SHINDO2
Saga University
RansomwareSize not disclosed
LEAK UNCLEARRecovering
Open in the live monitor ▶- Disclosed
- Sep 25, 2026
- Detected
- Sep 24, 2026
- Detection to disclosure
- 1 day
- Leak
- Unknown
- Type
- Ransomware
- Status
- Recovering
- Security spend
- Not checked yet
- Compensation
- Not announced
Cause
Damage believed to be caused by ransomware on network-attached storage (NAS) used by administrative departments (entry route under investigation)
Timeline
- Detected
- Disconnected the device and stopped use of administrative terminals
- First disclosure
- Service restored
- Normal operations resumed
Response
- Blocked the entry point
- Service stopped
- Forensic investigation
Disconnected the affected device and suspended administrative terminals; investigating the intrusion route and scope and strengthening security
What you should do
- Check the company's notice to see if you're affected
Lessons for companies
- Offline backups with restore drills; segment the network
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Oct 1, 2026
- Security Measures Lab Researcher · Oct 2, 2026