SHINDO3

OCS Family Link Service

Unauthorized accessSize not disclosed

POSSIBLE LEAKPostal address / Phone numberInvestigating

Open in the live monitor ▶
Disclosed
Jul 24, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name
ContactOverseas delivery address, Email address, Phone or fax number, Address of the responsible department
Account dataSite member number
Business dataCompany name, Administrator name
CredentialsLogin password

Who is affected

  • Site members (overseas delivery addresses)
  • Corporate administrators

Cause

Unauthorized access by an outside third party (cyberattack)

Timeline

  1. First report (as stated in the third report)
  2. Reported to authority
  3. Individual notifications began
  4. Third report

Response

  • Blocked the entry point
  • Service stopped
  • Notified individuals

The site's systems and related networks were cut off and the service stays suspended until safety is confirmed. Individual notices from July 28. Orders up to July 23 handled through verified-safe procedures

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources