SHINDO4

Shueisha HAPPY PLUS COMMUNITY

Bloggers2,835people

LEAK CONFIRMEDPostal address / Date of birthUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 28, 2026
Detected
Sep 9, 2026 14:53 JST
Detection to disclosure
19 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
5010001018556

What leaked

IdentityFull name, Date of birth, Gender, Occupation, Profile image (image), Physical characteristics
ContactEmail address, Address, Phone number
Account dataSocial media accounts, Follower count
Family & private lifeMarital status, Whether they have children

How many

  • Bloggers 2,835 people

Who is affected

  • Bloggers

Cause

An attack targeting API credentials, caused by a misconfiguration of the CMS in use. Unauthorized privileged accounts were created

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Intrusion began
  4. Detected
  5. Intrusion stopped
  6. Individuals notified
  7. First disclosure

Response

  • Forensic investigation
  • New detection
  • Config review
  • Data deleted

Deleted the unauthorized accounts, changed system settings, strengthened intrusion detection, outside forensic investigation

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources