SHINDO4

Yellow Hat

Membersup to1.8Mpeople

POSSIBLE LEAKPhone number / Full nameUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Aug 28, 2026
Detected
Aug 18, 2026
Detection to disclosure
10 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced
Corporate number
1010001126172

What leaked

IdentityFull name
ContactPhone number, Email address
Account dataMember number

Not leaked

  • Credit card information
  • Login passwords

How many

  • Members up to 1.8M people

Who is affected

  • Members

Cause

Attack on the web service-booking system using a malicious program

Timeline

  1. Detected
  2. First disclosure

Response

  • Blocked the entry point
  • Notified individuals

Cut external connections and improved system security. Affected people notified by email, SMS, phone or letter. Consulted the police and reported to the PPC

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources