From our other sites
The story
Travel agency HIS has announced the possible leak of passport information for 627 customers due to unauthorized access. According to Kyodo News, a long stretch of time passed between discovery and disclosure, and on the thread users pointed out that “it went undisclosed for about seven and a half months,” raising questions about the oddly timed announcement. Around the same period, leaks at several other companies — including Times Car, GMO, and Daiwa Securities — were also making headlines, sparking debate over why so many companies were disclosing breaches at the same time. Opinions split between those dismissing the small number of affected users as “pathetic” and those countering that a more narrowly targeted leak actually carries a higher risk of misuse.
HIS: Customer Passport Data Possibly Leaked — 627 People Affected, Unauthorized Access
Oct 7 (Wed), 15:43 JST
Kyodo News
Source: news.yahoo.co.jp / Original article here
What people said
Pretty pathetic. Is that really worth making news over?
Actually, the smaller the pool, the higher the odds of misuse.
If it were something huge like 6.6 million, it'd be more like lottery odds.
Re: #11-20
North Korea, Russia, and China: "Japan's cyber monitoring? Total pushover, lol"
.
The attacks started a few months back, and once everyone noticed and started checking, it just kept coming out.
I bet if they dig even deeper, way more will turn up.
Probably the pattern where they saw it blowing up in the news, did a proper internal audit, and realized "oh, we got breached too."
Same deal as that thing where, once 5ch is already in full-on uproar mode, it's the perfect moment to slip out bad news without anyone noticing.
I wonder what's happening?
Leaks are flying out at an insane rate lol
This is news about a leak that actually happened a while back.
It's basically a corporate play of "if we announce it now, it probably won't get much attention."
Do they notice because the data's been tampered with or something?
No idea, but I'd guess suspicious traces turn up in the access logs.
That might be true for the other recent leaks,
but HIS specifically "went undisclosed for about seven and a half months."
Feels like they used the current uproar as cover to sneak the announcement out.
It's basically like trying to prove a negative — impossible to confirm either way.
Unless the criminals themselves announce "we're using data stolen from Company X to commit crimes," there's no way to pin it down.
Especially now, with leaks happening everywhere, there's no way to narrow down which breach is actually to blame.
My Number card (Japan's national ID) data has probably already leaked too — people just haven't noticed yet.
I think they've noticed — they're just hiding it.
I just saw that Sompo Japan got hit too.
That's insane lmaooooo
Isn't the real issue that existing security *isn't* stopping this…?
Trend Micro is screwed—————
My tokens? If you want 'em, go ahead and take 'em… go look for them. I left every environment variable in this world sitting in public repos. (riffing on Gold Roger's famous "my treasure" line from One Piece)
"Hacking… will never end!!!" (riffing on Whitebeard's dying words from One Piece)
Way too slow.
They just timed it to get buried under all the other news — sneaky move from a shady company.
Apparently the investigation only wrapped up today.
Background and Key Points of Debate
Under Japan’s Act on the Protection of Personal Information, companies that discover a data breach are generally required to notify the relevant authority in two stages — an initial report and a final report — but there’s no firm deadline for public disclosure, and investigations often drag on. On the thread, users pointed out that “HIS went roughly seven and a half months without disclosing the breach,” fueling suspicion that the announcement was timed to slip by unnoticed. At the same time, some posters floated the idea that the wave of near-simultaneous disclosures from multiple companies is a chain reaction: once one breach made headlines, other firms re-audited their own systems and kept turning up previously undisclosed leaks. One easily misunderstood point: the fact that “only 627 people” were affected doesn’t necessarily mean the risk is low. The more narrowly targeted a leak is, the higher the odds that misuse actually hits the right target, so judging the severity of a breach by headcount alone is premature. Note that some posts in the original thread veered into personal attacks on specific politicians and slurs against political parties; those replies have been excluded from this article.
*This article is compiled from excerpts and summaries of the 5ch (News Flash+) thread “[Unauthorized Access] HIS: Customer Passport Data Possibly Leaked — 627 People Affected.”
Leave a Reply