Skip to content
>_ITDITDWeb Security Platform

Security Guides

Lashinbang data breach (count not disclosed): ID document numbers and bank details may have leaked — what sellers should do

Japanese anime-goods resale chain Lashinbang says ID document numbers, payout bank details and consent-form images from buyback may have leaked. What to do.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 12 min read

For: anyone who has sold items to (used the buyback service of) or bought from Lashinbang, a Japanese chain that resells used anime and manga goods, and any business that buys secondhand goods. This article is based on the company's official notice and does not cover attack or scam techniques.

What buyback customers should do today

1

Check whether you are affected

The company says it is sending individual notices to people whose data may have leaked, in stages. What is affected differs depending on which services you used and how.

If no notice has arrived yet, or you want to know which of your data is involved, open the company's official website yourself and use the dedicated personal-information inquiry form linked from its notices (handled on weekdays, 10:00–18:00 Japan time). Reach it from the official site rather than from a link in an email or text message.

2

Ignore LINE or PayPay invitations and contacts claiming to be the company

The company warns that emails, text messages, letters and phone calls posing as the company or as other parties may arrive, and asks customers not to open the links in them or enter or give out personal information.

In particular, the company says it never sends emails that steer customers to LINE or PayPay (a messaging app and a payment app widely used in Japan) to register. Do not click the links in such emails; delete them (how to spot these: What is phishing?).

3

If your bank details leaked, check your statements and never share your PIN or login

An account number and holder name are details you give out so that people can pay you, and on their own they cannot be used to withdraw money. Withdrawals and transfers require things like your cash card and PIN, or your online banking login and authentication codes.

The thing to watch for is a contact from someone claiming to be your bank, the company or the police who uses your account details to sound genuine and says your account is being misused or a refund needs processing. Never give out your PIN, login details or one-time passwords (single-use authentication codes) by phone or email.

Also check your passbook or banking app for deposits, withdrawals or debits you do not recognize, and contact your bank immediately if you find any.

4

If your ID document number leaked, consider a credit bureau self-declaration

The data at risk is the "type and number" of the identity document. The notice describes it as number information rather than images, but combined with your name, address and date of birth it could be used in applications made in your name.

As a precaution, consider registering a self-declaration with Japan's credit bureaus (CIC, JICC and the Japanese Bankers Association's credit information center). Member lenders and card companies see it during credit checks and review applications more carefully. The steps, and how to request your own credit report to check for unfamiliar contracts, are covered in what Times Car members should do after the breach.

5

Reissuing cards and changing passwords are not required by the notice

The company says no credit card information or passwords leaked, so there is no need to rush to reissue a card or change your password because of this incident alone.

The exception is if a fake email tricked you into entering a card number or password. Contact your card issuer about the card, and change the password straight away. If you use the same password on other services, this is a good moment to separate them (Choosing a password manager).

6

If you paid money or entered details, get help right away

If you sent money or entered bank or card details in response to a suspicious contact, contact your bank or card issuer first.

In Japan you can also call the police consultation line (#9110) or the consumer hotline (188). The sooner you report it, the better the chance of stopping the loss.

What happened (from Lashinbang's notice)

On October 1, 2026, Lashinbang Co., Ltd. posted a notice on its official website titled (in translation) "Important: notice and apology regarding a possible personal information leak due to unauthorized access", together with a Q&A page. Everything below is from the company's announcements.

  1. September 14–16, 2026

    The period of unauthorized access to a service the company operates. After detecting it, the company fixed the system and checked its security, and says no unauthorized access has occurred since.
  2. After discovery

    The company cut off the access, began investigating the cause and scope, and started work to prevent a recurrence. It consulted the police and reported to Japan's Personal Information Protection Commission.
  3. October 1

    The company announced the incident on its website and set up a dedicated inquiry form. It says it is sending individual notices to people whose data may have leaked, in stages.
Not disclosed
Number of people whose data may have leaked
Sep 14–16
Period of unauthorized access (2026)
Bank + ID no.
The most sensitive data that may have leaked
Not leaked
Credit card information and passwords
Data that may have leaked (from the company's notice)
Basic details
Name (including phonetic reading), postal code, address, email address, phone number, date of birth, gender, occupation, member number
Identity
The type and number of identity documents. The company says it does not collect My Number (Japan's individual number)
Bank
The bank name, branch, account number and account holder entered when applying for a buyback
Images
Images of consent forms related to buybacks (the notice does not say which forms or what they show)
Transactions
Buyback details (item names, quantities, unit prices), buyback amounts, order details (item names, quantities, prices), order amounts, payment method, recipient name, preferred delivery date and time, tracking number, points awarded
Not leaked
Credit card information, passwords
Count
Not announced. What is affected differs depending on which services were used and how
Cause
Not disclosed
Reporting
Police consulted; reported to the Personal Information Protection Commission
Contact
The dedicated personal-information inquiry form on the official website (weekdays, 10:00–18:00 Japan time)

What the notice does not say about the consent-form images

The notice only says "images of consent forms related to buybacks". It does not say which forms they are, or whether signatures, addresses or other details appear in them.

The company's buyback guide asks sellers under 18, and students at high-school level or below, to submit a parental consent form. If your child has sold items to the company and you want to know whether a parent's details are included, ask through the dedicated inquiry form.

The mail-in buyback suspension has a different cause

On October 1 the company separately announced that it had paused new applications for mail-in buyback (selling by sending items in). According to the company, this is because a pickup service of its delivery partner, Sagawa Express, has stopped accepting requests; it is a separate notice from the unauthorized access. Sagawa Express's own incident is covered in the Yamato Transport and Sagawa Express breaches.

Why data from buyback customers is especially sensitive

Japan's Secondhand Articles Dealer Act requires licensed dealers who buy used goods to verify the seller. Article 15 says the dealer must confirm the seller's address, name, occupation and age when buying an item.

Transactions with a total value under 10,000 yen are generally exempt. However, video game software, recorded media such as CDs, DVDs and Blu-ray discs, and books require the check regardless of value (Article 16 of the Act's enforcement regulations). Anime-goods buyback often involves exactly these items.

In other words, many buyback customers did not hand over ID details because they chose to trust the shop; they showed ID as a legal step in the sale. Unlike signing up for an online shop, they had little choice about whether to provide this data.

What the leaked data could be used for

  • Calls or emails that quote your account or buyback details to seem genuine
  • Contacts that use a "refund" or "account check" as a pretext to get your PIN or login
  • Applications made in your name using your name, address, date of birth and ID number

What the leaked data alone cannot do

  • Withdraw money using just your account number and holder name
  • Misuse your card or password (the company says these did not leak)
  • Misuse your My Number (the company says it does not collect it)

Because buyback item names, amounts and even tracking numbers may have leaked, a fake contact can quote your real transaction. Correct details are not proof that a message is genuine. The company's Q&A says it cannot tell whether contacts from unfamiliar numbers or addresses are directly related to this incident, and asks customers not to respond to suspicious contacts.

What is still unknown

As of October 3, the number of people affected, the cause, whose ID document numbers leaked, and what the consent-form images show have not been announced. The company says it will continue investigating and will announce any new facts. We will update this article when it does.

For businesses that buy secondhand goods

The cause has not been disclosed, so this section focuses on general points for any business holding the same kinds of data.

1

Separate the records the law requires you to keep, and know for how long

Article 16 of the Secondhand Articles Dealer Act requires dealers to record the transaction date, item and quantity, distinguishing features, the other party's address, name, occupation and age, and the verification method used. Article 18 requires those records to be kept for three years from the date of the last entry.

First, split the data you hold into "required by law" and "kept for business convenience". Delete the legally required records when their period ends, and set a much shorter limit for everything else, such as deleting it once a payout is complete, with automatic deletion rather than manual clean-up.

2

Decide whether to keep payout bank details after the payment is made

The bank account for a buyback payout is needed to make the payment. If you keep it to make the next application easier, let customers choose whether it is saved, and consider deleting it once the payment is complete for those who do not opt in.

3

Store identity-verification records apart from the order and member systems

ID document numbers and consent-form images do not need to be read day to day by order processing or member pages. Keep them in a separate store with separate permissions so that a breach of the member or order system does not take them too, and put multi-factor authentication on admin logins (Choosing multi-factor authentication).

For more on reviewing services that hold identity documents, see the operator section of the Times Car article.

Sources (public record)

The facts in this article are based on the public information below. We have not speculated about the count or the cause, which have not been disclosed.

  • Lashinbang Co., Ltd., notice and apology regarding a possible personal information leak due to unauthorized access (October 1, 2026, Japanese) — lashinbang.com
  • Lashinbang Co., Ltd., Q&A on the unauthorized access and possible personal information leak (October 1, 2026, Japanese) — lashinbang.com
  • Lashinbang Co., Ltd., temporary suspension of pickups for mail-in buyback (October 1, 2026, Japanese) — lashinbang.com
  • Lashinbang Co., Ltd., parental consent form (buyback guide, Japanese) — lashinbang.com
  • ITmedia NEWS report (October 1, 2026, Japanese) — itmedia.co.jp
  • Secondhand Articles Dealer Act, Articles 15, 16 and 18 (Japanese) — e-Gov law search
  • Enforcement Regulations of the Secondhand Articles Dealer Act, Article 16 (exemptions from verification, Japanese) — e-Gov law search

Update history

2026-10-03: First version, based on Lashinbang's notice and Q&A of October 1. We will update it when the count or cause is announced.

FAQ

QWhat was leaked in the Lashinbang breach?
A

According to Lashinbang Co., Ltd.'s notice of October 1, 2026, the data that may have leaked is: name (including the phonetic reading), postal code, address, email address, phone number, date of birth, gender, occupation, the type and number of identity documents, member number, buyback details (item names, quantities and unit prices), buyback amounts, the bank name, branch, account number and account holder entered when applying for a buyback, order details (item names, quantities and prices), order amounts, payment method, recipient name, preferred delivery date and time, tracking number, points awarded, and images of consent forms related to buybacks. The company says what is affected differs depending on which services a customer used and how.

QWere credit cards or passwords leaked?
A

The company says no credit card information or passwords leaked. It also says it does not collect My Number (Japan's individual number) from identity documents.

QHow many people are affected?
A

As of October 3, 2026, no number has been announced.

QHow can I find out whether I am affected?
A

The company says it is sending individual notices to people whose data may have leaked, in stages. If you have not received one, or want to check which of your data is involved, you can use the dedicated personal-information inquiry form linked from the notices on the company's official website (handled on weekdays, 10:00–18:00 Japan time).

QCan someone withdraw money with my leaked account number?
A

An account number and holder name are details you give out so that people can pay you; on their own they cannot be used to withdraw money. Withdrawals and transfers require things like your cash card and PIN, or your online banking login and authentication codes. The real risk is a call or message that uses your account details to seem genuine while trying to get your PIN or login details. Never give those out by phone or email.

QI got an email from 'Lashinbang' pointing me to LINE or PayPay.
A

The company says it never sends emails that steer customers to LINE or PayPay (a messaging app and a payment app widely used in Japan) to register. It asks customers not to click the links in such emails and to delete them.

QWhy did selling items require an ID document?
A

Article 15 of Japan's Secondhand Articles Dealer Act requires a licensed secondhand dealer buying goods to confirm the seller's address, name, occupation and age. Transactions with a total value under 10,000 yen are generally exempt, but video game software, recorded media such as CDs, DVDs and Blu-ray discs, and books require the check regardless of value (Article 16 of the Act's enforcement regulations). That is why many buyback customers had to show an identity document.