SHINDO3
WEBLIFE
WebLife Inc.
Personal dataup to7,425people
POSSIBLE LEAKPostal address / Date of birthUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Aug 18, 2026
- Detected
- Aug 17, 2026
- Detection to disclosure
- 1 day
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Measures, no amount
- Compensation
- Not announced
What leaked
IdentityFull name, Name reading (kana), Gender, Occupation, Date of birth
ContactAddress, Postal code, Email address, Phone, fax and mobile numbers
Account dataOther service management data
Not leaked
- No leak of passwords or credit card information has been confirmed so far
- No leak of passwords or credit card information has been confirmed so far
How many
- Customers using the service through OEM partners up to 7,425 people
Who is affected
- Customers using the service through OEM partners
Cause
Access-control flaw in the customer management system for OEM partners
Timeline
- Intrusion began
- Intrusion stopped
- Detected
- First disclosure
- Company issued an update
- Company issued an update
Response
- Access review
- Forensic investigation
- Hotline
Fixed the access-control flaw, continued the investigation and set up a dedicated inquiry form
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- WebLife Inc. (follow-up report) Official notice · Aug 26, 2026
- Cybersecurity-jp.com News · Aug 24, 2026
- Security NEXT News · Sep 4, 2026