card

Business card holders370people

LEAK CONFIRMEDAPI key / private key / Source codeUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
May 1, 2026
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentCardholder name in the Latin alphabet, Last 4 digits of the card number
System & internalGitHub repositories (source code)
CredentialsAuthentication keys and passwords embedded in the source code

Not leaked

  • No leak of full card numbers, expiry dates or security codes was confirmed

How many

  • Business card holders 370 people

Who is affected

  • Cardholders of Money Forward Business Card

Cause

GitHub credentials used for software development were misused and a third party copied repositories

Timeline

  1. Official announcement

Response

  • Revoked credentials
  • Service stopped
  • Notified individuals

Invalidated the misused credentials and account access; deactivated authentication keys and passwords in the source code; temporarily suspended bank-account linking in all services; emailed affected users individually

What you should do

  1. Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources