SHINDO2

TENTIAL

Personal data~110,000records

LEAK UNCLEARUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 28, 2026
Leak
Unknown
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

How many

  • Suspicious (phishing) emails sent ~110,000 records

Cause

A third party misused the access key of the company's email-sending service to send phishing emails that appeared to come from the company

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. First disclosure

Response

  • Revoked credentials
  • Blocked the entry point
  • Phishing warning

The abused credential was revoked and the sending route blocked. Customers warned about the suspicious emails

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources