SHINDO4

Osaka Marathon 2026

Personal data4,101people

LEAK CONFIRMEDPhone number / Full nameMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Mar 25, 2026
Leak
Leak confirmed
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Employment & HRAffiliated organization
ContactMobile phone number, Email address

How many

  • Volunteer registrants whose data became viewable 4,101 people
  • Of which names and organization names were actually viewed 3,477 people

Who is affected

  • Osaka Marathon 2026 volunteers

Cause

On March 16 the system developer, acting on the contractor's instructions, mistakenly disabled authentication while shutting the system down

Timeline

  1. Authentication was mistakenly disabled during system shutdown work
  2. Announced (per the article)

Response

  • Notified individuals
  • Hotline
  • Vendor review
  • Staff training
  • Change process

Notified and apologized to affected people by email and set up an inquiry line. Directed the contractor to recheck personal data management, train staff, follow manuals and use two-step checks

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Never sit on a known defect. Test every change before production
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources