SHINDO4
OZmall
Starts Publishing Corporation
ozmall.co.jp
Personal dataup to442,779people
POSSIBLE LEAKEmail address / Postal addressUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Sep 27, 2026
- Detected
- Sep 26, 2026
- Detection to disclosure
- 1 day
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Measures, no amount
- Compensation
- Not announced
- Corporate number
- 7011701004273
What leaked
ContactEmail address, Address (prefecture only, some records)
IdentityFull name (some records)
How many
- Members (up to 447,610 in the first report) up to 442,779 people
Who is affected
- Members
- Some former members
Cause
A vulnerability was exploited through a large volume of unauthorized access from overseas (technical details not disclosed)
Timeline
- Detected
- First disclosure
- Reported to authority
- Company issued an update
Response
- Blocked the entry point
- Patched
- Forensic investigation
- More monitoring
- Service stopped
Fixed the vulnerability, blocked the unauthorized access, strengthened monitoring with outside experts
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Starts Publishing Official notice · Oct 1, 2026
- ASCII.jp News · Oct 2, 2026