Security Guides
Abahouse data breach (count under investigation): order details may have leaked — how to handle fake refund emails
Abahouse International member and order data may have leaked, former members included. What leaked, and how to handle fake refund emails that quote your real order.
For: anyone who has shopped at Abahouse International's online store in Japan (including former members), and anyone who runs an online shop. This article is based on the company's official notice and does not cover attack or scam techniques.
What customers should do today
Check whether you are affected — former members are included
The company says it cannot yet identify what was taken, so everyone whose member data it holds may be affected. Former members are included too, because their past orders remained as order records.
On October 2, the company emailed people who may be affected, with a Japanese subject line that translates as "Important: possible leak of your member information due to unauthorized access". If you received it, assume your data may have leaked and take the steps below.
If you get a 'refund' or 'out-of-stock' email, check My Page instead of the link
The company says suspicious emails posing as Abahouse and citing a "refund" or "out of stock" have been seen. If you receive one, do not use the links or phone numbers in it; open the official website yourself and check your order history in My Page, or contact the customer support center.
If there really is a refund or an out-of-stock item, the order history or support center will show it. Never enter a password, card number or security code on a page reached from an email link (how to spot these: What is phishing?).
Do not respond to LINE invitations or deadlines that rush you
The company highlights three warning signs:
- The email comes from an address unrelated to the company, such as a free webmail account
- It asks you to get in touch through LINE (a messaging app widely used in Japan), for example via an "official LINE" account
- It sets a deadline, such as "by next Wednesday", to rush you into a refund
If any one of them applies, do not reply and do not add the LINE account.
Change your AMC password and stop reusing it
As a precaution, the company recommends changing your AMC (Abahouse Members Club) login password.
If you use the same password on other services, change those too. A password manager is the realistic way to keep a different password for each service.
Check your card statements
Card numbers are not stored in the company's systems, and no leak of them has been confirmed. Even so, the company asks customers to check their statements for charges they do not recognize. This also covers the case where someone was tricked by a fake email into entering card details.
If you clicked, entered details or sent money, get help right away
The company says that if you opened a link in a suspicious email or suffered a loss, you should contact your card issuer or bank immediately.
In Japan you can also call the police consultation line (#9110) or the consumer hotline (188). The sooner you report it, the better the chance of stopping a payment.
What happened (from Abahouse International's notice)
On October 2, 2026, Abahouse International Co., Ltd. posted a notice of apology and report on a possible personal data leak due to unauthorized access, on its corporate site and its online store. Everything below is as stated in the company's notice.
Late Sep 27 – Sep 28, 2026
The period during which unauthorized access is believed to have taken place.Sep 28
Several customers reported receiving suspicious refund emails that matched their order details. The company began an internal investigation.Investigation
Traces of unauthorized access to part of the member and order data were found. The company says the route it identified has been cut off.Oct 2
The company emailed people who may be affected (including former members), published the notice and reported to the Personal Information Protection Commission.
- Who
- Possibly everyone whose member data the company holds. Former members are included because their past orders remained
- Items
- Member ID, name, address, phone number, email address, date of birth, gender, order information (order date and time, product names, amounts, delivery addresses, etc.)
- Count
- Not announced (the scope of data taken has not been identified)
- Credit cards
- Card numbers and security codes are managed by a payment processor (a company that handles card payments on the shop's behalf). No leak confirmed
- Cause
- An unauthorized login to an internal system, followed by abuse of system flaws to place and run a malicious program that accessed the database
- Secondary harm
- Suspicious emails posing as the company and citing a "refund" or "out of stock" have been seen
- Reported to
- Personal Information Protection Commission (Japan's data protection authority)
- Contact
- The company's customer support center (open it from the official website)
What is unusual here: the fake emails arrived before the breach was known
In many breaches, scam messages that exploit the incident increase after the company announces it. Here the order was reversed: customers receiving fake refund emails is how the breach was discovered.
In other words, messages using the leaked order data were already being sent before the October 2 announcement. Be careful with emails that arrived before then as well.
Why an email that matches your order can still be fake
Many people have assumed that if an email shows the right product name and amount, it must come from the shop. The reasoning was that only the shop knows what you ordered.
That reasoning does not hold here. Order dates, product names, amounts and delivery addresses may all have leaked, so a fake email can quote your real order. The company itself warns that an email can be fake even when it contains information matching your actual order.
Not proof that an email is genuine
- The order date, product name and amount are correct
- Your name, address and phone number appear in it
- It carries the shop's name and logo
Things you can check yourself
- Whether your My Page order history shows a refund or out-of-stock item
- Whether the support center, reached from the official site, says the same thing
- Whether the sender's address belongs to the company at all
Scams that use a refund or an out-of-stock item to move people onto LINE were known before this incident. In July 2024, Japan's National Consumer Affairs Center warned about messages that start with "your item is out of stock, so we will refund you", move the conversation to LINE, and then, under the name of a refund procedure, actually get the customer to send money.
Receiving a refund normally does not require you to operate an app or your bank account. If a "refund" leads to requests for your bank details or instructions to use a payment app, stop the conversation there.
What is still unknown
As of October 3, the company has not announced the number of people affected, the exact scope of the data taken, or whether anyone has lost money to the fake emails. The notice does not mention an outside investigation or prevention measures. This article will be updated when more is published.
For those who run online shops
The cause the company gave is an unauthorized login to an internal system and the abuse of flaws in that system. Details have not been published, so this section sticks to points worth checking for any shop that holds the same kind of data.
Decide how long to keep order data for former members
In this incident, past order data for former members remained as order records and was included in the scope. Some records do have to be kept for a period for accounting or tax purposes.
Even so, set a retention period for each item and, once it passes, delete the data automatically or strip names and contact details so that only figures for reporting remain. Manual deletion does not last.
Require multi-factor authentication for admin logins
According to the notice, the intrusion started with an unauthorized login to an internal system. Admin panels, remote access and cloud admin accounts that can reach the customer database should all require a check beyond the password (multi-factor authentication). See Choosing multi-factor authentication.
Treat 'I got a suspicious email' reports as a signal to investigate
This breach was found through customer inquiries. If your support desk gets several reports of suspicious emails that quote real order details, do not just reply with a scam warning; have a set route for passing them to the people who run your systems.
To reduce fake emails that use your own domain, see Email spoofing and SPF, DKIM, DMARC.
For another online-shop case, see the APORITO online store (RIZAP) card data incident; for a case where fake refund messages were the main risk, see the Trenitalia breach.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed details of the intrusion and the number affected are not speculated on.
- Abahouse International Co., Ltd., notice of apology and report on a possible personal data leak due to unauthorized access (October 2, 2026, Japanese) — abahouse.co.jp (online-store version: abahouse.jp)
- ITmedia NEWS (October 3, 2026, via Yahoo! News Japan, Japanese) — news.yahoo.co.jp
- National Consumer Affairs Center of Japan, warning about "refund via payment app" scams (July 31, 2024, Japanese) — kokusen.go.jp
Update history
2026-10-03: First version, based on Abahouse International's notice of October 2. Will be updated when the count or investigation results are published.
Read next
- Follow-on scams: What is phishing? / Fake virus warnings (tech-support scams)
- Fake refund and compensation messages: Trenitalia (Italy, delay refunds) / TVING (South Korea, compensation) / Booking.com (booking details)
- Passwords: Choosing a password manager / Choosing multi-factor authentication
- Other Japanese cases from the same period: The Times Car breach / APORITO online store (RIZAP)
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat was leaked in the Abahouse breach?
According to Abahouse International Co., Ltd.'s notice of October 2, 2026, the data that may have leaked is member ID, name, address, phone number, email address, date of birth, gender and order information (order date and time, product names, amounts, delivery addresses and so on). Card numbers and security codes are managed in a payment processor's system and are not stored in the company's own systems; the company says no leak of them has been confirmed so far.
QAm I affected?
The company says the whole database may have been accessed and it cannot yet identify what was taken, so everyone whose member data it holds may be affected. Former members are included too, because their past orders remained as order records. On October 2, the company emailed people who may be affected; the Japanese subject line translates as 'Important: possible leak of your member information due to unauthorized access'.
QHow many people are affected?
As of October 3, 2026, no number has been announced. The company says it has not been able to identify the scope of the data taken.
QIs a refund email that shows my real order genuine?
Not necessarily. The company itself warns that an email can be fake even when it contains details matching your actual order. Because order dates, product names, amounts and delivery addresses may have leaked, a fake email can show all of them correctly. Do not use the links or contact details in the email; check your order history in My Page, or contact the customer support center through the official website.
QShould I change my password?
The company recommends changing your Abahouse Members Club (AMC) login password as a precaution. If you use the same password on other services, change those as well.
QWhat if I already clicked a link in a suspicious email?
The company says that if you opened a link in a suspicious email or suffered any loss, you should contact your card issuer or bank right away, and that you can also consult the police consultation line (#9110) and the consumer hotline (188) in Japan. If you entered card or bank details, contact your card issuer or bank first.
QWhat caused the breach?
According to the company, an unauthorized login to an internal system was the starting point; flaws in the system were then abused to place and run a malicious program, which accessed the database holding member and online-store order data. The company says the access route it identified has been cut off and that it has reported the incident to Japan's Personal Information Protection Commission.