SHINDO5

Zetton Co., Ltd.

Personal data records18,553records

POSSIBLE LEAKHealth / medical / treatment / Postal addressInfostealer · Contained

Open in the live monitor ▶
Disclosed
Mar 27, 2026
Detected
Feb 18, 2026
Detection to disclosure
37 days
Leak
Leak possible
Type
Infostealer
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress, Phone number, Email address
Special-care dataAllergy information
Transactions & activityReservation details, etc.

Not leaked

  • No credit card or My Number data included

How many

  • Personal data records 18,553 records

Who is affected

  • Restaurant customers (June 2018 - September 2025)
  • Party customers and attendees
  • Business partners
  • Employees who used the old email system

Cause

One PC was infected with malware; credentials of two email accounts were stolen and used to log in

Timeline

  1. Intrusion began
  2. Unauthorized logins began
  3. An employee noticed suspicious emails
  4. First disclosure

Response

  • Blocked the entry point
  • Password reset
  • Revoked credentials
  • Forensic investigation
  • Notified individuals

Isolated the infected PC; reset passwords for all old email system users; terminated the accounts; digital forensics by outside specialists; notified affected people by email or post

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Expect targeted phishing posing as HR or interview contacts
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Never sit on a known defect. Test every change before production
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources