SHINDO2

Rakusai Shingaku Kyoshitsu / Shingakukan

Personal data13people

POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Recovering

Open in the live monitor ▶
Disclosed
Sep 4, 2026
Detected
Aug 24, 2026
Detection to disclosure
11 days
Leak
Leak possible
Type
Unauthorized access
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Gender, Age
Account dataUniversity name, Stated preferences
ContactAddress, Phone number, Email address

How many

  • Job applicants and employees 13 people

Who is affected

  • Job applicants
  • 3 employees

Cause

A vulnerability in a third-party software plugin was exploited and a malicious program was placed on the server

Timeline

  1. Malicious program found on the server
  2. First disclosure

Response

  • Patched
  • Notified individuals

Security fixes applied and sites being restored in turn; reviewing the security set-up and personal data management. Affected people contacted individually by email

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources