SHINDO3

Tombow Inryo

RansomwareSize not disclosed

POSSIBLE LEAKBank account / Company nameRecovering

Open in the live monitor ▶
Disclosed
Jan 22, 2026
Detected
Jan 20, 2026
Detection to disclosure
2 days
Leak
Leak possible
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentSuppliers' bank account details registered in the accounting software
Business dataInformation about business partners

Who is affected

  • Suppliers

Cause

Servers were hit by ransomware; the intrusion route is not stated in the article

Timeline

  1. Intrusion began
  2. Possible leak of supplier bank account details found
  3. Investigating together with the police
  4. First disclosure

Response

  • Forensic investigation

Investigating the damage with outside specialists and the police, and restoring systems

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources