SHINDO2

Institute of Science Tokyo

Unauthorized accessSize not disclosed

POSSIBLE LEAKPostal address / Full nameInvestigating

Open in the live monitor ▶
Disclosed
Sep 7, 2026
Detected
Aug 28, 2026
Detection to disclosure
10 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress, Email address

Not leaked

  • At this time, no leak of information about the university hospital's patients has been confirmed

Who is affected

  • Students
  • Faculty and staff
  • Former staff

Cause

Unauthorized third-party access to the university's information infrastructure (method not disclosed)

Timeline

  1. Information security incident response headquarters set up on August 28
  2. First disclosure

Response

  • Forensic investigation
  • Governance / committee
  • Phishing warning

Took steps to prevent further damage, set up an incident response headquarters and is investigating with outside help. Warned about impersonation emails

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources