SHINDO2

Tokyo Metropolitan University

Personal records423records

POSSIBLE LEAKPostal address / Phone numberPhishing · Investigating

Open in the live monitor ▶
Disclosed
Jan 13, 2026
Detected
Jan 7, 2026
Detection to disclosure
6 days
Leak
Leak possible
Type
Phishing
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName
ContactPhone number, Email address, Address
Employment & HREmployer
Communications & contentEmail correspondence history

How many

  • Personal records 423 records
  • Event applicants and survey respondents 180 records
  • Admissions results records 249 records

Who is affected

  • Event applicants and survey respondents
  • Admissions applicants

Cause

A School of Business Administration faculty member had Google account credentials stolen by a phishing email from an overseas researcher's account

Timeline

  1. Phishing email received from an overseas researcher's account
  2. Found when recipients reported phishing emails disguised as document shares sent from the account
  3. Security NEXT report date

Response

  • Notified individuals

Continuing to gather information; notified and apologized to affected people

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources