SHINDO2
Tokyo Metropolitan University
Tokyo Metropolitan Public University Corporation
Personal records423records
POSSIBLE LEAKPostal address / Phone numberPhishing · Investigating
Open in the live monitor ▶- Disclosed
- Jan 13, 2026
- Detected
- Jan 7, 2026
- Detection to disclosure
- 6 days
- Leak
- Leak possible
- Type
- Phishing
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityName
ContactPhone number, Email address, Address
Employment & HREmployer
Communications & contentEmail correspondence history
How many
- Personal records 423 records
- Event applicants and survey respondents 180 records
- Admissions results records 249 records
Who is affected
- Event applicants and survey respondents
- Admissions applicants
Cause
A School of Business Administration faculty member had Google account credentials stolen by a phishing email from an overseas researcher's account
Timeline
- Phishing email received from an overseas researcher's account
- Found when recipients reported phishing emails disguised as document shares sent from the account
- Security NEXT report date
Response
- Notified individuals
Continuing to gather information; notified and apologized to affected people
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Jan 13, 2026