Skip to content
>_ITDITDWeb Security Platform

Security Guides

What may have leaked is a list of medical professionals — what Medica Shuppan readers, authors and small publishers should do after the ransomware attack

Japanese medical and nursing publisher Medica Shuppan was hit by ransomware, putting data of about 641,000 people (may include duplicates) — readers, authors, partners and staff — at risk of leaking. From the company's notices: what to do, and lessons for small publishers.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 18 min read

Who this is for: nurses, medical staff, teachers and students who have used Medica Shuppan's books, journals, seminars or digital services in Japan; authors and lecturers who worked with the company; staff at hospitals, facilities and organizations that outsourced work to it; and small publishers and online shops that hold customer lists. This article is based on Medica Shuppan Co., Ltd.'s official notices and does not cover attack techniques.

What affected people should do now

1

Check whether you are affected — not everyone will get a notice

The company says it is contacting people who were or may have been affected individually, in stages. It also says that where direct notice is difficult, publication on its website takes its place. Medica ID users, buyers of its books and journals, seminar attendees, authors and lecturers, people at hospitals, facilities and organizations that outsourced work to it, and its employees and job applicants may be in scope even without a notice. To check, contact the Medica Shuppan customer center (0120-276-115 or 06-6398-5008 in Japan, 9:00–17:00, closed weekends and holidays). Use the number from the company's official website, not one written in an email.

2

Don't open links in emails about a 'data leak notice' or 'password reset'

On May 1, the company warned that emails impersonating it had been seen. They say things like "there was unauthorized access", "your personal data may have leaked" or "you need to reset your password", and lead to a page asking you to enter personal information. The company says it never asks for personal or confidential information to be entered or confirmed by email, and that personal information can only be entered on its official site. Even when the sender field shows an address on the company's own domain, the company says the emails were not sent by it. The sender field is not proof of anything (see What is phishing?).

3

Notice when the 'leaked items' contradict the real notices

The sample fake email the company published listed login passwords and part of credit card data among the information that may have leaked. The real notices say the opposite: Medica ID passwords are managed separately and could not have leaked, and its online sales system does not hold credit card data. An email that lists "leaked items" contradicting the official notices and rushes you into a procedure is reason enough for suspicion.

4

Verify messages about study materials, seminars, societies or credits with the organizer

When a list of medical professionals is at risk, fake messages need not be "leak notices". Everyday pretexts for healthcare workers are plausible — subscription renewals, online seminar invitations, academic society registration or training credit (points) procedures, invoices for study materials (this site's assessment). For these too, don't use the link or the phone number in the message; check through the organizer's official site that you open yourself, or through the relevant department at your workplace. If it arrived at your work address, share it with your hospital's or facility's IT staff so the same attempt can be stopped for colleagues.

5

Authors and lecturers: watch for the message that comes after the account number, and turn on alerts

Author and contractor data includes bank account numbers. A major Japanese bank warns that if a third party learns your PIN in addition to your account number, it can lead to unauthorized withdrawals via online banking, and says it never asks for a PIN over the phone or has you enter it through automated voice guidance. The Japanese Bankers Association likewise says it never asks for PINs or passwords. Do not respond to messages that, under the name of "confirming the account for your manuscript fee" or "processing your honorarium", ask for a PIN, online banking ID and password or a one-time password. Turn on transaction alerts in online banking or your bank's app, and contact your bank if you see a transaction you don't recognize.

6

If you registered your My Number, you can consult your municipality

My Numbers are included only for authors and contractors who registered them. A My Number normally never changes, but under Article 7(2) of the My Number Act, when it is found that the number has leaked and may be used improperly, the mayor can assign a new one, for example at your request. First confirm with the company's desk whether your data is in scope, then consult the municipality where you are registered as a resident if needed.

7

End password reuse, and know the public help desks

Medica ID passwords are said not to be at risk, but the company recommends changing them regularly. If you use the same password elsewhere, change it (see choosing a password manager). In Japan, fake emails can be forwarded to the Council of Anti-Phishing Japan; technical worries such as having entered information or a device you are unsure about can go to the IPA Information Security Safety Consultation Desk (03-5978-7509, 10:00–17:00, closed weekends, holidays and New Year); and fraud or concerns about it to the police consultation line #9110.

What happened (from Medica Shuppan's notices)

The company published several notices between March 13 and May 13, 2026. Everything below is as stated in the company's official notices. Counts and status in this article follow the latest report, of May 13.

  1. Mar 13, 2026

    A system failure was detected in the early hours, and the affected servers were physically disconnected from the internal network. The same day, the company posted notices of an internal system problem and the suspension of order taking, shipping and inquiry handling.
  2. By Mar 14

    The police were notified and consulted, and a report was made to the Personal Information Protection Commission.
  3. Mar 17

    The company announced the cause was a ransomware attack. It wrote that some personal data of customers, business partners, applicants and employees, and some business information, "had been confirmed to have leaked outside", and that it was announcing publicly first because it could not even access its list of contacts. It said card data did not leak because its system does not hold it.
  4. Mar 25 (2nd report)

    Affected servers were isolated and devices confirmed safe were restored in turn. All websites and digital products were confirmed safe. The number of records leaked was not yet determined.
  5. Apr 9 (3rd report)

    As of 15:00 on April 8, personal data that may have leaked was put at 772,000 records in total (may be double-counted), with the data items listed. Many services resumed.
  6. May 1

    The company warned of fake emails impersonating it.
  7. May 13

    The outside forensic investigation was complete, and a final report had been submitted to the Personal Information Protection Commission on May 11. The company said it treats data of about 641,000 people (may include duplicates) as at risk of leakage.
  8. May 19

    Periodical publication delays were resolved.
~641,000
People whose data is at risk of leakage (may include duplicates; May 13)
772,000 → revised
Record count in the Apr 9 third report, revised after further review
Not held
Credit card data (by design of the online sales system)
None confirmed
Secondary harm believed to stem from the incident (as of May 12)
Data at risk (from the Apr 9 third report and the May 13 investigation report)
Medica ID users
Medica ID, name, email address. Where registered: prefecture, address, phone number
General customers
Name, contact details (workplace or home address, phone and fax numbers)
Authors and outside contractors
Name, contact details, job title, email address, bank account number, images provided as manuscripts, etc. Where registered: My Number
Data entrusted by client companies, facilities and organizations
Name, contact details, job title, email address, IDs, passwords, passports, residence cards, health checkup results, bank accounts, etc.
Employees and applicants
Employees: name, date of birth, address, department, performance evaluations, résumé contents, etc. Applicants: application documents, résumé contents, etc.
Categories (May 13)
Customers including Medica ID users; staff of hospitals and medical facilities; people at schools and other educational institutions; people at academic society secretariats and other organizations; authors, lecturers and other outside collaborators; registrants of its staffing business and similar; contacts at business partners; employees and job applicants
Said not to have leaked
Credit card data (not held). Medica ID passwords (managed separately)
Investigation result
No definitive evidence directly showing data was taken out; possibility not completely ruled out based on several traces, so treated as "at risk of leakage"
Starting point per the company
A third party entered the internal network using legitimate account credentials. How the credentials leaked has not been identified

How to read it: 'confirmed to have leaked' on March 17 vs 'at risk of leakage' on May 13

The March 17 notice said some personal data "had been confirmed to have leaked outside". The May 13 report, issued after the forensic investigation ended, says no definitive evidence directly showing data was taken out was found, but because the possibility cannot be completely ruled out, the data is treated as "at risk of leakage". This article follows the latest, May 13 wording. From the point of view of affected people, what to do is the same either way.

What is specific to this case: a specialist publisher's customer list is a list of medical professionals

A general online shop's customer list tells you "people who bought from this shop". At a medical and nursing publisher, being a customer indicates a profession and a field. The May 13 categories include staff of hospitals and medical facilities, people at educational institutions, people at academic society secretariats and other organizations, and registrants of a staffing business. The third report says general customers' contact details include their workplace. The figure below lays out the fake messages such a list makes possible and where each can be stopped (this site's analysis).

At risk: name, workplace, contact details, email (and bank account numbers for authors)

+ the fact of being a medical and nursing publisher's customer → a list of who works where in healthcare

↓

"Leak notice", "reset your password"

The fake email type the company confirmed

↓

Compare the leaked items with the official notices. Enter data only on an official site you opened yourself

Subscription renewal, seminars, societies, training credits

Natural pretexts for healthcare workers

↓

Check with the organizer's official site or your workplace. Share with your IT staff

"Confirm the account for your manuscript fee"

Uses the known account number to seem genuine

↓

Never give out a PIN or online banking details. Turn on transaction alerts

How a specialist publisher's list can feed fake messages that feel natural to the recipient (left), and the actions readers and authors can take to stop them (right). The pretexts are this site's assessment; what the company confirmed is fake email posing as a 'leak notice' or 'password reset'.

A word on account numbers. An account number is also what you give people so they can pay you, such as a publisher paying a manuscript fee. What banks warn about is the account number combined with a PIN. In 2020, after account information obtained illegally was used to open payment-service accounts in depositors' names, link them to bank accounts and withdraw money, the Japanese Bankers Association asked its member banks to strengthen authentication. So what authors need to protect is less the account number itself than the PIN or online banking details that someone will try to get next.

This site's view: whose list it is matters more than how many

Breach coverage tends to compare counts, but for the people on the list, the danger depends on what can be inferred from it. Lists held by specialist publishers, academic societies, certification exams and industry bodies reveal profession, workplace and field of interest even from a name and email address alone. Fake messages to the people on those lists use pretexts that fit their daily work, which makes them harder to spot. For hospital staff, the risk is not only personal harm: a work email account can become a way in to the workplace. Another Japanese case this year, the CAMPFIRE breach, also involved bank account details of backers and project owners, and there too the main advice was to watch for messages about "refunds" or "confirming your payout account".

Lessons for small publishers and online shops

From the company's notices, here are three things small businesses holding customer lists can review in their own setup. None of them is a claim that the company fell short; they are preparations worked backward from facts in the notices.

1

Keep a 'list you can contact people from' outside the systems that can be hit

The March 17 notice said the company was announcing publicly first because it could not even access its list of contacts. When ransomware stops business systems, the very list you need to notify affected people individually can become unusable. Keep contact details for partners, authors and key customers in a backup separated from the business network (offline or under separate management), and regularly test that it can actually be restored (see backup essentials (the 3-2-1 rule)).

2

Put multi-factor authentication on every way into the internal network from outside

The company says the starting point was a third party entering its internal network using legitimate account credentials. If even one entry point — VPN, remote desktop, a cloud admin console — accepts a password alone, it becomes the weak point for everything. The first step is to list every entry point reachable from outside and check that multi-factor authentication applies to each. The company, too, lists strengthened ID authentication and security among measures taken, and strengthening its authentication platform to prevent unauthorized logins among planned ones. Cases of the same type are collected in 2026 breaches that ran on legitimate credentials.

3

Don't keep authors' account numbers and My Numbers in the same place as the reader list

The third report's items show that readers' contact details, authors' account numbers and My Numbers, entrusted health checkup results and employee evaluations all fell within the scope of the same attack. Keep My Numbers needed for tax paperwork and account numbers used for payments in a separate place with separate access, and delete data once payments are done and it is no longer needed. Data kept apart means one outage affects one kind of data. Also, as a defense against fake emails using your domain, review SPF, DKIM and DMARC, which makes it easier to tell customers how to recognize your real emails.

How ransomware works and how organizations prepare are covered in What is ransomware?.

Sources (public record)

The facts in this article come from the public sources below. Attack methods and system details the company has withheld are not speculated on.

  • Medica Shuppan Co., Ltd., notice of an internal system problem and notice of the system outage (March 13, 2026, Japanese) — system problem / outage
  • Medica Shuppan Co., Ltd., apology and report on the system outage and information leak caused by unauthorized access (ransomware) (March 17, 2026, Japanese) — medica.co.jp / release (PDF)
  • Medica Shuppan Co., Ltd., report on the ransomware damage and current status, 2nd report (March 25, 2026, Japanese) — medica.co.jp
  • Same, 3rd report (April 9, 2026, Japanese) — medica.co.jp
  • Medica Shuppan Co., Ltd., warning about suspicious emails impersonating the company (May 1, 2026, Japanese) — medica.co.jp
  • Medica Shuppan Co., Ltd., report on investigation results and recurrence-prevention measures (May 13, 2026, Japanese) — medica.co.jp
  • Medica Shuppan Co., Ltd., periodical delay notice (April 13, 2026) and resolution notice (May 19, 2026, Japanese) — Apr 13 / May 19
  • Sumitomo Mitsui Banking Corporation, warning about calls from people posing as officials or bank staff trying to obtain account numbers and PINs (Japanese) — smbc.co.jp
  • Japanese Bankers Association, response to unauthorized withdrawals via payment services of funds-transfer providers (September 14, 2020, Japanese) — zenginkyo.or.jp / warning about fake Japanese Bankers Association sites (Japanese) — zenginkyo.or.jp
  • Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (My Number Act), Article 7 (Japanese) — e-Gov Law Search
  • Council of Anti-Phishing Japan, reporting phishing (Japanese) — antiphishing.jp / IPA Information Security Safety Consultation Desk (Japanese) — ipa.go.jp / Government of Japan, police consultation line #9110 (Japanese) — gov-online.go.jp

Update history

2026-09-30: First version, based on Medica Shuppan's notices from March 13 to the May 13 investigation report. The count follows the May 13 report (about 641,000 people, may include duplicates); the April 9 third report's 772,000 records is noted as part of the sequence of events.

FAQ

QWhat happened at Medica Shuppan?
A

According to Medica Shuppan Co., Ltd., it detected a system failure in the early hours of March 13, 2026, and an investigation with outside specialists found that a ransomware attack by a third party was the cause (disclosed March 17). Order taking, shipping and its inquiry desk were suspended for a time, and April's periodicals were delayed by one to three weeks. The company said the delays were resolved on May 19.

QWhat data may have leaked?
A

The April 9 third report lists: for Medica ID users, the ID, name and email address (plus prefecture, address and phone number where registered); for general customers, name and contact details; for authors and outside contractors, name, contact details, job title, email address, bank account number and images provided as manuscripts (plus the My Number, Japan's national ID number, where registered); information entrusted by client companies, facilities and organizations; and employee and job-applicant data. The company says its online sales system does not hold credit card data, so card data did not leak.

QHow many people are affected?
A

The company's May 13 investigation report puts the total at about 641,000 people (may include duplicates of the same person). The April 9 third report had said 772,000 records; the company says the figure was revised after further review.

QDid the data actually leak?
A

Per the May 13 report, the outside forensic investigation found no definitive evidence directly showing that personal data was taken out. However, based on several traces, the possibility could not be completely ruled out, so the company treats the data as 'at risk of leakage'. As of May 12, it said no secondary harm, such as misuse, believed to stem from the incident had been confirmed.

QI'm an author. Can someone withdraw money with my leaked bank account number?
A

Japanese banks warn that if a third party learns your PIN in addition to your account number, it can lead to unauthorized withdrawals through online banking. So the thing to watch for is a message that uses your known account number as bait to get your PIN or online banking ID and password. Banks and the Japanese Bankers Association say they never ask for PINs or passwords by phone or similar means. Turn on transaction alerts, and contact your bank if you see a transaction you don't recognize.

QI registered my My Number. What should I do?
A

The third report says My Numbers are included only for authors and contractors who registered them. A My Number normally stays the same for life, but under Article 7(2) of the My Number Act, the mayor of your municipality can assign a new number when it is found that the number has leaked and may be used improperly. First confirm with the company's desk whether your data is in scope, then consult the municipality where you are registered as a resident.

QShould I change my Medica ID password?
A

The company says Medica ID passwords are managed separately and there is no possibility they leaked, but it recommends changing them regularly for security. If you use the same password on other services, now is a good time to stop reusing it.

QWhat caused it?
A

Per the May 13 report, the starting point was a third party entering the company's internal network using legitimate account credentials, after which unauthorized operations on servers led to ransomware damage such as file encryption. The company says it investigated using the logs available but could not identify how the credentials leaked. It is withholding details of the attack method and system configuration to prevent further harm.