SHINDO3

UPSIDER Holdings, Inc.

Malware infectionSize not disclosed

LEAK UNCLEARCard numberInvestigating

Open in the live monitor ▶
Disclosed
Apr 10, 2026
Detected
Mar 31, 2026
Detection to disclosure
10 days
Leak
Unknown
Type
Malware infection
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentCustomer card data (numbers tokenized)
UnspecifiedPersonal and corporate data

Not leaked

  • Card PINs and security codes

Who is affected

  • Corporate customers

Cause

Unauthorized access through a malicious program planted in open-source software the company used

Timeline

  1. Intrusion began
  2. Notified by the cloud service provider
  3. Services stopped to prevent further damage
  4. First disclosure

Response

  • Service stopped
  • Forensic investigation

Completed the initial response; outside specialists to investigate; reported to the PPC and other authorities

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources