SHINDO4

OZmall

ozmall.co.jp

Personal dataup to442,779people

POSSIBLE LEAKEmail address / Postal addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 27, 2026
Detected
Sep 26, 2026
Detection to disclosure
1 day
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
7011701004273

What leaked

ContactEmail address, Address (prefecture only, some records)
IdentityFull name (some records)

How many

  • Members (up to 447,610 in the first report) up to 442,779 people

Who is affected

  • Members
  • Some former members

Cause

A vulnerability was exploited through a large volume of unauthorized access from overseas (technical details not disclosed)

Timeline

  1. Detected
  2. First disclosure
  3. Reported to authority
  4. Company issued an update

Response

  • Blocked the entry point
  • Patched
  • Forensic investigation
  • More monitoring
  • Service stopped

Fixed the vulnerability, blocked the unauthorized access, strengthened monitoring with outside experts

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources