Skip to content
>_ITDITDWeb Security Platform

Security Guides

Baitoru breach (up to 3.88 million email addresses): only emails leaked — how members can spot fake interview messages and job scams

dip Corporation said on October 9, 2026 that unauthorized access from overseas to its Baitoru and Baitoru NEXT job sites leaked up to 3,885,771 member email addresses, and nothing else. How to spot fake recruiter messages, and what is still unknown.

Published 2026-10-10 Updated 2026-10-10 Last verified 2026-10-10 13 min read

For: anyone registered on Baitoru or Baitoru NEXT, the job sites run by dip Corporation in Japan (including past members), and anyone who runs a web service with member accounts. This article is based on dip Corporation's official notice and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 10, 2026

Not yet known

  • Actual number of addresses leaked (only the maximum, 3,885,771, is known)
  • Which function had the flaw, and what it was
  • When the unauthorized access began
  • When individual notification emails will be finished

The company's October 9 notice does not say whether a follow-up will be published. It says affected members were told on the services on October 6 and are being contacted individually by email and other means. This article will be rewritten if the company publishes more.

What Baitoru members should do today

1

Check whether you are affected in the official app or site you open yourself

The company says it told affected members on Baitoru and Baitoru NEXT on October 6, 2026, and is contacting them individually by email and other means. No way for members to check for themselves has been published.

Because people know an email from the company is coming, fake emails imitating it are possible. To check, do not use a link in an email; open the site from the official app on your home screen or your own bookmark and read the notices there.

2

Match interview and application messages against your application history in the app

On a job site, it is normal to get messages from employers about interview times or confirming an application. That is exactly why messages imitating them are hard to tell apart.

For any such message, check in the official app or site whether you really applied for that job and whether the listing still exists. If you do not remember applying, or the listing cannot be found, ignore the message without opening the link (the basics: What is phishing?).

3

Never give your password or card details in response to a message

Per the company's notice, passwords and credit card details were not among the leaked data. The company also says it never asks for passwords or credit card details by email or other messages.

So a message asking you to type a password or card number "to verify your identity" or "to protect your account" is fake. If you already entered one, change the password right away from the official app, and change it on any other service where you used the same password (how to check whether a password leaked).

4

Refuse requests to move to another messaging app or to send ID or family details

This is general advice about job sites, not a statement about Baitoru. Japan's National Police Agency warns that even listings on legitimate job sites can include harmful ones that recruit people for crimes, such as collecting cash for phone scams. Signs it lists include being told to install a highly anonymous messaging app, being asked repeatedly for personal details about you, your family or friends, and being unable to confirm the workplace or the job content.

The agency says legitimate part-time jobs do not need such apps, and asks people who get these requests to stop responding and consult the police. If you already sent a photo of an ID document, see what to do if your Japanese driver's license data was leaked.

5

Do not apply to offers of 'high pay', 'paid the same day' or 'just receive a package'

The National Police Agency lists, as signs of recruitment for crimes (known in Japan as yami baito), postings that promise high pay without a clear job description, phrases such as "high pay", "paid the same day" and "white (clean) job", and offers of high pay just for carrying or receiving packages.

If you have already applied and cannot get out, the agency asks you to call the police consultation line #9110 or go to a nearby police station.

6

If 'easy side work' turns into a request for money, call 188 first

Japan's National Consumer Affairs Center warns of side jobs that promise easy money for simple tasks in spare time but end with people paying money instead. Most start from social media or ads, and some involve applying through a messaging app.

If you are asked to send money for work that was supposed to pay you, call the consumer hotline 188 before paying.

1. Do not open links in the email or message

The sender name or a Baitoru logo does not prove a message is genuine

↓

2. In the official app you open yourself, check your applications and the listing

No application on record, or the listing cannot be found → ignore it

↓

Refuse any of these requests

Typing a password or card number / joining another messaging app / ID or family details / paying money first

Where to get help in Japan

Want out of a yami baito job → #9110 or a police station / asked to pay → 188

The order in which to check a job-related email or message (this site's summary)

What happened (per dip Corporation's notice)

The following is based on dip Corporation's notice of October 9, 2026. When the company's news list was checked on October 10, there was no follow-up.

  1. October 6, 2026

    Unauthorized third-party access to part of the website's functions is confirmed. Right after confirming it, the company blocks all access from overseas and modifies the program.
  2. October 6

    Affected members are told on Baitoru and Baitoru NEXT. The company then starts contacting them individually by email and other means.
  3. October 9

    The company publishes its notice and apology about the partial leak of email addresses on its official website.
  4. As of October 10

    No follow-up. The company says its services, including Baitoru and Baitoru NEXT, remain available.
Up to 3,885,771
Email addresses that may have leaked
Email only
Leaked data (no names, phone numbers, passwords or cards)
None confirmed
Posting online or misuse (as of the notice)
Available
Baitoru and Baitoru NEXT services
What dip Corporation's notice says
Services
The Baitoru and Baitoru NEXT job sites
Leaked data
Member email addresses only. Names, phone numbers, passwords and credit card details were not included
Number
Up to 3,885,771 addresses may have leaked
Cause
Confirmed as unauthorized access from overseas that exploited a flaw in the specification of part of the system's functions. Which function and what flaw have not been disclosed
Response
Blocked all access from overseas; modified the affected program so the same method can no longer be used; strengthened security measures and monitoring
Reports
Reporting to the Personal Information Protection Commission and the Kanto Bureau of Telecommunications (Ministry of Internal Affairs and Communications), and consulting the police
Member notice
Told on the services on October 6; individual notices by email and other means in progress
Inquiries
The user inquiry form linked from the company's notice

What is known and what is not

Status as of October 10, 2026. When a follow-up appears, the status column will be rewritten.

ItemWhat the notice saysStatus
LeakSome member email addresses leakedConfirmed (company)
Data leakedEmail addresses onlyConfirmed (company)
Names, phone numbers, passwords, cardsNot includedConfirmed (company)
Other personal dataNo leak confirmedNone confirmed as of the notice
NumberUp to 3,885,771 addresses may have leakedMaximum only (actual number not given)
CauseAccess from overseas exploiting a specification flaw in part of the systemConfirmed (no details)
Period of accessConfirmed on October 6; start date not statedNot disclosed
Posting online or misuseNot confirmedNone confirmed as of the notice
Notice to membersOn-site notice on October 6; individual emails in progressIn progress
ServiceRemains availableConfirmed (company)

How to read it: 'no misuse confirmed' does not mean 'safe'

The company says it has not confirmed the data being posted online or misused. That means nothing had been found as of the notice. Lists of email addresses are sometimes used for spam or scams much later. For some time, keep checking job-related messages in the official app.

What can happen with email addresses alone

In general, when a list of email addresses leaks, the following can happen. This does not mean it has happened in this case.

  • More spam. Do not press "unsubscribe" in spam, because it can tell the sender the address is in use
  • Fake emails imitating the service (phishing), leading to fake pages that ask for a password or card details
  • Login attempts on other services where you signed up with the same address, using passwords leaked in other breaches. Not reusing passwords stops this

This site's view: what leaked is also the fact of being a job-site member

These addresses are not just any list of emails; they belong to people registered on a job site. People looking for work are waiting to hear from companies they do not know. That makes fake interview invitations, application confirmations and attractive "scout" offers look more natural than other fake emails. Judge by whether the official app has a record of it, not by the sender or the wording, and you will not have to guess.

For people running member services: "specification flaws" and mass harvesting

The company describes the cause as "unauthorized access from overseas that exploited a flaw in the specification of part of the system's functions". Which function and what flaw have not been disclosed. This section does not guess at the company's flaw; it describes, in general terms, what operators can check on their own services for the kind of problem usually called a specification flaw.

A "specification flaw" usually means a hole in how a feature was designed rather than a coding mistake. Examples: a logged-in user can see someone else's data just by changing a number (IDOR); a screen that says whether an address is already registered lets anyone check other people's addresses; a single request returns an unlimited number of records. Each request in these cases looks "normal", so you cannot notice unless you count volume.

1

List every function that returns or confirms other people's data

Write down every screen or API that returns member data such as email addresses, every function that says whether an account exists (sign-up, password reset, login), and every function where a number selects someone's data. For each one, check that the server checks every time whether this user may see that record (the idea: authentication vs authorization).

2

Cap how many other people's records one user can see per day

Count not only requests but the number of other people's records returned, per logged-in account or API key. Measure what normal use needs, set the cap from that, and start by alerting someone when usage reaches 80% of it. IP addresses can be changed, so count by account or key. The full design is in rate limiting and abuse control.

3

Look for access that steps through IDs one by one

In access logs, look for one user querying sequential IDs or similar-looking email addresses in rapid succession. People clicking through screens do not produce that pattern, so requests per hour and the number of distinct targets queried are good signals.

4

Treat blocking by country as first aid, and fix the design itself

The company says that right after confirming the access it blocked all access from overseas and also modified the program. Blocking by country works quickly as a first response to stop damage. But in general it depends on how the connection's origin appears, so on its own it leaves the problem in the function. Use the time it buys to add per-record permission checks and volume caps to the function itself; that is the real fix.

Sources (public record)

The facts in this article come from the public information below. Undisclosed details of the flaw or method are not speculated on.

  • dip Corporation, notice and apology about the partial leak of email addresses from unauthorized access to Baitoru and Baitoru NEXT (October 9, 2026, Japanese) — dip-net.co.jp
  • dip Corporation, news list (checked October 10, 2026, Japanese) — dip-net.co.jp
  • National Police Agency, warning about harmful listings on legitimate job sites (Japanese) — npa.go.jp
  • National Police Agency, on the dangers of so-called yami baito (Japanese) — npa.go.jp
  • National Consumer Affairs Center of Japan, warning about "easy money in spare time" side-job trouble (September 4, 2024, Japanese) — kokusen.go.jp

Update history

2026-10-10: First version, based on dip Corporation's October 9 notice. Will be updated when the actual number or details of the cause are published.

FAQ

QWhat leaked from Baitoru?
A

According to dip Corporation's notice of October 9, 2026, only the email addresses of Baitoru and Baitoru NEXT members leaked. The company says names, phone numbers, passwords and credit card details were not included, and that as of the notice it had not confirmed any other personal data leaving the company.

QAm I affected, and how many people are?
A

The number of email addresses that may have leaked is up to 3,885,771. No way for members to check for themselves has been published. The company says it told affected members on Baitoru and Baitoru NEXT on October 6, 2026, and is contacting them individually by email and other means. To check, log in through the official app or site you open yourself and read the notices there, not through a link in an email.

QShould I change my password or email address?
A

Per the company, passwords were not among the leaked data, and it never asks for passwords or credit card details by email or other messages. So any message asking you to type a password is fake. If you already entered your password on a fake page, change it right away from the official app. The company has not advised changing email addresses. This site's view is that it is worth considering only if spam becomes a real problem.

QWhat caused it?
A

The company says it confirmed unauthorized access from overseas that exploited a flaw in the specification of part of its system's functions. Which function, what kind of flaw, and when the access began have not been disclosed. The company says it modified the program so the same method can no longer be used.

QWhat if someone contacts me claiming to be Baitoru or an employer?
A

Do not open links or attachments. Check in the Baitoru app or site you open yourself whether that application or job listing really exists. The company warns that the leaked addresses could receive spam or spoofed emails and asks people not to open unfamiliar links or attachments. If you are asked to sign up to LINE or another messaging app, or to send ID documents or details about your family, do not do it.

QIf only email addresses leaked, is there anything to worry about?
A

Direct harm is less likely than when passwords or card details leak. But these addresses belong to people registered on a job site. People looking for work are often waiting to hear from companies they do not know, so messages pretending to be interview invitations or application confirmations look natural. Decide in advance how you will check such messages, on the assumption that more of them may arrive.