SHINDO2

Sekaimon

Unauthorized accessSize not disclosed

POSSIBLE LEAKPostal address / Date of birthInvestigating

Open in the live monitor ▶
Disclosed
Feb 20, 2026
Detected
Feb 10, 2026 13:00 JST
Detection to disclosure
10 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName, Date of birth, Gender
ContactAddress, Phone number, Email address
Financial & paymentLast four digits of credit card, Card expiry date

Not leaked

  • Passwords were stored hashed

Who is affected

  • Sekaimon members

Cause

A third party exploited a vulnerability and accessed part of the database on the server

Timeline

  1. Site suspended and the vulnerable route blocked that evening
  2. Third-party access to the database detected
  3. Security NEXT report date

Response

  • Service stopped
  • Blocked the entry point
  • Forensic investigation

Suspended the site, blocked the exploited route, investigating

What you should do

  1. Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources