SHINDO2

Post Office App (Japan Post)

Customer records69records

LEAK CONFIRMEDPostal address / Date of birthUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 29, 2026
Detected
Sep 25, 2026
Detection to disclosure
4 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
1010001112577

What leaked

IdentityFull name, Date of birth, Gender, Shipping label data (sender/recipient names, addresses, company names, phone numbers, email addresses, tracking numbers, item descriptions, scheduled delivery dates)
ContactAddress, Phone number, Email address, Shipping label data (sender/recipient names, addresses, company names, phone numbers, email addresses, tracking numbers, item descriptions, scheduled delivery dates), Shipping label data (sender/recipient names, addresses, company names, phone numbers, email addresses, tracking numbers, item descriptions, scheduled delivery dates), Shipping label data (sender/recipient names, addresses, company names, phone numbers, email addresses, tracking numbers, item descriptions, scheduled delivery dates)
Employment & HREmployer information
Family & private lifeFamily information
Communications & contentAddress book entries
Transactions & activityShipping label data (sender/recipient names, addresses, company names, phone numbers, email addresses, tracking numbers, item descriptions, scheduled delivery dates)
Business dataShipping label data (sender/recipient names, addresses, company names, phone numbers, email addresses, tracking numbers, item descriptions, scheduled delivery dates)

How many

  • Customer records 69 records
  • Affected individuals 19 people

Who is affected

  • Yu ID members
  • Post Office App users

Cause

Unauthorized access by a third party to the Post Office App (method not disclosed)

Timeline

  1. Detected
  2. Service suspended
  3. Service restored
  4. First disclosure
  5. Company issued an update

Response

  • Notified individuals
  • Service stopped

Emergency maintenance and investigation; service resumed after security measures were implemented; affected people notified individually in writing

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources