SHINDO2

Osaka City

Exam applicants106people

POSSIBLE LEAKPhone number / Full nameUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 15, 2026
Detected
Sep 11, 2026
Detection to disclosure
4 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Name reading (kana)
ContactEmail address, Phone number

How many

  • Exam applicants 106 people

Who is affected

  • Exam applicants

Cause

Unauthorized access to a data analytics tool used by the system provider

Timeline

  1. Intrusion began
  2. The provider blocked the access as an emergency measure
  3. The system provider reported to the city
  4. First disclosure

Response

  • Blocked the entry point

The provider took emergency measures on September 7 to block the unauthorized access

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  2. Put security requirements, audit rights and reporting deadlines in vendor contracts
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources