SHINDO3
Money Forward Business Card
Money Forward, Inc.
Business card holders370people
LEAK CONFIRMEDAPI key / private key / Source codeUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- May 1, 2026
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
Financial & paymentCardholder name in the Latin alphabet, Last 4 digits of the card number
System & internalGitHub repositories (source code)
CredentialsAuthentication keys and passwords embedded in the source code
Not leaked
- No leak of full card numbers, expiry dates or security codes was confirmed
How many
- Business card holders 370 people
Who is affected
- Cardholders of Money Forward Business Card
Cause
GitHub credentials used for software development were misused and a third party copied repositories
Timeline
- Official announcement
Response
- Revoked credentials
- Service stopped
- Notified individuals
Invalidated the misused credentials and account access; deactivated authentication keys and passwords in the source code; temporarily suspended bank-account linking in all services; emailed affected users individually
What you should do
- Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
- Check the company's notice to see if you're affected
Lessons for companies
- Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Cybersecurity-jp.com News · May 7, 2026
- Money Forward, Inc. Official notice · May 1, 2026