SHINDO4

Yoshinoya / Hanamaru

Personal data5,366records

LEAK CONFIRMEDDate of birth / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 30, 2026
Detected
Sep 7, 2026
Detection to disclosure
23 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
2011501016151

What leaked

IdentityFull name (katakana), Date of birth, Gender, Occupation (some records)
ContactEmail address, Phone number, Address (some records)
CredentialsUsername, Encrypted passwords
Account dataAccess permissions

How many

  • Job applicants (Yoshinoya 4,998; Hanamaru 368) 5,366 records
  • Recruiter accounts 418 accounts

Who is affected

  • Job applicants
  • Recruiters (employees)

Cause

Unauthorized access to former contractor ApplyNow's recruitment management platform, exploiting a vulnerability in a data analysis tool. The data had remained there after the contract ended in June 2024

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detected
  4. Detected
  5. Reported to authority
  6. Detected
  7. First disclosure
  8. Notifications to affected people began

Response

  • Blocked the entry point
  • Patched
  • Password reset
  • Forensic investigation
  • Notified individuals

Blocked the intrusion route and fixed the vulnerability; investigation with outside experts and lawyers; asked users to change passwords; notifications to affected people from October 1

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Expect targeted phishing posing as HR or interview contacts
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  2. Put security requirements, audit rights and reporting deadlines in vendor contracts
  3. Data outlived the contract. Always get proof of deletion and set retention limits
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources