SHINDO4

Ryomo Systems

Personal data~136,049records

POSSIBLE LEAKPassword / Postal addressRansomware · Investigating

Open in the live monitor ▶
Disclosed
Aug 15, 2026
Detected
Aug 14, 2026
Detection to disclosure
1 day
Leak
Leak possible
Type
Ransomware
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced
Corporate number
2070001016771

What leaked

IdentityFull name, Name reading (furigana)
ContactAddress, Phone number
Account dataBilling number, customer number, School name, grade
Device & networkGas meter number
Transactions & activityGas consumption
Financial & paymentGas charges
CredentialsAccount name, Password

Not leaked

  • Bank account and credit card information are not included (Daito Gas)
  • Bank account numbers and credit card information are not included (Nabari Kintetsu Gas, Shingu Gas)

How many

  • Sum of the counts published by four client organizations (Daito Gas approx. 124,000; Nabari Kintetsu Gas approx. 6,800; Isesaki City 3,789; Shingu Gas approx. 1,460). Other clients have not published counts ~136,049 records
  • Daito Gas customers ~124,000 records
  • Nabari Kintetsu Gas propane customers ~6,800 records
  • Student accounts at Isesaki municipal schools 3,789 records
  • Shingu Gas customers ~1,460 records

Who is affected

  • Customers of gas utilities
  • Students of Isesaki municipal elementary and junior high schools and Yotsuba Gakuen

Cause

Ransomware attack on Ryomo Systems' internal network (file server). Entry was through misuse of a VPN account (per Security Measures Lab's summary of the company's third report; how the account was obtained has not been disclosed). Files of customer information handled in past work for client companies had remained on the internal network (per Daito Gas)

Timeline

  1. Summary of Ryomo Systems' third report (Security Measures Lab)
  2. Detected
  3. Contained
  4. First disclosure
  5. Listed on a leak site (Ryomo Systems has not named the attacker)
  6. Third report: ransomware attack and possible leak of client customer data announced
  7. Daito Gas, Isesaki City, Nagano Toshi Gas and Echigo Tennen Gas announced
  8. Nabari Kintetsu Gas, Shingu Gas and Daiwa Gas announced

Response

  • Blocked the entry point
  • Forensic investigation
  • Hotline
  • Notified individuals
  • Phishing warning

Network disconnected; forensic investigation by an outside specialist organization (from August 15); reported to client organizations (September 24); dedicated call center (0120-998-970, weekdays 9:00-17:00). Each client organization is contacting affected people individually and warning about suspicious contacts

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Data outlived the contract. Always get proof of deletion and set retention limits
  3. Offline backups with restore drills; segment the network
  4. Don't keep ID or bank data: delete after checks or use a KYC provider
  5. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  6. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources