SHINDO3
UPSIDER Holdings, Inc.
Malware infectionSize not disclosed
LEAK UNCLEARCard numberInvestigating
Open in the live monitor ▶- Disclosed
- Apr 10, 2026
- Detected
- Mar 31, 2026
- Detection to disclosure
- 10 days
- Leak
- Unknown
- Type
- Malware infection
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
Financial & paymentCustomer card data (numbers tokenized)
UnspecifiedPersonal and corporate data
Not leaked
- Card PINs and security codes
Who is affected
- Corporate customers
Cause
Unauthorized access through a malicious program planted in open-source software the company used
Timeline
- Intrusion began
- Notified by the cloud service provider
- Services stopped to prevent further damage
- First disclosure
Response
- Service stopped
- Forensic investigation
Completed the initial response; outside specialists to investigate; reported to the PPC and other authorities
What you should do
- Call your card issuer, reissue the card, check statements daily and turn on alerts
- Check the company's notice to see if you're affected
Lessons for companies
- Put security requirements, audit rights and reporting deadlines in vendor contracts
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Cybersecurity-jp.com News · Apr 14, 2026