SHINDO3

N.E. Chemcat Corporation

Malware infectionSize not disclosed

POSSIBLE LEAKDate of birth / Postal addressContained

Open in the live monitor ▶
Disclosed
Aug 20, 2026
Detected
May 28, 2026
Detection to disclosure
84 days
Leak
Leak possible
Type
Malware infection
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Gender, Date of birth
ContactAddress, Email address, Phone number
Employment & HRHR information

Who is affected

  • Employees
  • Former employees
  • Temp and contractor staff
  • Group company employees

Cause

Malware apparently ran on a device, and a third party misused an employee's account

Timeline

  1. Detected
  2. First disclosure

Response

  • MFA
  • Access review
  • More monitoring

Reported to the PPC and filed a damage report with the police; tightened authentication and access management; strengthened monitoring

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources