Article

Article

Apology for Display of Program Titles on Our Learning Platform

People Focus Consulting, Co. Ltd.
Takuo Matsumura, Representative Director

October 17, 2023

To Our Valued Business Partners,

Apology for Display of Program Titles on Our Learning Platform

We recently discovered an oversight on our learning platform where program titles, associated with our training sessions, became inadvertently accessible to participants (users) of other programs. This situation emerged from our oversight in not properly adapting to changes in the platform’s specifications. Please be assured, no personal information, such as trainee names or course content, was compromised.

However, we recognize the gravity of this oversight, especially considering the trust our clients place in us. We extend our sincerest apologies for any concerns this may have caused.

We are treating this matter with utmost seriousness and are committed to implementing measures to prevent any future occurrences. The following is a detailed account of the incident:

1.Background: On August 23, 2023, a training participant brought to our attention that program titles from other organizations were visible on our platform. We verified this and found a list of program titles displayed on a specific page. The root cause was identified promptly, and by August 25, the situation was rectified. With the cooperation of our learning platform provider, UMU Technology Japan Co. Ltd., we initiated a comprehensive review of access logs. This investigation is now complete, and we are directly reaching out to potentially impacted clients to offer our apologies and provide updates.

2.Situation Regarding Program Title Display:

  • Cause: The issue arose from a failure to adjust access permissions for each program following platform specification changes on August 1, 2023.
  • Details: Under certain operations (not typically executed by students), program titles were listed on specific pages. For instance: “Assertiveness Skills Training on [Date] for [Company XXX].” We have confirmed that no participants from other companies accessed the detailed program content or associated participant data. The displayed program titles spanned from October 10, 2017, to August 25, 2023.
  • Specific Operations: By clicking on the administrator name, "People Focus Consulting," within the program’s video materials, users were directed to the administrator’s profile where program titles were listed. Ideally, this list should not have been visible and wasn’t a routine operation for students.

  • Access to Administrator Profile: During the period from August 1 to August 25, 2023, we noted that 11 users accessed the administrator profile, specifically between August 16 and August 24.

3.Preventative Measures: Between the early hours of August 23 and 3:00 p.m. on August 25, we updated access permissions across all our managed programs, ensuring other users could no longer view them. Additionally, we are in the process of revising our internal procedures and will ensure thorough communication of these updated guidelines to all staff members. We are also liaising with the platform provider to discuss potential modifications to display settings.

4.Contact for Inquiries: For further clarification or concerns regarding this incident, kindly reach out to us at: security@peoplefocus.co.jp.