SHINDO2
Omikenshi Co., Ltd.
RansomwareSize not disclosed
POSSIBLE LEAKFull nameClosed (final report)
Open in the live monitor ▶- Disclosed
- Mar 23, 2026
- Leak
- Leak possible
- Type
- Ransomware
- Status
- Closed (final report)
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityEmployee names
Not leaked
- Customer personal data
Who is affected
- Employees
Cause
Entry through the VPN with improperly obtained credentials
Timeline
- Attack late at night on March 16
- First report
- Update
- Announced an extension of the filing deadline for its financial report
- Final forensic report
Response
- Revoked credentials
- Access review
- MFA
Revoked credentials, reviewed VPN accounts, extended multi-factor authentication and tightened access controls (done or planned)
What you should do
- Expect targeted phishing posing as HR or interview contacts
- Check the company's notice to see if you're affected
Lessons for companies
- Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
- Offline backups with restore drills; segment the network
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security Measures Lab Researcher · Jul 17, 2026