SHINDO4

The Life Insurance Association of Japan

System users~37,000records

EXPOSEDPostal address / Phone numberSoftware defect · Investigating

Open in the live monitor ▶
Disclosed
Jul 29, 2026
Leak
Exposed, access unknown
Type
Software defect
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress, Phone number, Email address

How many

  • System users ~37,000 records

Who is affected

  • Users of the life insurance policy lookup service

Cause

Because of a vulnerability, users' personal information could be viewed from outside by performing certain operations (cause under investigation)

Timeline

  1. First disclosure

Response

  • Service stopped
  • Forensic investigation
  • Notified individuals

Web applications suspended until safety is confirmed; paper applications accepted instead. Investigation by outside experts started. Affected users to be notified

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources