SHINDO3

SoftBank Corp.

Personal data2,019records

LEAK CONFIRMEDPostal address / Date of birthSoftware defect · Closed (final report)

Open in the live monitor ▶
Disclosed
Jan 28, 2026
Detected
Jan 13, 2026
Detection to disclosure
15 days
Leak
Leak confirmed
Type
Software defect
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName, Date of birth
ContactAddress, Phone number
Transactions & activityContract details
Financial & paymentBilled amount
Communications & contentEmail sender addresses and mobile phone numbers

How many

  • Mis-displays when viewing contract or billing information 2,019 records
  • Mix-ups in sending and receiving carrier email 2,209 records

Who is affected

  • SoftBank and Y!mobile customers

Cause

A software bug in a proxy server introduced on 25 September 2025 mixed up data when several requests ran at once; a network setting change on 13 January 2026 made it frequent

Timeline

  1. Investigation started after a customer report
  2. Exposure began
  3. Exposure ended
  4. Security NEXT report date

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Never sit on a known defect. Test every change before production
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources