SHINDO3

Mushitaiji.com

Customers15people

LEAK CONFIRMEDCard security code / Card numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Aug 22, 2026
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName, address, phone, email, order details and more
ContactName, address, phone, email, order details and more, Name, address, phone, email, order details and more, Name, address, phone, email, order details and more
Transactions & activityName, address, phone, email, order details and more
Financial & paymentCard number, expiry, security code, cardholder name, Card number, expiry, security code, cardholder name, Card number, expiry, security code, cardholder name, Card number, expiry, security code, cardholder name

How many

  • Customers 15 people
  • Credit card users 6 people

Who is affected

  • Customers

Cause

A malicious program was planted on the payment page; administrator rights were obtained through a vulnerability in a related plugin

Timeline

  1. Malicious program active 8/11 to 8/18
  2. Malicious program removed and vulnerability fixed
  3. First disclosure

Response

  • Patched
  • Data deleted
  • Notified individuals

Removed the malicious program and fixed the vulnerability; contacted affected people individually; reported to the payment processor and the PPC

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources