SHINDO2

montbell

www.montbell.com

Customersup to15people

POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 25, 2026
Detected
Sep 11, 2026
Detection to disclosure
14 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced
Corporate number
2120001047910

What leaked

IdentityFull name
ContactPhone number, Postal code, Address

How many

  • Customers up to 15 people

Who is affected

  • Registered users

Cause

A vulnerability in the global site (montbell.com), which handles overseas shipping, was exploited and registered users' data may have been obtained by a third party

Timeline

  1. Data obtained on August 9-10
  2. Intrusion stopped
  3. Detected
  4. First disclosure

Response

  • Patched

Fixed the vulnerability found and strengthened information management

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources