SHINDO3

Space Co., Ltd.

Suspicious emails sent2,329records

POSSIBLE LEAKMessages / email bodies / Email addressPhishing · Contained

Open in the live monitor ▶
Disclosed
Jun 29, 2026
Detected
Jun 15, 2026
Detection to disclosure
14 days
Leak
Leak possible
Type
Phishing
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmail addresses (recipients)
Communications & contentInformation in the email account

How many

  • Suspicious emails sent 2,329 records

Who is affected

  • Recipients including business partners

Cause

An employee entered their email address and password on a fake site linked from a phishing email posing as a business partner

Timeline

  1. Employee received a phishing email posing as a business partner and entered credentials
  2. Confirmed 2,329 suspicious emails had been sent
  3. First disclosure

Response

  • Revoked credentials
  • Password reset
  • MFA
  • Staff training
  • More monitoring
  • Forensic investigation

Disabled the account, changed passwords, suspended external services, rolled out multi-factor authentication company-wide, reset all passwords, and strengthened staff training and monitoring. Investigation and reports to authorities began June 17

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources