Security Guides
Bookoff Member Data Leak (Up to About 6.43 Million Records): Names, Addresses, Emails and Password Hashes May Be Exposed — What Members Should Do
Bookoff says member data leaked from a subsidiary's system: up to about 6.43 million records, including password hashes. What leaked and what members should do.
For: anyone who has registered as a Bookoff member in Japan (official app, online store, point card and so on), and anyone who runs a service that holds member data. This article is based on the official notice from BOOKOFF GROUP HOLDINGS LIMITED and does not cover attack techniques.
Developing: this article will be updated as the organisation publishes more
As of October 10, 2026Not yet known
- Actual number of people affected
- Which data actually leaked
- Which services are involved (app, online store, etc.)
- Name of the subsidiary
- How the attacker got in
- Start of individual notifications
The company says it is continuing a detailed investigation and will promptly announce any new facts. It is still reviewing the number of people affected and the data that may have leaked, and will publish a follow-up once these are known. It plans to contact affected people individually, in turn, based on the results.
What Bookoff members should do today
Work out whether you could be affected (the services have not been named)
The notice refers only to "a system, provided by a subsidiary, that manages member information". It does not name the subsidiary or say which services' members are involved. The items that may have leaked include a point card number and a member number.
The company says the figure of up to about 6.43 million is the number of member numbers that may have leaked, not the actual number of people. This site recommends that anyone who has registered as a Bookoff member take the steps below without waiting for an individual notice.
If you use your Bookoff password on other services, change it there
The company's notice does not ask members to change passwords. What may have leaked is the password hash (a value converted so that it cannot be turned back into the password), which the company describes as information that "cannot be read as is".
In general, though, short or common passwords can sometimes be worked out from a hash (how this works: What is password hashing?). A recovered password paired with an email address gets tried on other services.
So this site recommends changing the password on any other service that shares it, especially email, online shopping and financial services. If Bookoff offers a screen to change your password there too, doing so does no harm. A password manager is the practical way to stop reusing passwords, and adding two-step verification makes logins safer still.
Do not open links in emails, texts or calls claiming to be Bookoff
The company warns that emails, text messages and calls pretending to be the group or its partners may arrive. It asks members not to open links or attachments in unexpected messages, and not to enter personal data or login details.
It says the group will never ask for passwords, verification codes, credit card details or bank account details by email, text message or phone. Any request for these is fake (how to spot one: What is phishing?).
Check even the real notification email through an official entry point
According to the company's inquiry page (checked October 10), it plans to start emailing affected people in turn "from next week, over about two weeks". That means real notices and lookalike fakes may arrive in the same period.
This site recommends that you do not sign in through links in the email, even if it looks genuine. Check the content in the official app, or on the official website opened from your own bookmark or a search.
Look for point use or other activity you do not recognise
The company asks members to contact its inquiry desk if they notice suspicious contact or use they do not recognise. If you can sign in to the official app or online store, check your point balance, usage history and registered details for changes you did not make. The company says it had not found any rewriting of member data as of the announcement.
Use the contact points listed in the official notice
The notice lists a customer phone line, 0570-01-2902 (Navi Dial, 10:00–18:30, Japanese), and a dedicated inquiry form on the Bookoff Group Holdings website. Find these through the notice on the official website you open yourself, not through numbers or links in a message you received.
What happened (per Bookoff Group Holdings)
The following is based on the company's notice of October 9, 2026 (a stock exchange disclosure, also posted in the news sections of the Bookoff website and its official online store) and the FAQ on the company's inquiry page (checked October 10).
October 6, 2026 (Tue)
Unauthorized third-party access to the subsidiary's member management system confirmed. The investigation found that member data managed in that system had been taken from outside.After confirmation
Traffic from the attack source blocked, the vulnerability fixed and outside access to the system cut off. The company says the known route used to take the data has been contained and monitoring continues.October 9 (Fri)
Notice of apology for the personal data leak published. The company says it is taking the necessary steps, including reporting to the Personal Information Protection Commission.As of October 10
No follow-up notice. The FAQ on the inquiry page says emails to affected people will start "from next week, over about two weeks".
- System
- "A system, provided by a subsidiary, that manages member information". The subsidiary and the services involved are not named
- Count
- Up to about 6.43 million. This is the number of member numbers that may have leaked, not the actual number of people
- Items
- Name, date of birth, gender, email address, phone number, postal code and address, password hash, point card number, member number
- Passwords
- Hashes. The company describes them as "an encrypted password that cannot be read as is"
- Not included
- Payment data such as credit card details (not held in this system). The FAQ adds that ID document images and bank account details from mail-in buybacks are not part of the leak
- Leak and misuse
- The company confirmed member data was leaked outside the company. As of the notice, it had not confirmed publication or misuse by a third party, or any rewriting of member data
- Next steps
- Emergency review of all systems, added security and permanent prevention measures on both the network and application side, individual contact with affected people
What is known and what is not
Status as of October 10, 2026. When a follow-up is published, the status column will be updated.
| Item | What the company said | Status |
|---|---|---|
| Unauthorized access and leak | Confirmed that member data was leaked outside the company | Confirmed |
| Data items | Name, date of birth, gender, email, phone, postal code and address, password hash, point card number, member number | May have leaked (under review) |
| Count | Up to about 6.43 million (member numbers) | Upper limit only |
| Actual number of people | Under review | Under investigation |
| Services and subsidiary name | Not stated in the notice | Not disclosed |
| Payment data | Not held in this system, so not included | Not included |
| Buyback ID images and bank details | Not part of the leak (FAQ) | Not included |
| Text read from driver's licences | Not in the notice's list; the FAQ does not mention it | Not disclosed |
| Publication or misuse | Not confirmed as of the notice | Not confirmed |
| Cause and route in | Only that the vulnerability was fixed | Not disclosed |
| Password change request | Not requested in the notice | No request |
| Individual notices | By email, in turn, starting "from next week, over about two weeks" | Planned |
How to read this: 'no misuse confirmed' does not mean 'safe'
What the company says is that, as of the notice, it had not confirmed that the leaked data had been published or misused. The leak itself is confirmed. Fake messages can arrive long after a leak, so stay alert for at least several months.
What these combinations of data can be used for
In general, the following combinations make the following misuse possible. This does not mean it happened in this case.
- Name + address + phone number + email address: a convincing "apology" or "please confirm" message with the correct name and address
- Email address + password hash: if the password is easy to guess, it can be recovered and tried on other services that share it
- Member or point card number + date of birth: material for pretending to be the member on the phone or in a support request. Knowing these numbers does not prove who someone is
In a past case, the Seicomart app breach announced in September 2026, the first notice gave about 570,000 accounts; the third and fourth notices then fixed the count (574,647 people) and the company began telling each member through in-app notices whether they were affected. This case may not follow the same path.
Open the link in the email or text
You have to judge from the wording whether it is real
↓→
Risk of typing your password into a fake sign-in page
Go in through the official app or a site you open yourself
Treat the email only as a sign that a notice exists
↓→
You only ever see the real notice. No judgement needed
This site's view: real notices and fakes will arrive in the same week
Here, the company announced in advance that it will email affected people individually. Knowing when those emails will arrive helps anyone sending fakes just as much. The most reliable way to tell them apart is not the wording but choosing the entry point yourself. If you never use links in the email and always go through the official app or a website you open yourself, you no longer need to judge whether a message is real.
For services that hold member data: make breach notices distinguishable from fakes
The cause has not been disclosed, so this section does not discuss how to prevent the intrusion. Two things can be drawn from the notice: password hashes were among the data, and the company will contact affected people by email. The steps below are limited to what you can decide in advance for your own service. This section does not assess the company's response.
Do not put sign-in links in breach notification emails
A breach notification email becomes the template for lookalike fakes. If the notice says "sign in here to change your password", a fake can use exactly the same layout.
If the notice contains no links and says "please check the notice in the official app or on the official website", you can consistently tell users never to open links. Announcing the sender address and subject line on your website beforehand also helps.
Check your hashing method and decide in advance what you will tell users
How hard it is to recover passwords from leaked hashes depends heavily on the method. Check that you store passwords with a slow password-specific method (such as bcrypt or Argon2) and a salt.
Also decide in advance what you will ask users to do if hashes leak (a reset for everyone, or advice to change reused passwords), so the wording of the announcement is not decided under pressure. More in What is password hashing?
Sources (public record)
The facts in this article are based on the following public information. It does not speculate about the undisclosed route or method of intrusion, the subsidiary's name or the services involved.
- BOOKOFF GROUP HOLDINGS LIMITED, notice of apology regarding a personal data leak caused by unauthorized access (October 9, 2026, stock exchange disclosure, Japanese) — PDF
- Bookoff official website news (same notice, same day, Japanese) — bookoff.co.jp
- Bookoff Group Holdings inquiry page for this incident, including FAQ (checked October 10, 2026, Japanese) — bookoffgroup.co.jp
Update history
2026-10-10: First version, based on the company's notice of October 9 and the FAQ on its inquiry page (checked October 10). The company says it will publish the number of people affected and the data involved in a follow-up, and this article will be updated when it does.
Read next
- Other member-data cases from the same period: Seicomart app breach / Yakiniku King app breach / MrMax app and online store breach
- Passwords: How to check if your password leaked / Password manager guide
- Scam follow-ups: What is phishing?
- Other 2026 cases: Data breaches and cyberattacks in 2026
FAQ
QWhat leaked from Bookoff?
According to Bookoff Group Holdings' notice of October 9, 2026, the data that may have leaked is name, date of birth, gender, email address, phone number, postal code and address, password hash, point card number and member number. Payment data such as credit card details is not held in the affected system and is not included. The company says it has confirmed that member data was leaked outside the company, and it is still reviewing how many people are affected and which data actually leaked.
QAm I affected?
This had not been confirmed as of October 10. The company gives a maximum of about 6.43 million records, but says this is the number of member numbers that may have leaked, not the actual number of people. The notice does not say which services' members are involved. According to the company's inquiry page (checked October 10), it plans to start emailing affected people in turn 'from next week, over about two weeks'. This site recommends that anyone who has registered as a Bookoff member act as if they may be affected, without waiting for that email.
QShould I change my password?
The company's notice does not ask members to change passwords. What may have leaked is the password hash, which the company describes as 'an encrypted password that cannot be read as is'. In general, though, short or common passwords can sometimes be worked out from a hash. So this site recommends that if you use your Bookoff password on any other service, you change it there.
QWhat caused it?
It has not been disclosed. The company says that after confirming the unauthorized access it blocked traffic from the attack source, fixed the vulnerability and cut off outside access to the affected system. It has not said which vulnerability was involved or how the attacker got in. It says it is running an emergency review of all its systems.
QWhat if I get an email or text message claiming to be from Bookoff?
The company asks members to watch out for suspicious emails, text messages and calls pretending to be the group or its partners, not to open links or attachments in unexpected messages, and not to enter personal data or login details. It says the group will never ask for passwords, verification codes, credit card details or bank account details by email, text message or phone. Treat any such request as fake, and check through the official app or a website you open yourself.
QDid the ID images or bank details I gave when selling items leak?
According to the FAQ on the company's inquiry page (checked October 10), in-store buybacks only read the text on a driver's licence and do not photograph it, so no image data is held. It also says ID document images and bank account details from mail-in buybacks are not part of the leak. That answer does not say whether the text read from a driver's licence is involved. Licence data is not among the items listed in the October 9 notice.