SHINDO2

NS Bio Japan

Customer personal records40records

LEAK CONFIRMEDPostal address / Phone numberPhishing · Closed (final report)

Open in the live monitor ▶
Disclosed
Feb 25, 2026
Detected
Feb 3, 2026
Detection to disclosure
22 days
Leak
Leak confirmed
Type
Phishing
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName
ContactAddress, Phone number, Email address
Account dataCustomer ID

How many

  • Customer personal records 40 records

Who is affected

  • New customers without accounts who ordered since 13 September 2016

Cause

A phishing attack stole the login ID and password of the cart system (ASP) admin account

Timeline

  1. Signs of unauthorized access found
  2. Reported to authority
  3. Reported to authority
  4. First disclosure

Response

  • Notified individuals

Contacted affected customers by email and letter

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources