SHINDO4

VOISING

Affected records~170,000records

LEAK CONFIRMEDPostal address / Date of birthUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Aug 18, 2026
Detected
Aug 16, 2026 23:55 JST
Detection to disclosure
2 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
9010401170416

What leaked

IdentityFull name, Date of birth, Gender, User name
ContactAddress, Phone number, Email address
Transactions & activityPurchase history
Financial & paymentPayment amount records
Account dataService subscription status, Selected favorite talent, VOISING ID

Not leaked

  • Credit card number, expiry date and security code
  • Credit card number, expiry date and security code
  • Credit card number, expiry date and security code
  • Payment data such as credit card numbers and bank account details, and customers' password data, were never held in the system that was accessed, so they did not leak
  • No customer account passwords leaked at all.

How many

  • Affected records ~170,000 records
  • Records that may have been published on a particular website ~50,000 records
  • Records confirmed as posted on social media 10 records

Who is affected

  • Members of VOISING ID, fan clubs and related services
  • Online store customers

Cause

A vulnerability in the BI (business intelligence) tool the company used was exploited. The unauthorized access happened before the fix was applied, and data stored in the tool was illegally downloaded

Timeline

  1. Intrusion began
  2. Data was illegally downloaded on August 16 between 18:47 and 20:21
  3. BI tool shut down
  4. Intrusion stopped
  5. First disclosure
  6. Emails sent to affected people in turn
  7. Second report: response status
  8. Preliminary report already filed with the PPC by the second report
  9. Already reported to the local police station by the second report
  10. Individual contact with the 10 people whose data was posted on social media
  11. Leaked data found posted on social media (10 records)
  12. Approx. 50,000 records may have been published on a particular website
  13. Third report: some data found published externally
  14. Fourth report: investigation results and prevention measures

Response

  • Blocked the entry point
  • Patched
  • Revoked credentials
  • Service stopped
  • Forensic investigation
  • Notified individuals
  • Phishing warning
  • Governance / committee
  • Config review

Shut down the BI tool and disconnected it from the network, discarded the compromised environment, applied the vulnerability fix, invalidated or changed all passwords and access keys, investigated with an outside specialist organization, notified affected people by email, and reported to the police and the PPC. Prevention measures: a system for receiving vulnerability information with response deadlines by severity, a clearly named decision owner, and a redesign so internal tools are not exposed directly to the internet

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources