SHINDO4

Nichirei

Personal data records53,866records

LEAK CONFIRMEDSalary / Residence status (visa)Ransomware · Contained

Open in the live monitor ▶
Disclosed
Jul 13, 2026
Detected
Jul 13, 2026 06:50 JST
Detection to disclosure
Same day
Leak
Leak confirmed
Type
Ransomware
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
8010001034889

What leaked

IdentityFull name, Date of birth, Gender, Residence status (visa)
ContactAddress, Phone number, Email address
Employment & HREmployee number, Salary information, HR and labor-management information
Business dataCompany name

How many

  • Personal data records 53,866 records

Who is affected

  • Delivery-destination customers
  • Business-partner contacts
  • Employees
  • Former employees
  • Employees' family members
  • Job applicants

Cause

System outage caused by a cyberattack (the company described whether it was ransomware as "under investigation")

Timeline

  1. Intrusion began
  2. System outage
  3. First disclosure
  4. Contained
  5. Detected
  6. Report No. 2 published
  7. Update published
  8. Service restored
  9. Report No. 4 published
  10. Operations restored at all sites (late July)
  11. Update published
  12. Company issued an update
  13. Reported to authority
  14. Company issued an update

Response

  • More monitoring
  • Phishing warning
  • BCP review

Strengthened cybersecurity and monitoring, reviewed the business continuity plan, warnings about suspicious emails, SMS and phone calls

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  5. Expect targeted phishing posing as HR or interview contacts
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources