SHINDO5

YCC Information System Co., Ltd.

Personal dataat least700,000records

POSSIBLE LEAKHealth insurance card / Health / medical / treatmentRansomware · Recovering

Open in the live monitor ▶
Disclosed
Apr 3, 2026
Detected
Apr 2, 2026
Detection to disclosure
1 day
Leak
Leak possible
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactAddress, Phone number
ID documentsMy Number (Yamagata City HR and payroll system), Insurer numbers
Special-care dataHealth check records and student health data
Financial & paymentBank account data (Takahata Town), Credit card transaction data (Yamagata Shimbun)

How many

  • Total records announced by client organizations at least 700,000 records
  • Yamagata City ~558,387 records
  • Yamagata Kotsu 121,880 records
  • Yamagata University 80,091 records
  • Yamagata Prefecture ~26,800 records
  • Shonai Town 12,996 records
  • Takahata Town 2,354 people

Who is affected

  • Residents (Yamagata City, Shonai Town, Takahata Town, etc.)
  • Staff (Yamagata City payroll; Yamagata Prefecture staff health data)
  • Yamagata University students
  • Yamagata Kotsu customers

Cause

Ransomware attack. The intrusion route had not been identified and the investigation continued

Timeline

  1. Attack detected in the early morning
  2. First disclosure
  3. Confirmed as ransomware
  4. Possible data leak confirmed
  5. Yamagata City announced its affected counts
  6. Yamagata Prefecture, Yamagata Kotsu, Shonai Town and Satte City announced
  7. Yamagata University announced

Response

  • Forensic investigation
  • Notified individuals

Outside investigation of the scope; each client organization informed the affected people

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  4. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Watch for unexpected mail or invoices; your address is hard to change
  7. Expect targeted phishing posing as HR or interview contacts
  8. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources