SHINDO2

Oriental Diamond

RansomwareSize not disclosed

POSSIBLE LEAKPostal address / Phone numberRecovering

Open in the live monitor ▶
Disclosed
May 12, 2026
Detected
May 4, 2026
Detection to disclosure
8 days
Leak
Leak possible
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName
ContactAddress, Phone number

Not leaked

  • Bank account, credit card and My Number data are not included

Who is affected

  • Customers and others (no detail in the article)

Cause

A third party exploited a VPN vulnerability and encrypted data on the head-office file server

Timeline

  1. Detected
  2. First disclosure

Response

  • Service stopped
  • MFA
  • Blocked the entry point
  • Staff training

Stopped using the VPN and strengthened authentication; restricted outside connections while rebuilding; staff training

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Offline backups with restore drills; segment the network
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources