SHINDO1

Mori no Dengonban Yururu (NPO)

Personal data80records

LEAK CONFIRMEDEmail addressMisdelivery · Closed (final report)

Open in the live monitor ▶
Disclosed
Sep 3, 2026
Detected
Sep 3, 2026
Detection to disclosure
Same day
Leak
Leak confirmed
Type
Misdelivery
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmail address

How many

  • Email addresses of related groups and others 80 records

Who is affected

  • Related groups and others

Cause

A bulk email was sent with the addresses in the To field instead of Bcc

Timeline

  1. Email sent to 80 recipients
  2. Detected
  3. Miyagi Prefecture press release

Response

  • Data deleted
  • Notified individuals

Apologised to recipients and asked them to delete the email; the prefecture says it will check that preventive measures are carried out

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Use DLP: recipient checks, send delay, automatic attachment protection
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources