Security Guides
EPARK Relax & Esthe "PeakManager" data breach (about 22.18M records): health notes leaked too — what salon customers should do
A breach of PeakManager, a booking system used by massage and relaxation salons in Japan, sent about 22.18M customer records outside. You may be affected without using EPARK.
For: anyone who has visited a massage, relaxation or esthetic salon in Japan, salons that keep their customer ledger in a cloud service, and companies that provide business systems to such shops. This article is based on the operator's official notices and does not cover attack or scam techniques.
What customers should do today
Work out whether you may be affected — how you booked does not matter
The company explains that PeakManager is a ledger in which each salon enters and manages its own customer data; only the name is required, and phone number and email address are optional.
So even if you only booked by phone or walked in, you may be included if the salon entered your name or contact details into PeakManager. People who never used the EPARK website or app are not excluded.
No list of salons using PeakManager has been published. If you are unsure, ask the salon you use, or contact the operator's helpline listed below.
Do not use links or phone numbers in messages claiming to be from a salon, EPARK or the operator
The leaked data combines name, address, date of birth, phone number and email address, and shows which salon you used. That is enough to build convincing messages offering "an apology coupon", "a booking confirmation" or "a points refund".
The company says it will never ask for card numbers or security codes by email or SMS in connection with this incident. If you get such a message, do not open the links; check through the salon's official website or a phone number you already knew (see What is phishing?).
If you set a password on an online booking My Page, change it
In its first notice the company said that passwords for the PeakManager customer My Page may have leaked in encrypted form, and asked customers to change them.
If you remember creating a My Page through a salon's online booking, change that password. If you are not sure where you created it, ask the salon whether its booking My Page runs on PeakManager.
Change the same password on other services
The encryption method has not been published. Depending on the method, the original password could be worked out (see What is password hashing? for the difference).
If you use the same password for email, online shopping or other services, change it there too. A password manager is the practical way to keep a different password for each service.
Check who you are talking to before discussing your health or salon visits
The leaked notes field holds handover notes that salons wrote for treatments. According to the company, it partly contains health conditions and other sensitive personal information (a category defined in Japanese law, such as medical history, that requires special care).
A caller who knows your physical condition or which salon you go to is easy to believe. Even if they get the details right, that alone does not make them genuine. If you are asked to buy something or pay, do not decide on the spot; hang up. In Japan you can consult the consumer hotline (188).
Ask salons you no longer use to delete your data
Japan's Act on the Protection of Personal Information lets individuals request that use of their data be stopped or the data deleted when a reportable leak has occurred (Article 35(5)).
Each salon manages its own customer ledger. If a salon you no longer visit still holds your data, you can ask it to delete it.
What happened (from the operator's notices)
EPARK Relax & Esthe Co., Ltd. published a first notice on July 31, 2026 and a second notice on September 24. It is a consolidated subsidiary of EPARK Inc. Everything below comes from the two companies' official notices.
July 27, 2026
The company confirmed unauthorized access to part of the PeakManager database and that stored customer data had been deleted.July 30
Reported to Japan's Personal Information Protection Commission.July 31
First notice: about 33 million records may have leaked (not the same as the number of people). Customers asked to change passwords. Data restored, switched to a backup database, the misused database connection account stopped, credentials changed, and migration to a new server and database completed.August 4
Parent company EPARK Inc. stated that its own systems and those of other EPARK companies were not accessed.September 24
Second notice: an investigation by an outside specialist firm confirmed that database contents were transferred outside. About 22.18 million records after removing duplicates. Disclosed that the notes field contained health conditions and five entries that may be card data.
- Scope
- Customer data registered by salons using PeakManager. About 22.18 million records (about 33 million in the first notice). A count of records, not people
- Items
- Name, phonetic reading of the name, date of birth, gender, address, phone number, email address, notes field (treatment handover notes and the like). Not every record has every item
- Sensitive personal information
- The notes field partly contains health conditions and similar details
- Passwords
- The first notice said encrypted passwords for the customer My Page may have leaked and asked for them to be changed. The encryption method has not been published
- Card data
- No field for it. However, the notes field contained five entries that may be card data (not confirmed as real cards; all expired)
- My Number
- The first notice said the affected database did not contain My Number (Japan's national ID number) data
- Cause
- Misuse of a database connection account. Data was transferred outside, then deleted. Intrusion route and method not disclosed (to avoid inviting similar attacks)
- Contact
- EPARK Relax & Esthe Co., Ltd., PeakManager division, 0120-206-460 (weekdays 10:00–17:00, Japan)
How to read the figures: records are not people
The company explains that because each salon registers its customers separately, the same person can appear in several salons' ledgers, sometimes with their name written differently.
Records with matching phone numbers or email addresses were merged as one person, but where neither was registered, records with the same name were kept separate. So the 22.18 million figure is a count of records, not people; the company judged it difficult to convert into an accurate number of people and has reported this to the Personal Information Protection Commission.
Why people who never used EPARK are included
Salon A
booked by phone
Salon B
filled in a form in store
Salon C
booked online
↓ each salon enters its own customers
PeakManager customer database
name, contact details, date of birth, notes (health etc.)
↓ misuse of a database connection account
Customer data transferred outside
about 22.18 million records
When most people give a massage salon their name and phone number, they think they have given it to that salon. In practice it also sits in the database of the company that runs the salon's booking system.
This setup is convenient for salons, which do not need to build their own booking ledger. But because one database holds the customers of many salons together, a single breach affects customers of unrelated salons all at once.
Who may be affected
- People who booked through EPARK (if the salon uses PeakManager)
- People who only booked by phone or in person (if the salon registered them)
- People who told a salon about their health on a first-visit form
Where the notices found no impact
- Systems of EPARK Inc. and the other EPARK companies
- The operator's systems other than PeakManager
- My Number data
For a similar case in which notices came from a company most recipients had never heard of, see the Aesto Health breach.
What is still unknown
As of October 3, the number of people affected, which salons' customers are included, the password encryption method and the intrusion route have not been published. The second notice also says nothing about individual notification. This article will be updated when more is published.
For salons, and for companies that build systems for them
Salons that keep their customer ledger in a cloud service
Decide what may go in the notes field
In this case the notes field, meant for treatment handover notes, ended up holding health conditions and even entries that may be card data. A free-text field with no rules collects anything.
Agree in your shop what may be written (for example, areas to avoid during treatment) and what may not (card numbers, detailed diagnoses and the like), and do not copy paper intake forms into it word for word.
Be ready to explain to your own customers
From the customer's point of view, the salon is who they gave their data to. Do not just wait for the operator's notice; know which system your shop uses and which items you registered, so you can answer questions.
A salon's legal responsibility depends on its contract and how it uses the service. If unsure, check with the Personal Information Protection Commission's consultation service or a similar adviser.
Companies that provide systems to shops
List the database connection accounts that can read the whole customer table
What the company stopped was a misused database connection account. If one account can read every salon's customers, leaking that account's credentials is enough to take everything.
As a first step, list the connection accounts used by the application, operations and analytics, and write down which tables each can read and how many rows. Remove bulk-read rights from any account that does not need them.
Set read-volume alerts on the database side
Normal use of the application screens reads one salon's data at a time. Configure the database audit log or your cloud monitoring to alert when a single connection account reads several salons' customer data in a short time. Start by measuring the largest normal overnight batch and alerting above that level.
Keep backups where production credentials cannot delete them
In this case the data was deleted after being transferred, and the company has switched to a backup database and completed restoration.
In general, if the account that connects to the production database can also delete backups, you lose your way back along with the data. Check that production credentials cannot delete backups. See Backup essentials: the 3-2-1 rule and a recovery plan.
Hold data in a way that lets you decide who to notify
Here only the name was required and phone and email were optional, so the same person could not be identified and the leaked records could not be converted into a number of people. Without that, contacting individuals is hard too.
Collecting no more than you need and being able to reach the people concerned after a leak both have to be designed for. At minimum, make sure you can reliably trace which salon registered which record, so notification through the salons remains possible.
For the minimum controls an organization should have, see Where is an organization's security minimum?; for how services should store passwords, see How to store passwords safely.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed details of the intrusion and the number of people affected are not speculated on.
- EPARK Relax & Esthe Co., Ltd., notice of a possible personal data leak due to unauthorized access (first notice, July 31, 2026, Japanese) — epark-relax.co.jp
- EPARK Relax & Esthe Co., Ltd., notice of unauthorized access and personal data leak (second notice, September 24, 2026, Japanese) — epark-relax.co.jp
- EPARK Inc., notice on the data leak at EPARK Relax & Esthe (August 4, 2026, Japanese) — epark.jp
- ScanNetSecurity (August 21, 2026, Japanese) — scan.netsecurity.ne.jp
- Act on the Protection of Personal Information, Article 35 (Japanese) — e-Gov law search
Update history
2026-10-03: First version, based on EPARK Relax & Esthe's first notice (July 31) and second notice (September 24) and EPARK Inc.'s notice of August 4. Will be updated when the number of people or individual notification is announced.
Read next
- Follow-on scams: What is phishing? / Fake virus warnings (tech-support scams)
- Passwords: Choosing a password manager / What is password hashing?
- Similar cases: Aesto Health (US, notice from an unfamiliar company) / Booking.com (booking details)
- Other Japanese cases in 2026: Times Car (driver's licence images) / Abahouse (order details and fake refund emails)
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat leaked in the PeakManager breach?
According to EPARK Relax & Esthe Co., Ltd.'s second notice of September 24, 2026, the leaked items are name and phonetic reading, date of birth and gender, address, phone number and email address, and the notes field where member salons recorded handover notes for treatments. The notes field partly contains health conditions and other information classed as sensitive personal information under Japanese law. Not every record contains every item. The first notice of July 31 said encrypted passwords may have leaked and asked customers to change them.
QCan I be affected if I never used EPARK?
Yes. The company explains that PeakManager is a ledger in which each salon enters and manages its own customer data. If you booked by phone or in person and the salon entered your name or contact details into PeakManager, you may be included regardless of how you booked. No list of salons using PeakManager has been published, so if you are unsure, ask the salon you use or contact the company's helpline.
QIs it 33 million or 22.18 million?
Both figures come from the company, and both are numbers of data records, not people. The first notice gave about 33 million records; treating records with matching phone numbers or email addresses as the same person and removing duplicates left about 22.18 million. Where no phone number or email address was registered, records with the same name were kept separate, so the company judged it difficult to convert the figure into an accurate number of people and has reported this to Japan's Personal Information Protection Commission.
QShould I change my password?
Yes. In its first notice the company said that passwords used to access the PeakManager customer My Page may have leaked in encrypted form, and asked customers to change them. The encryption method has not been published. If you used the same password on other services, change those too.
QWas card data leaked?
PeakManager has no field for card data by design. However, the second notice corrected the first: five entries in the notes field may be card information. The company has not confirmed whether they belong to real cards, and all are past their expiry dates. It says it will never ask for card numbers or security codes by email or SMS in connection with this incident.
QWhat caused the breach?
According to the company, a third party misused a database connection account, transferred data from the database holding customer information to outside, and then deleted the data. The deleted data has been restored. The company is not publishing the specific intrusion route or method, saying doing so could invite similar attacks. It found no trace of impact on its other systems.
QWas the EPARK booking site itself breached?
On August 4, 2026, the parent company EPARK Inc. stated that the incident occurred in PeakManager and that there was no unauthorized access to the systems or data infrastructure of EPARK Inc. or the other companies operating under the EPARK brand.