TOPPAN Mis-sends Data on 170,000 Sompo Japan Policyholders — 5ch: “Just Ban ZIP Files Already, lol”

From our other sites

The story

It was reported on September 30, 2026 that TOPPAN, during a data transfer job entrusted to it by Sompo Japan Insurance, made a drag-and-drop error and sent the personal information of roughly 170,000 policyholders to the wrong company instead of the intended recipient. On 5ch, discussion centered on whether “operational mistake” was really a fair description — many argued the true cause was a failure to double-check before sending — while others called for scrapping manual-work-reliant processes altogether, sparking debate over how to genuinely prevent a repeat.

Published

September 30, 2026, 8:44 AM

Author

Source: itmedia.co.jp / Original article here

What people said

2AnonymousSep 30, 2026 13:12
Lol. When something feels off, you'd better actually stop and check it.
3AnonymousSep 30, 2026 13:19
First things first: ban ZIP files, lol
5AnonymousSep 30, 2026 13:36
You could've just run `unzip -l` to see the file list before sending…
7AnonymousSep 30, 2026 13:46
Yeah, this proves you really shouldn't let people work outside a CLI (command-line interface).
25AnonymousSep 30, 2026 14:55
Re: #7
It's the same problem even with manual work.
And with a CLI, there's the horror of your `history` (command log) coming back to bite you.
8AnonymousSep 30, 2026 13:50
Come on…
Fine if it's your personal mouse, but if you're using one for work and it's double-clicking on its own (chattering), replace it immediately.
9AnonymousSep 30, 2026 13:56
This particular case was a dumb mistake, but yeah —
drag-and-drop really is
prone to slipping off target.
11AnonymousSep 30, 2026 14:01
TOPPAN, probably: "Oh, Times leaked 6 million records? Guess we'll quietly drop our own 170,000-person leak while everyone's distracted!"
12AnonymousSep 30, 2026 14:01
Work like this should always be done with a written procedure, a second checker present, and evidence like screenshots being logged along the way.
Even then, mistakes still happen sometimes, though.
13AnonymousSep 30, 2026 14:21
Guess the other insurance companies are saying "thanks" (for making them look good by comparison).
14AnonymousSep 30, 2026 14:23
Between this and that earlier business where they brushed off the Agent Orange (defoliant) issue, the insurance industry's ethics are completely falling apart.
15AnonymousSep 30, 2026 14:23
With cyber incidents, they hide the real details so as not to give copycat criminals any ideas.
There's no way the customer database is actually connected to the open internet… right?
16AnonymousSep 30, 2026 14:33
Drag-and-drop is hard to verify, yeah.
If the PC's specs are garbage, it can stutter and the drag can release without you noticing, moving the file somewhere you never meant it to go.
19AnonymousSep 30, 2026 14:43
That's not quite accurate.
It shouldn't be framed as "due to a drag-and-drop mistake" —
it should be "a drag-and-drop mistake" AND "a failure to double-check."
Sending straight off a drag-and-drop without any verification doesn't add up, so
ultimately the main cause was failing to check before sending.
It's obvious they're trying to hide a bigger failure and make it look
like a minor operational slip, lol
26AnonymousSep 30, 2026 14:55
Re: #19
Good point, exactly right.
This happens a lot —
the media pulling its punches out of deference.
21AnonymousSep 30, 2026 14:47
At the end of the day, a human is the one who screws it up, so no matter how tight you make security it's useless, useless, USELESS!
All you can really do is encrypt it and store it so it's only ever handled on your own company's machines — basically keep it locked down "hell-safe" (a jokey, garbled riff on "fail-safe").
22AnonymousSep 30, 2026 14:47
Might be better to split responsibility by client company,
or just use separate PCs for each.
23AnonymousSep 30, 2026 14:54
Clackety-clackety-clack… *ta-daa!*

You're supposed to double-check BEFORE the "ta-daa," lol
24AnonymousSep 30, 2026 14:54
Happens all the time.
They always say this kind of mistake will be "corrected," but is there an actual fix?
27AnonymousSep 30, 2026 15:00
Re: #24
Cut out the manual work.
Cut out single-person processing.
It's bad enough that the vendor is treating 170,000 files like some ad-hoc, non-standardized task.
They say they're moving it to ServiceNow or AI, sure — but on a totally unrelated note, ServiceNow's McDermott was actually at Trump's gathering of tech-industry bigwigs yesterday, showing up flashy enough to look like a rock star. He's tight with that guy in the leather jacket (Jensen Huang) — they show up at each other's annual events, and it's basically a running bit that the two of them, Jensen and McDermott, always end up together in a Bloomberg interview.

Okay, that went completely off-topic.
33AnonymousSep 30, 2026 15:36
Re: #24
Sending data outside the company is a pretty critical action,
so it should require sign-off from multiple people.
28AnonymousSep 30, 2026 15:02
Honestly the file management itself is the real problem here, isn't it?
How much are they even getting paid for this contract?
Just build a proper system for it.
29AnonymousSep 30, 2026 15:04
If you're sending data on 170,000 people, shouldn't it need approval at the level of, like, a manager pressing a button?
Though the manager's probably just as careless,
given they let the workflow get this sloppy in the first place.
30AnonymousSep 30, 2026 15:07
For data entrusted to you by other people, there should be logs of
who accessed it,
who copied it,
who updated it —
right?
There's zero recognition that the actual owner of that data is the person it's about.
And that goes for the insurance company that outsourced the work too.

Even with My Number (Japan's national ID) data,
Japan doesn't operate on the idea that the data belongs to the individual it describes.
Everyone who has accessed that data —
meaning everyone who's
looked at it, touched it —
should be made known,
every single one,
to the person the data is about.
That's what real privacy actually means.

Bet you don't get it, do you?
31AnonymousSep 30, 2026 15:19
Very fitting for a country that lost the IT war — gotta love it.
38AnonymousSep 30, 2026 16:24
Well, I'm sure they've signed confidentiality agreements with every company involved, so contractually it shouldn't leak.
Contractually, anyway.
39AnonymousSep 30, 2026 16:37
Even if you fat-fingered the operation, you'd normally double-check before hitting send, right?
Why'd they just let it go through as-is?
40AnonymousSep 30, 2026 16:39
Why not encrypt it before sending, then contact the recipient separately afterward to send the decryption key?

I think banks used to do something like that back in the day.
41AnonymousSep 30, 2026 16:43
New hires pull this all the time.
Companies really should separate the internal LAN from the external LAN with a two-PC setup in the first place —
but since that's not happening, misdeliveries like this are bound to keep occurring.

Background and Key Points

TOPPAN has been shifting its business from printing toward information and data-processing services, and handles large volumes of personal data on behalf of client companies such as insurers. In this incident, the company was sending policyholder data via drag-and-drop as part of that work when the file was dropped onto the wrong destination, leaking data on roughly 170,000 people. Where opinions on the thread split was over how fair the “operational mistake” framing really was: comment #19 argued that the true cause was a failure to check before sending, and that calling it a mere “operational mistake” downplays where the responsibility actually lies. Many commenters also called for mandatory multi-person approval, automated system checks, and eliminating manual handling altogether — the shared view being that treating this as simple human error won’t actually stop it from happening again. Notably, this comes around the same time as a report that car-share giant Times leaked roughly 6 million records, putting renewed scrutiny on how outsourced work handling large volumes of personal data gets checked.

*This article is excerpted and summarized from the 5ch (Business News+) thread “TOPPAN Mistakenly Sends Data on 170,000 Sompo Japan Policyholders to Another Company Due to a Drag-and-Drop Error.”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *