Skip to content
>_ITDITDWeb Security Platform

Security Guides

Unauthorized Access to Lawson ID (2,155,345 Records): Email Addresses and Names Leaked — What Members and App Reservation Users Should Do

On October 8, 2026, Lawson said personal data from 2,155,345 Lawson ID records and 26 Lawson App Reservation records leaked through unauthorized third-party access. What leaked, what affected people should do today, and what is still unknown, based on the official notice.

Published 2026-10-10 Updated 2026-10-10 Last verified 2026-10-10 12 min read

For: anyone with a Lawson ID (the account used for Lawson's apps and web services), anyone who reserved products through Lawson App Reservation, and anyone who runs a member app or web service. This article is based on Lawson, Inc.'s official notice and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 10, 2026

Not yet known

  • Details of the mechanism that was misused
  • How the company noticed the access
  • Progress of the individual notification emails
  • Reopening date of Lawson App Reservation

The notice does not say that further investigation results will be published. For Lawson App Reservation, the company plans to reopen in mid-October and says it will announce the reopening on its website. As of October 10, there was no follow-up notice.

What Lawson ID holders should do today

1

Do not open links in emails or texts claiming to be Lawson

Email addresses and names leaked, and for some people phone numbers and addresses too. The company asks people to be careful with suspicious emails, texts and calls sent to the contact details registered to their Lawson ID.

Fake messages imitating Lawson existed before this incident. In June 2026 the company warned about fake websites that pose as giveaways or free-voucher campaigns to collect personal data. Whether a message says "your points are expiring", "claim your coupon" or "you have won", do not open the link and do not enter your ID, password or card details (how to tell: What is phishing?).

2

Even if a notification email arrives, check through the official app

Lawson says it is contacting affected people individually from "Lawson ID Mail" (lawson_id@mailservice.lawson.jp), and it has posted a notice in the Lawson app.

The sender shown on an email can be faked, though. Lawson itself, in a separate notice on October 1 (about its mail server being misused), wrote that the sender display alone may not tell you whether a message is genuine. Even if a notification looks real, check through the official app on your home screen or a bookmark, not through the links in the email.

3

Passwords are not among the leaked items, so focus on where you type yours

Passwords are not among the items the company says leaked, and it has not asked people to change them.

What is more likely to happen is a fake login page sent to a leaked email address, where you type your password yourself. Logging in only through the official app largely removes that risk. If you use your Lawson ID password on other services too, make them different regardless of this incident, so a leak somewhere else does not spread (a password manager makes this practical).

4

The 26 App Reservation users should check their card statements

For Lawson App Reservation, the leaked items are name, phone number and part of the credit card number. The company says no misuse has been confirmed. A partial number is generally not enough to shop online, but check your statements and contact your card issuer about any charge you do not recognize. If someone calling as your "card company" asks for the rest of the number or your PIN, do not answer.

5

Send questions to the contact listed in the official notice

The contact listed in the notice is the dedicated form of the Lawson Customer Center (lawson-faq.lawson.co.jp). No phone number is given. For people who have already entered information into a fake message, the company's June warning advises consulting the nearest police station or the prefectural police cybercrime consultation desk.

What happened (per Lawson)

The following is based on Lawson's notice of October 8, 2026.

  1. September 12–14, 2026

    Lawson ID was accessed without authorization (per the company's investigation).
  2. September 17

    Lawson App Reservation was accessed without authorization (per the company's investigation).
  3. October 7

    An investigation by the company found the unauthorized access above.
  4. October 8

    The company published an apology and notice. It says it blocked suspicious access sources, suspended App Reservation, posted a notice in the app, began contacting affected people individually, and reported to the Personal Information Protection Commission and other bodies.
  5. As of October 10

    No follow-up notice. App Reservation is planned to reopen in mid-October.
2,155,345
Lawson ID records confirmed leaked
26
App Reservation records (including partial card numbers)
None confirmed
Misuse or secondary harm (as of the Oct 8 notice)
Suspended
Lawson App Reservation (reopening planned mid-October)
Data that leaked (per Lawson)
Lawson ID
2,155,345 records. Email address, name
Only for people who entered them
Gender, phone number, address, newsletter preference (if entered, for example when applying for a giveaway with Lawson ID)
Lawson App Reservation
26 records. Name, phone number, part of the credit card number
Not listed
Passwords, the full card number, expiry date and security code are not listed among the leaked items
Cause as described
A system related to the Lawson app was misused. A mechanism meant to show information only to the user themselves in the app was accessed without authorization by a third party
Other impact
The company confirmed no other unauthorized access and no malware infection
Prevention measures
Stronger security for the affected systems, stronger monitoring, and a stronger incident response setup

What is known and what is not

Status as of October 10, 2026. When a follow-up appears, the status column will be updated.

ItemWhat the notice saysStatus
Period of unauthorized accessLawson ID: September 12–14. App Reservation: September 17Confirmed (per the company's investigation)
Lawson ID records and items2,155,345. Email address, name (plus gender, phone, address, newsletter preference if entered)Leak confirmed
App Reservation records and items26. Name, phone number, part of the card numberLeak confirmed
PasswordsNot listed among leaked items. No request to change themNot listed
CauseMisuse of an app-related system. The mechanism that shows users their own information was accessed without authorizationDescribed (details not disclosed)
What the flaw was and how it was misusedNot covered in the noticeNot disclosed
Misuse or secondary harmNot confirmed as of October 8None confirmed
Contacting affected peopleIndividual emails from Lawson ID Mail, one after anotherIn progress
App Reservation reopeningPlanned for mid-October, to be announced on the websitePlanned

'Not confirmed' does not mean 'will not happen'

The company's statement that no misuse or secondary harm has been confirmed describes the situation on October 8. Fake messages using leaked email addresses and names can arrive some time after a leak. For at least the next few months, keep the habit of not opening Lawson messages through their links.

What email addresses, names and phone numbers can be used for

In general, the following combinations make the following kinds of misuse possible. This does not mean it has happened in this case.

  • Email address + name: "points expiring", "you have won" or "apology" emails with your correct name, which look more genuine
  • Phone number + name: texts or calls claiming to be Lawson or a delivery company
  • Address + name: fake letters or postcards
  • Name + phone number + partial card number: a fake "card company" call that confirms "the last digits are …" to sound genuine, then asks for the rest of the number or the PIN

A similar case where names and email addresses leaked from a member app is the MrMax app and online store incident announced on October 6, 2026. What readers should do is the same for this combination of data.

For people who run a member app: how to check features that show users their own data

Lawson says the mechanism meant to show information only to the user themselves in the app was accessed without authorization. It has not disclosed what the flaw was or how it was misused. This section does not assess Lawson's system or response; it covers what operators with the same kind of feature can check in their own service.

Many apps have features that return the logged-in user's own data: a "my page", member details, reservation or order history. For this kind of feature, the server generally needs to check, on every request, that the owner of the data being returned is the person who is logged in. If the server trusts a member number sent in the request and returns that member's data, changing the number returns someone else's data. This type of flaw is called IDOR, and it happens when checking who someone is (authentication) is confused with checking what they may see (authorization) — see authentication vs. authorization. Lawson has not said that this was the cause.

App: "Show my member details"

↓

Server: who is logged in?

Decided from the login session, not from a member number in the request

↓

Return only that member's data

Monitoring: number of different members shown per login or per source

For an "own data" feature this is normally one. Alert at two or more

What the server checks in a feature that shows users their own data (general design)
1

List every feature that returns the user's own data, and check that ownership is verified on the server

Write down every feature that returns the logged-in user's data: my page, member details, reservation and order history, point balance, coupon list. Include the APIs (the endpoints the app uses to fetch data from the server) behind the app.

For each one, check that the owner of the returned data is decided from the login session. Where a member number sent by the app is used, change it so that it is checked against the logged-in member on every request. At the same time, check whether the response includes fields the screen never shows.

2

Count how many different members each login was shown, and alert at two or more

A feature that shows users their own data, used correctly, involves exactly one member per login. So from the access records of that feature, count how many different members' data was returned per login (or per source) per hour.

Normal use gives one, so alert the person in charge at two or more. Monitoring by volume misses slow, small-batch retrieval; this count flags the very first record that does not fit. If your records do not show whose data was returned, start by recording that.

3

Make features switchable one at a time

After finding the problem, Lawson suspended the App Reservation feature. In a member service, a switch that turns off one feature while others keep running shortens the time between discovery and containment.

This site's view: features meant to show only one user's data are the easiest to monitor

Volume-based monitoring struggles to separate abuse from normal load. A feature that shows users their own data has a clear normal shape — one member per login — so counting distinct members is enough to spot something wrong. In the Lawson ID case, about three weeks passed between the unauthorized access (September 12–14) and its discovery (October 7). This kind of count is a cheap way for operators to notice first.

Sources (public record)

The facts in this article come from the public records below. Undisclosed techniques are not speculated on.

  • Lawson, Inc., notice of apology regarding a personal data leak caused by unauthorized third-party access (October 8, 2026, Japanese) — lawson.co.jp
  • Lawson, Inc., notice on suspicious emails sent through misuse of the company's mail server (October 1, 2026, a separate notice, Japanese) — lawson.co.jp
  • Lawson, Inc., warning about suspicious emails and fake websites imitating Lawson (June 5, 2026, Japanese) — lawson.co.jp

Update history

2026-10-10: First version, based on Lawson's October 8 notice (no follow-up as of October 10). Will be updated when the App Reservation reopening or further investigation results are announced.

FAQ

QWhat leaked from Lawson ID?
A

According to Lawson's notice of October 8, 2026, the company confirmed that 2,155,345 Lawson ID records leaked, containing email address and name. For people who had entered them, for example when applying for a giveaway, gender, phone number, address and newsletter preference are also included. In Lawson App Reservation, 26 records leaked, containing name, phone number and part of the credit card number. Passwords are not among the listed items.

QAm I affected?
A

Lawson says it is contacting affected people individually, one after another, by email from 'Lawson ID Mail' (lawson_id@mailservice.lawson.jp). Because the sender shown on an email can be faked, check through the official app or website you open yourself rather than through links in the email. Questions can be sent through the dedicated form of the Lawson Customer Center (lawson-faq.lawson.co.jp).

QShould I change my password?
A

Passwords are not among the items the company says leaked, and it has not asked people to change them. The realistic risk here is a fake login page sent to a leaked email address, where you type your password yourself. Log in through the official app you open yourself. If you use the Lawson ID password on other services too, it is worth making them all different regardless of this incident.

QWhat caused it?
A

The company says the incident is believed to have been caused by misuse of a system related to the Lawson app, and that a mechanism meant to show information only to the user themselves in the app was accessed without authorization by a third party. It has not disclosed what the flaw was or how the system was misused. It says it confirmed there was no other unauthorized access and no malware infection.

QWhat if I get a message claiming to be Lawson or offering points or coupons?
A

Lawson asks people to be careful with suspicious emails, text messages and calls sent to the contact details registered to their Lawson ID. Even if a message says your points are expiring, a coupon is waiting or you have won something, do not open the link and do not enter your ID, password or card details. Check in the official app you open yourself. If you have already entered information, Lawson's guidance is to consult the police cybercrime consultation desk.

QI am one of the 26 App Reservation users whose partial card number leaked. Should I cancel my card?
A

Only part of the card number leaked, and the company says no misuse has been confirmed. A partial number is generally not enough to shop online, but check your statements and contact your card issuer about any charge you do not recognize. A name, phone number and partial card number together can make a fake call from a 'card company' sound genuine, so do not give card details or a PIN over the phone.