SHINDO6

Tabiq

ID documents1.1Mpeople

EXPOSEDPassport images / Driver's licence imagesMisconfiguration · Contained

Open in the live monitor ▶
Disclosed
Jun 29, 2026
Detected
May 13, 2026
Detection to disclosure
47 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityUsers' face photos (image)
Communications & contentSignature images (image)
ID documentsImages of ID documents such as passports and driver's licenses (image), Images of ID documents such as passports and driver's licenses (image)

How many

  • Users whose ID document images and related data were accessible 1.1M people

Who is affected

  • Users (guests of lodging facilities)

Cause

Misconfiguration of the cloud storage (Amazon S3) used by the company

Timeline

  1. Exposure began
  2. Detected
  3. Exposure ended
  4. External access blocked
  5. Preliminary report to the PPC
  6. Final report to the PPC
  7. First disclosure
  8. Update noted by the July 2026 slice researcher

Response

  • Blocked the entry point
  • Access review
  • More monitoring
  • New detection
  • Vulnerability testing
  • Change process

Implemented IAM access controls; strengthened monitoring with CSPM and threat detection; ran vulnerability assessments; improved internal security review procedures

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources