SHINDO5

Zynas Corporation

Personal data23,585people

POSSIBLE LEAKDisability / Health / medical / treatmentUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Mar 26, 2026
Detected
Jan 29, 2026
Detection to disclosure
56 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

Employment & HREmployee code
Communications & contentPersonal data in interview and onboarding documents
Special-care dataDisability status, Medical history
Family & private lifeFamily information

How many

  • Joyfull employees, job applicants and related persons 23,585 people
  • Of which health history etc. was included 2,397 people
  • Of which family information was included 1,189 people

Who is affected

  • Joyfull employees
  • Job applicants
  • Related persons (household members)

Cause

Unauthorized access by a cyberattack on a server prepared for handing data to a subcontractor

Timeline

  1. Unauthorized access to a server for handing data to a subcontractor, and partial deletion of the database, were found
  2. First disclosure

Response

  • Notified individuals
  • Hotline

Took emergency steps, informed Joyfull by phone and reported to the PPC. Set up a dedicated helpline

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources