SHINDO3

Tokyo Metropolitan Government

Personal data565people

EXPOSEDPostal address / Phone numberMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
May 27, 2026
Detected
May 1, 2026
Detection to disclosure
26 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress, Phone number
Financial & paymentLoan amount

How many

  • Total (437 borrowers, 128 guarantors) 565 people
  • Loan recipients 437 people
  • Joint guarantors 128 people

Who is affected

  • Recipients of nursing student loans
  • Joint guarantors

Cause

A system configuration flaw meant certain operations displayed other facilities' data beyond the user's access rights

Timeline

  1. System went live
  2. Found through a report from a facility
  3. Announced

Response

  • Service stopped
  • Config review
  • Notified individuals

Suspended the system, investigated the cause and reviewed the whole system. Notified and apologized to affected people and facilities

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources