SHINDO1

Thinca (Kaikura)

kaiwa.cloud · thinca.co.jp · carconnect.jp

Personal data0records

NO LEAK FOUNDUnauthorized access · Closed (final report)

Open in the live monitor ▶
Disclosed
Aug 28, 2026
Detected
Aug 24, 2026
Detection to disclosure
4 days
Leak
No leak
Type
Unauthorized access
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced
Corporate number
5010001158006

Not leaked

  • Full name (no trace of a leak)
  • Company name (no trace of a leak)
  • Email address (no trace of a leak)
  • Phone number (no trace of a leak)

How many

  • Personal data leaked (no trace found) 0 records

Who is affected

  • People who applied for seminars and webinars
  • People who made inquiries

Cause

A vulnerability in a plugin of the site's CMS was exploited; a third party broke into the server and planted malicious programs, one of which made it technically possible to pull information from the server

Timeline

  1. Detected
  2. Detected
  3. Service suspended
  4. Notice of unauthorized access to the company's service sites, dated August 28, 2026
  5. Preliminary report
  6. Sites reopened in stages from August 28 to September 1
  7. Announced that all sites were back online
  8. Consulted the local police station
  9. Final report
  10. Final report

Response

  • Service stopped
  • Forensic investigation
  • Revoked credentials
  • New detection
  • Data deleted
  • Governance / committee

Paused access to the four sites and moved them to a verified environment. Investigation by an outside specialist firm. Rebuilt the server environment, renewed credentials, added protection and detection, stopped holding personal data on the sites, and changed the team responsible for operations. Plans to move to a SaaS CMS

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources