Skip to content
>_ITDITDWeb Security Platform

Security Guides

JR East, VIEW Card and JR Kyushu email address leak (eki-net about 1.67 million, VIEW's NET about 4.03 million, JR Kyushu Web members about 1.3 million): Otona no Kyujitsu Club also covers birth date and card expiry — what members should do

On October 9, 2026, JR East, VIEW Card and JR Kyushu said member email addresses may have leaked after unauthorized access to the cloud platform used by their email delivery service. What was exposed and how to handle fake emails.

Published 2026-10-10 Updated 2026-10-10 Last verified 2026-10-10 16 min read

For: people registered with eki-net or Otona no Kyujitsu Club (JR East), VIEW's NET (VIEW Card) or JR Kyushu Web membership, and staff at companies and organisations that use an outside service to send email to their members. This article is based on the official announcements of JR East, VIEW Card and JR Kyushu and on the notices of the cloud service provider where the unauthorized access occurred, and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 10, 2026

Not yet known

  • Whether data actually leaked (currently "cannot be ruled out")
  • Who exactly is affected (VIEW Card is still identifying)
  • How the cloud service provider was breached
  • Whether data was taken
  • When apology emails will be sent
  • When email delivery will resume

All three companies say they will email people who may be affected once ready. The cloud service provider is investigating with an outside security firm and says it will promptly announce any new facts that should be made public. On October 10 we checked the notice pages of the three companies and of the provider; no follow-up had been published.

What members should do today

1

Know whether you could be affected

You may be affected if you are registered with any of the following. The figures are the maximums the companies announced.

  • eki-net members: about 1.67 million (excluding Business eki-net members)
  • Otona no Kyujitsu Club members: about 390,000
  • Users of VIEW Card's member site VIEW's NET: about 4.03 million email addresses (cards with the ii mark and VIEW corporate cards are excluded)
  • JR Kyushu Web members: about 1.3 million

One person may be registered with several services using the same address, so adding the figures does not give a number of people. The three companies say they will email those who may be affected, but prepare with the steps below before that email arrives.

2

Do not log in from links in emails

For the coming weeks, decide that you will not open links in any email or SMS claiming to be from eki-net, VIEW Card, JR Kyushu, JRE POINT and the like. Common pretexts in fake emails include:

  • "Your account has been restricted" or "automatic cancellation of membership"
  • "Your points are about to expire" or "we will refund your points"
  • "You need to re-register your card" or "update your details to verify your identity"

VIEW Card says that if addresses did leak, suspicious emails may be sent to them.

3

To check, use the official app or your own bookmark

If an email worries you, close it and log in through an entry point you open yourself:

  • the official app installed on your phone
  • an official site you bookmarked yourself earlier
  • the notices on the official site, not an ad in search results

If your account really needs action, the same message should appear after you log in or in the official notices. If it does not, you can ignore the email.

4

Do not act on links in apology emails either

The three companies say they will send apology emails to people who may be affected once ready. Because genuine apology emails are expected, fake apology emails become harder to spot.

Read the apology email as a notice that you were in scope, and do not change passwords or enter details on a linked page. Confirm its content by checking that the same guidance appears in the notices on the official site.

5

If you entered details, change and report immediately

If you entered your ID and password on a fake site, change the password through the official app or site. If you use the same password elsewhere, change it there too (see Choosing a password manager).

If you entered a card number or security code, contact your card issuer and ask about blocking and reissuing the card. For VIEW Card, the contact in its announcement is the VIEW Card Center (03-6685-7000, 9:00 to 17:30). Use a phone number you have confirmed on the official site, not one written in an email.

What Otona no Kyujitsu Club members should know

According to JR East, for Otona no Kyujitsu Club members the member number, credit card expiry date and date of birth may also have leaked, in addition to the email address. Card numbers, names, addresses and phone numbers are excluded.

  • Paying online normally requires the card number, so it is unlikely that the expiry date and date of birth alone could be used to make payments
  • On the other hand, a fake email showing your correct member number, date of birth and expiry date looks genuine. Knowing correct details does not make the sender real
  • Fake sites posing as eki-net have in the past been reported to ask for the date of birth, card expiry date and even the security code. Do not go along with any flow that asks you to enter details "for confirmation"
  • If you use your date of birth as a card PIN or password, change it now

What happened (from the three companies' announcements)

JR East, VIEW Card and JR Kyushu each made their announcement on October 9, 2026. All three say the external email delivery service they use to email members was affected by unauthorized access at a cloud service provider. The announcements do not say whether the three companies use the same email delivery service.

  1. October 7, 2026 (Wed), about 3:40 a.m.

    An outage caused by unauthorized access by a third party began in part of the cloud service provider's platform (per the provider). The same day, the provider attributed it to a ransomware attack and cut the affected area off from the network.
  2. October 7

    According to VIEW Card, the company learned that the external email delivery service it uses had become partly unavailable and that email addresses may have leaked.
  3. October 8

    The cloud service provider issued its third report: 495 companies and local governments were affected, and data stored in the affected area is expected to be difficult to retrieve or restore.
  4. October 9

    JR East, VIEW Card and JR Kyushu announced that email addresses and other data may have leaked. Email delivery to members was partly unavailable. The provider published its fourth report, on its response structure.
  5. October 10

    This site checked the notice pages of the three companies and the provider. No follow-up.
What the three companies' announcements tell us
JR East: eki-net
About 1.67 million members (maximum). Email address. Business eki-net members excluded
JR East: Otona no Kyujitsu Club
About 390,000 members (maximum). Email address, member number, credit card expiry date, date of birth
VIEW Card: VIEW's NET
About 4.03 million email addresses. Cards with the ii mark and VIEW corporate cards excluded. Identification of affected people under way
JR Kyushu: JR Kyushu Web members
About 1.3 million (maximum). Email address. Newsletter subject lines and bodies also excluded
Not involved
Name, address, phone number, credit card number and similar (all three)
Stage
Email log data including email addresses "cannot be ruled out" as having been viewed or obtained (JR East, JR Kyushu)
Service impact
Email delivery to members partly unavailable. JR Kyushu cannot send its newsletter
Next steps
Apology emails to people who may be affected once ready (all three). VIEW Card says it will review security measures with the operator of the email delivery service
Contact
VIEW Card Center 03-6685-7000 (9:00 to 17:30; listed in its announcement)

Other companies have also announced impact from the unauthorized access to the same cloud platform. For example, Takashimaya said on October 9 that an outage hit the cloud platform used by the contractor that sends newsletters for its Takashimaya Online Store and other sites, and that member email addresses and other data were held there. The company said that as of October 9 no leak of member information had been confirmed.

What is known and what is not

Status as of October 10, 2026. We will update this table when follow-ups are published.

ItemWhat was announcedStatus
Unauthorized access to the cloud service providerRansomware attack by a third party (per the provider)Confirmed
Impact on the three companies' email deliveryEmail delivery to members partly unavailableConfirmed
Leak of email addresses and other dataCannot be ruled out that data was viewed or obtainedPossible
Items possibly leakedeki-net, VIEW's NET, JR Kyushu Web members: email address. Otona no Kyujitsu Club: email address, member number, card expiry date, date of birthAnnounced
Name, address, phone number, card numberNot at risk (all three)Announced as excluded
Numberseki-net about 1.67M, Otona no Kyujitsu Club about 390K, VIEW's NET about 4.03M, JR Kyushu Web members about 1.3M (all maximums)Upper limits announced
Who exactly is affectedVIEW Card still identifyingUnder investigation
How the breach happenedProvider investigatingUnder investigation
Whether data was takenNot disclosedUnder investigation
Individual apology emailsTo be sent once readyPlanned
Resumption of email deliveryNot disclosedNot decided

What can happen with only an email address

The core item announced is the email address. An email address alone does not let anyone log in to your account or use your card. In general, what can happen is:

  • fake emails posing as eki-net, sent with the knowledge that the address belongs to an eki-net member
  • fake emails about bookings or points timed to busy travel periods (New Year, long weekends)
  • if you use the same address for several services, being targeted across all of them

Fake emails posing as eki-net were being reported repeatedly well before this incident. Whether this incident increases them is unknown, but the response is the same either way.

JR East

eki-net, Otona no Kyujitsu Club

VIEW Card

VIEW's NET

JR Kyushu

JR Kyushu Web members

↓ member email handed to an outside service (addresses and other data passed on)

External email delivery service

Holds recipient addresses and delivery records (logs)

↓ runs on

Cloud service provider's platform

Ransomware attack on October 7; 495 companies and local governments affected (per the provider)

How it happened. The problem was not in the three companies' own systems but in the cloud platform used by the outside service they relied on to send email.

This site's view: a correct member number or birth date is not proof

For Otona no Kyujitsu Club, details normally used only between the member and the company (member number, date of birth, card expiry date) were involved this time, in addition to the email address. When such details appear correctly in a message, it is easy to believe it is genuine.

Base the decision not on whether the details are right but on where you opened the page. If the same notice does not appear in the official app or bookmarked site you opened yourself, do not act on the email, however accurate it is. This rule works the same way whichever company an email claims to be from.

For companies and organisations that outsource member email

The cause has not been disclosed in detail, so this section does not judge the cloud service provider's security. What the published facts do show is that what you hand to your email delivery vendor decides how much is at stake if it leaks. In this incident, some services had handed over only email addresses, while another also had dates of birth and member numbers at the vendor.

1

List the items you hand to the vendor

For each service, list the items you pass to your email delivery service. Besides recipient addresses, check whether names, member numbers, dates of birth, point balances or card expiry dates are passed on to be merged into message bodies.

Also check whether delivery records (send logs) or the bodies of past emails remain with the vendor. JR East and JR Kyushu describe the data that may have leaked as "email log data".

2

Hand over fewer items, and set log retention

Stop passing items that are not needed for merging. Even if a birthday email needs a date, consider whether a derived value such as "birthday this month" would do instead of the date of birth itself.

Set a retention period in the contract for send logs and mailing lists held by the vendor, and have them deleted when it expires. Also make sure addresses of members who have left are not still on the list.

3

Know which cloud your vendor uses

As here, problems can arise not at the vendor itself but on the cloud platform the vendor uses. Ask the vendor for a list of the clouds where it keeps your data and of any subcontractors, and for the deadline by which it will tell you about outages or leaks.

Under Japan's Act on the Protection of Personal Information, a business that entrusts the handling of personal data must supervise the entrusted party. Reporting duties and notifying individuals are covered in the TEMAIRAZU case.

4

Prepare another way to reach members when the service is down

All three companies found email delivery to members partly unavailable, while they still need to send apology emails to those affected. Decide in advance how you would notify people when the delivery service is unavailable (notices on the member site or app, a backup delivery route).

The cloud service provider says data in the affected area is expected to be difficult to retrieve or restore and can be restored only from customers' own backups. Keep the master copy of your mailing list on your side, so it does not exist only at the vendor (see Backup essentials).

How customers can prepare for an incident at their provider is covered in When your web hosting provider is breached, and ransomware itself in What is ransomware.

Sources (public records)

The facts in this article are based on the public information below. We have not speculated about undisclosed numbers, the intrusion method or whether data was taken. In line with this site's policy, the cloud service provider and the email delivery service are referred to by role in the text.

  • East Japan Railway Company, "On the possible leak of email addresses and other data from an external email delivery service following unauthorized access at [the cloud service provider]" (October 9, 2026, Japanese) — jreast.co.jp
  • VIEW Card Co., Ltd., "On the possible leak of email addresses from an external email delivery service following unauthorized access at [the cloud service provider]" (October 9, 2026, Japanese) — jreast.co.jp
  • Kyushu Railway Company, "On the possible leak of email addresses and other data following unauthorized access at [the cloud service provider]" (October 9, 2026, Japanese) — jrkyushu.co.jp
  • Cloud service provider, "[Report 2] Unauthorized access to some systems of our service" (October 7, 2026, Japanese) — idcf.jp
  • Cloud service provider, "[Report 3] Outage caused by unauthorized access to some systems of our service" (October 8, 2026, Japanese) — idcf.jp
  • Cloud service provider, "[Report 4] Our response structure for the outage caused by unauthorized access" (October 9, 2026, Japanese) — idcf.jp
  • Takashimaya Co., Ltd., apology and notice on suspending the Takashimaya Online Store, TBEAUT and Takashimaya Fashion Square newsletters (October 9, 2026, Japanese) — takashimaya.co.jp
  • Earlier example of fake emails posing as eki-net: INTERNET Watch, warning about phishing emails impersonating JR East with the subject "[eki-net] Confirmed information" (January 5, 2022, Japanese) — internet.watch.impress.co.jp

Update history

2026-10-10: First version, based on the October 9 announcements by JR East, VIEW Card and JR Kyushu and on the cloud service provider's reports 1 to 4 (October 7 to 9). No follow-up as of October 10.

FAQ

QWhat was leaked?
A

According to the companies' announcements of October 9, 2026, only email addresses may have leaked for eki-net members (excluding Business eki-net members), VIEW's NET users and JR Kyushu Web members. For Otona no Kyujitsu Club members, four items are involved: email address, member number, credit card expiry date and date of birth. In every case the companies say they cannot rule out that the data was viewed or obtained; none says a leak has been confirmed.

QAm I affected?
A

The maximum numbers are about 1.67 million eki-net members, about 390,000 Otona no Kyujitsu Club members, about 4.03 million VIEW's NET email addresses and about 1.3 million JR Kyushu Web members. VIEW Card says cards with the ii mark and VIEW corporate cards are excluded, and that it is still identifying who is affected. All three companies say they will email people who may be affected once ready. If you are a member of any of these services, act as if you could be affected even before that email arrives.

QWere passwords or card numbers leaked?
A

All three companies say names, addresses, phone numbers and credit card numbers were not at risk. Passwords are not listed among the items involved. But if a fake email leads you to a fake login page and you enter your ID, password or card number there, they will be stolen at that point. If you already did, change your password through the official site and contact your card issuer.

QWhat caused it?
A

The companies say the external service they use for email delivery was affected by unauthorized access at a cloud service provider. That provider has said the outage that began at about 3:40 a.m. on October 7 was caused by a ransomware attack by a third party, and that 495 companies and local governments using the affected service were impacted. As of October 10, how the attackers got in and whether data was actually taken have not been disclosed.

QWhat should I do if I get an email claiming to be from eki-net or VIEW Card?
A

Do not open links in the email. Log in through the official app or an official site you bookmarked yourself, and check the notices and your account status there. Emails that rush you with reasons such as account suspension, automatic cancellation of membership, points expiring or being refunded, or re-registering your card are typical of fakes. Treat the apology emails the companies plan to send in the same way: do not complete any procedure from a link, and confirm the content in the notices on the official site.

QI am an Otona no Kyujitsu Club member. What can happen if my date of birth and card expiry date leaked?
A

According to JR East, card numbers are not involved. Using a card online normally requires the card number, so it is unlikely that the expiry date and date of birth alone could be used to make payments. The real concern is that a fake email showing your correct member number, date of birth and expiry date looks genuine. Correct details are not proof that a message is real. If you use your date of birth as a PIN or password, change it now.