SHINDO3

WEBLIFE

Personal dataup to7,425people

POSSIBLE LEAKPostal address / Date of birthUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Aug 18, 2026
Detected
Aug 17, 2026
Detection to disclosure
1 day
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name, Name reading (kana), Gender, Occupation, Date of birth
ContactAddress, Postal code, Email address, Phone, fax and mobile numbers
Account dataOther service management data

Not leaked

  • No leak of passwords or credit card information has been confirmed so far
  • No leak of passwords or credit card information has been confirmed so far

How many

  • Customers using the service through OEM partners up to 7,425 people

Who is affected

  • Customers using the service through OEM partners

Cause

Access-control flaw in the customer management system for OEM partners

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detected
  4. First disclosure
  5. Company issued an update
  6. Company issued an update

Response

  • Access review
  • Forensic investigation
  • Hotline

Fixed the access-control flaw, continued the investigation and set up a dedicated inquiry form

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources