Skip to content
>_ITDITDWeb Security Platform

Security Guides

Malware on a Daiichikosho Contractor's PC (About 8.72 Million Records): Big Echo and Other Members' Names, Birth Dates and Phone Numbers May Have Leaked — What to Do

Daiichikosho says malware on a contractor's PC may have exposed names, birth dates, emails and phone numbers in about 8.72 million Big Echo, DK Dining and other records. What to do.

Published 2026-10-10 Updated 2026-10-10 Last verified 2026-10-10 15 min read

For: anyone who has registered as a member or made a reservation at Big Echo, Mega Big, Karaoke CLUB DAM, Banana Club, B-GARAGE or DK Dining stores; current and former Daiichikosho employees; and businesses that hand customer data to contractors. This article is based on Daiichikosho Co., Ltd.'s official notices and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 10, 2026

Not yet known

  • Whether data actually left to outside parties
  • How the PC was infected
  • What work was outsourced
  • Whether affected people will be contacted individually
  • How to check whether you are affected
  • Measures to prevent recurrence

The company says it will promptly announce any new facts, including the scope of affected customers and its response. It opened a dedicated toll-free line on October 9. As of October 10, there has been no follow-up on the cause or scope.

What Big Echo and other members should do today

1

Check whether you could be affected (members and bookers of six brands, plus employees)

According to the company, the data concerns customers who registered as members or made reservations at its stores. The breakdown is below. All figures are approximate, and duplicates (about 515,000) are removed from the total.

  • Big Echo-related: about 5,558,000
  • DK Dining-related: about 3,462,000
  • Karaoke CLUB DAM-related: about 74,000
  • Mega Big-related: about 43,000
  • Banana Club-related: about 5,000
  • B-GARAGE-related: about 4,000

In addition, about 93,000 employee records are included. The notice does not say whether this covers only current staff or former staff as well.

As of October 10, the notices do not say whether affected people will be contacted individually or how to check whether you are included. If you have ever registered or booked with any of the brands above, assume you are included and follow the steps below.

2

Do not open links in emails or texts about coupons, membership updates or points

The company warns that, if the data did leak, it could be used for spoofed emails and phishing. It asks people to watch for suspicious emails, texts and calls and not to open unfamiliar links or attachments.

Karaoke and restaurant membership programmes routinely send coupons, membership-tier notices and points reminders. That makes fake "claim your coupon", "update your membership" or "points expiring" messages hard to tell apart from the real ones. Do not open the link; check whether the same notice appears in the official app or on an official site you bookmarked yourself (how to spot fakes: What is phishing?).

3

Treat any request for a password or card details as fake

The company says it will never ask for passwords or credit card details. Do not respond to messages that ask for them in the name of an apology, compensation or bonus points. If you have already entered them, change the password on that service, or call your card issuer if you entered card details.

4

If you use your birth date as a PIN or password, change it

From here on, this is this site's advice. Unlike a password, your birth date cannot be changed later. Since it may have leaked, if you use the 4 or 6 digits of your birth date as a bank card or phone PIN, or as part of a password, change it.

With your name and email address also possibly known, "name + birthday" passwords become easy to try. When you replace a password, a password manager is the practical way to make it long and unrelated to you.

5

A caller who recites your birth date is not proven genuine

When a caller "confirms your identity" by reading out your name and date of birth, they can sound official. Name, birth date and phone number are all among the items here, which makes such calls easier to fake. If someone calls you, do not answer their questions on the spot; hang up and call back on the number listed on the company's official website.

6

Use only the contact points in the official notice

The company's inquiry line is toll-free 0120-732-079 (10:00–17:00 Japan time, excluding weekends and holidays, callable from within Japan) and email incident-desk@dkkaraoke.co.jp (per its October 9 notice). It says email can be used if the phone line is busy. Confirm the number and address on the company's official website, not from an email or text you received.

Changing passwords: what the notice says, and what this site thinks

The company's notice says passwords are not included in the data that may have leaked, and that points cannot be used with this information alone. It says no misuse of points has been confirmed. The notice does not ask people to change passwords.

This site also does not think this incident alone is a reason to change your password. However, if you logged in on a page opened from an email or text link, change that password right away, and change it on any other service that uses the same one (how to check: How to check if your password leaked).

What happened (per Daiichikosho)

The following is based on Daiichikosho's notice of October 8, 2026 and its toll-free line notice of October 9. Items the company attributes to the contractor's report are stated as such.

  1. October 1–2, 2026

    According to the contractor's report, malware infection was found on one PC used by a contractor employee.
  2. October 2

    The contractor isolated the PC from its network.
  3. October 5

    After the contractor investigated the scope, Daiichikosho received its report.
  4. October 8

    Daiichikosho published "Potential Personal Information Leak at a Contractor" (Japanese and English).
  5. October 9

    A dedicated toll-free line for customers opened. The company says no misuse of personal data from this incident has been confirmed and the investigation continues.
  6. As of October 10

    No follow-up on the cause or scope.
~8.72M
Records that may have leaked (incl. employees)
~8.63M
Customer records (six brands, duplicates removed)
5 items
Name, gender, birth date, email, phone
1 PC
Infected contractor device
Data that may have leaked (per Daiichikosho)
Who
Customers who registered as members or made reservations at the company's stores (about 8,631,000) and employee records (about 93,000). About 8,724,000 in total
Items
Name (registered name), gender, date of birth, email address, phone number
Not included
Passwords. Points cannot be used with this information alone, and no misuse of points has been confirmed
Cause as disclosed
A PC (one device) used by an employee of a company to which Daiichikosho outsources personal-data handling was infected with malware. Personal data related to the outsourced work had been temporarily stored on it
Not confirmed
An actual external leak, misuse resulting from the incident, or any impact on the company's own systems
Contractor's response (per its report)
Isolated the PC from the network and reset passwords and other credentials. Investigating the cause and scope, including whether data leaked
Company's next steps
Monitoring for misuse and acting on signs of it, checking the systems it uses, reviewing the cause investigation and prevention plan by the contractor and an outside specialist, and reviewing and strengthening how it manages contractors

What is known and what is not

Status as of October 10, 2026. When a follow-up notice is published, we will update the status column.

ItemWhat the notice saysStatus
Infected deviceOne PC used by a contractor employee; isolated October 2Confirmed (per the contractor's report)
Data on the devicePersonal data related to outsourced work, stored temporarilyConfirmed (per the contractor's report)
Number of recordsAbout 8,724,000 (customers about 8,631,000; employees about 93,000)Scope known so far
ItemsName (registered name), gender, date of birth, email, phoneMay have leaked
PasswordsNot includedConfirmed
PointsCannot be used with this data alone; no misuse confirmedConfirmed (company's statement)
Actual external leakNot confirmed; under investigation, including whether data leakedUnder investigation
MisuseNot confirmed (as of October 9)Not confirmed
How the PC was infected / type of malwareNot mentioned in the noticeNot disclosed
What work was outsourcedNot mentioned in the noticeNot disclosed
Individual notificationNot mentioned in the noticeNot disclosed
Prevention measuresWill review the investigation by the contractor and outside specialists and strengthen contractor managementUnder review

How to read this: 'not confirmed' does not mean 'did not leak'

The company says it has not confirmed an actual external leak, but published the notice because it cannot rule one out. Whether data was taken from a malware-infected device often stays unclear until the investigation ends, which can take time. Until then, assume the data is out and be ready for fake messages.

What name, birth date, phone and email can be used for

In general, the following combinations can be misused as described. This does not mean it has happened in this case.

  • Name + email + phone: emails and texts with your correct name that look like membership notices
  • Name + birth date + phone: material for calls that pretend to confirm your identity, and for fake birthday-perk messages
  • Birth date + name: accounts of people who use their birth date as a PIN or password get tried
  • Gender + birth date: lets someone tailor a convincing sales pitch or scam to your age group and gender

This site's view: when data you cannot change leaks, reduce where your birth date alone gets you recognised

A password stops working once you change it, but your birth date and name cannot be changed. This combination stays usable for years.

So the defence is not getting the data back but removing situations where a birth date alone counts as proof of identity. Take your birth date out of PINs and passwords, and do not trust a caller because they know it. Both steps help not only here but every time a leak includes birth dates.

Big Echo

~5.558M

DK Dining

~3.462M

CLUB DAM, Mega Big, Banana Club, B-GARAGE

~126K combined

Employee records

~93K

↓ for outsourced work

Stored temporarily on one contractor employee's PC

~8.724M after removing duplicates

↓

Malware found Oct 1–2; PC isolated Oct 2

No external leak confirmed (under investigation)

Flow of data as described in the notice (based on Daiichikosho's notice)

For businesses that hand customer data to contractors

How the PC was infected has not been disclosed, so this section does not cover how to stop the malware. What other businesses can check against their own practice is one disclosed fact: member data from several brands, plus employee data, was temporarily stored on one contractor employee's PC. This section does not assess the company's or the contractor's actions.

Listing the contractors that hold your customer data, with record counts and notification deadlines, is covered in the Daiwa Securities contractor breach article. Here we focus on cases where the data ends up on the PCs of the people doing the work, not on a contractor's server.

1

Give contractors only the columns and records the task needs

When you outsource tabulation, mailing or analysis, exporting the whole member database puts columns and brands the task never uses onto the contractor's PCs. For each task, decide which columns are really needed before handing anything over.

For example: age bands instead of full birth dates for age-group reports, no email or phone number for work that involves no contact, member numbers instead of names. If the work is split by brand, split the files too. As a first step, pick one file you send to a contractor regularly and go through it column by column with the contractor, asking whether the task uses each one.

2

Have contractors work in an environment you control, not on their own PCs

Once data is saved on a contractor employee's PC, that PC's malware protection and update status become your customers' protection, and you cannot see either. Where possible, have contractors work in an environment you manage (a virtual desktop that only streams the screen, or a shared workspace with downloads blocked) so that no files stay on their PCs.

For work that genuinely needs a local copy, require encryption, deletion when the task ends, and a deadline for confirming the deletion to you.

3

Write device requirements and a first-notice deadline into the contract

Japan's Act on the Protection of Personal Information requires a business that outsources the handling of personal data to exercise necessary and appropriate supervision over the contractor (Article 25). To make that supervision concrete, put the following in the contract or a memorandum:

  • Requirements for devices that handle customer data: a tool that detects and records malware activity (such as EDR), OS and software updates, disk encryption, and no handling on personal devices
  • Where customer data may be stored, and the deadline for deleting it after the work
  • What happens when an infection or intrusion is found: a deadline for a first notice that does not wait for the scope investigation (for example, within 24 hours), set separately from the deadline for the investigation report

Check once a year that the contractor meets these requirements, through a written report on how it manages its devices or the results of its self-assessment.

Where an organisation should start overall is covered in Minimum security for organisations, and malware types and device protection in What is malware?.

Sources (public record)

The facts in this article are based on the public information below. We do not speculate on undisclosed infection routes or techniques.

  • Daiichikosho Co., Ltd., "Potential Personal Information Leak at a Contractor" (October 8, 2026) — en.dkkaraoke.co.jp (Japanese: dkkaraoke.co.jp)
  • Daiichikosho Co., Ltd., notice on opening a toll-free inquiry line about the possible leak at a contractor (October 9, 2026, Japanese) — dkkaraoke.co.jp
  • Personal Information Protection Commission, "Guidelines on the Act on the Protection of Personal Information (General Rules)" (supervision of contractors, Japanese) — ppc.go.jp

Update history

2026-10-10: First version, based on Daiichikosho's notice of October 8 and its toll-free line notice of October 9. The company says it will announce new facts, including the scope and its response, and we will update this article when it does.

FAQ

QWhat may have leaked in the Daiichikosho incident?
A

According to Daiichikosho Co., Ltd.'s notice of October 8, 2026, the data that may have leaked is name (registered name), gender, date of birth, email address and phone number. The total is about 8,724,000 records: about 8,631,000 customer records and about 93,000 employee records. As of the notice, the company had not confirmed that any data actually left to outside parties.

QAm I affected?
A

The notice covers customers who registered as members or made reservations at the company's stores. The breakdown is Big Echo-related (about 5,558,000), DK Dining-related (about 3,462,000), Karaoke CLUB DAM-related (about 74,000), Mega Big-related (about 43,000), Banana Club-related (about 5,000) and B-GARAGE-related (about 4,000). As of October 10, the notices do not say whether affected people will be contacted individually or how to check. If you want to ask, use the company's inquiry line listed in its official notice (toll-free 0120-732-079, from within Japan).

QDo I need to change my password? Are my points safe?
A

The company says passwords are not among the data that may have leaked and that points cannot be used with this information alone. It says no misuse of points has been confirmed, and the notice does not ask people to change passwords. This site does not think this incident alone is a reason to change your password. If you typed your password into a page opened from an email or text link, change it right away. If you use your birth date as a password or PIN, change that too.

QWhat caused it?
A

According to the company, a PC used by an employee of a company to which it outsources personal-data handling was infected with malware, and personal data related to the outsourced work had been temporarily stored on that PC. How the PC was infected and what kind of malware it was have not been disclosed. The contractor and an outside specialist organisation are investigating the cause and scope.

QWhat if I get an email or text claiming to be Big Echo or Karaoke DAM?
A

The company asks people to watch for suspicious emails, text messages and calls and not to open unfamiliar links or attachments. It also says it will never ask for passwords or credit card details. For any message that asks you to open a link about coupons, membership updates or expiring points, check through the official app or a bookmarked official site instead.

QMy date of birth may have leaked. What should I watch for?
A

Unlike a password, a birth date cannot be changed. Together with a name and phone number, it makes it easier to fake a call that 'confirms your identity' by reciting your details, or a message about a birthday perk. Someone knowing your birth date is not proof they are genuine. If you use your birth date as a PIN or password, change it.