Skip to content
>_ITDITDWeb Security Platform

Security Guides

MrMax app and online store breach (up to about 1.74 million people): names, emails and phone numbers leaked — what members should do

Unauthorized access to the servers of the MrMax app and online store leaked member IDs, names, emails and phone numbers of up to 1,735,154 people. What leaked, what did not, and what to do today.

Published 2026-10-06 Updated 2026-10-06 Last verified 2026-10-06 10 min read

For: people registered with the MrMax app or the MrMax online store in Japan, and anyone who runs a membership service. This article is based on the official notice from MrMax Co., Ltd. and does not cover attack techniques.

What members should do today

1

Do not follow links or instructions in emails, texts or calls claiming to be MrMax

The leaked data combines member ID, name, email address and phone number. With all of that, a scammer can send a message with your correct name and member ID.

If you get a message about "apology coupons", "bonus points", "re-registering your member details" or "refund procedures", do not open the link; open the app or official site yourself to check. Fake text messages (smishing) are handled the same way (see What is phishing?).

2

Never give anyone your password or card number

The company says it will never ask for your password or credit card number. It also says it confirmed that passwords and credit card data did not leak.

A caller who knows your name and member ID is not proven genuine by that. Those are exactly the details that leaked. If someone asks for a card number or password in the name of an apology or refund, treat it as fake.

3

Judge the company's apology email by its content, not its sender

The company says it will contact affected members individually by email, sent from noreply@mrmax.jp. That differs from the domain of its website (mrmax.co.jp), but it is the sender the company itself has announced.

Sender addresses can be faked, though. Even if the sender looks right, the simplest rule is never to log in or enter anything through a link in the email.

4

If you reuse the same password elsewhere, separate them

The company says passwords did not leak, so according to the notice there is no need to change yours right away.

If you use the same password as your MrMax account on other services, though, separate them now. A password manager is the realistic way to do the inventory. You can check whether a reused password appears in past leaks with How to check if your password was leaked.

5

Stay alert to unknown calls and texts for a while

You can create a new email address, but a phone number is not easy to change. The leaked numbers may receive scam calls and texts for a long time, including ones that have nothing to do with MrMax.

Turning on your phone's spam call and spam text filters reduces how many get through (background: Smartphone security basics). The company also asks members to watch for suspicious postal mail, although it says addresses did not leak.

6

Contact the company only at the address on its official site

The company gives an email address for inquiries about this incident (incident-desk@mrmax.co.jp). Use the contact details in the notice on MrMax's official website, not ones given in a message you received.

What happened (from MrMax's notice)

MrMax Co., Ltd. published its apology and notice on October 6, 2026. Everything below is as stated in the company's notice.

  1. Oct 3, 2026 (Sat), evening

    Suspicious access to the company's server was noticed. The company suspended the service immediately and blocked outside access the same day.
  2. Subsequent investigation

    It was found that a third party had misused a function of the software that makes up the service to get into the server, and that part of members' personal data had leaked.
  3. Oct 6

    Apology and notice published. The company said it had reported to the Personal Information Protection Commission and consulted the police.
Up to 1,735,154
People affected (members as of Oct 3)
4 items
Member ID, name, email address, phone number
Not leaked
Address, date of birth, card data, password, purchase history
None found
Harm from misuse of the leaked data (at the time of the notice)
What leaked (from MrMax's notice)
Services
MrMax app and online store
Who
MrMax app members and online store members, up to 1,735,154 people (those registered as of October 3, 2026)
Items leaked
Member ID, name, email address, phone number; varies with what each member registered
Not leaked
Address, date of birth, credit card data, password, purchase history
Cause (company's account)
A third party misused a function of the software that makes up the service to get into the server. The specific software or function has not been disclosed
Harm
No harm from misuse of the leaked data confirmed at the time of the notice
Response
The access route was blocked. Investigation with an outside specialist organization; monitoring strengthened
Member notification
Individual emails to affected members, sent from noreply@mrmax.jp

What the leaked items can be used for in combination

None of these items is rare on its own, but together they make scam messages look genuine. Addresses and dates of birth were not included this time; what stands out is that a name leaked together with two ways to reach you (email and phone).

Name + email + member ID

↓

Fake apology or coupon emails with your correct name and member ID

→ Do not open links; check in the official app

Name + phone number

↓

Fake texts and calls that use your name

→ Never give passwords or card numbers; use spam text filters

Combinations of the leaked items and the matching step for members

Not leaked, according to the company

  • Address
  • Date of birth
  • Credit card data
  • Password
  • Purchase history

Leaked (varies by member)

  • Member ID
  • Name
  • Email address (changeable, but a hassle)
  • Phone number (not easy to change)

How to read it: 'no harm confirmed' does not mean 'safe from now on'

The company says no harm from misuse of the leaked data had been confirmed at the time of the notice. That means nothing has been found yet, not that the data will never be used.

Phone numbers often stay the same for years, so they can be used in scam messages months or years later. Stay alert to messages that use this incident as a reason to contact you.

For those who run membership services

According to the company, the intrusion misused "a function of the software that makes up the service". Which software or function has not been disclosed, so this section sticks to points that any service with a similar setup can review. Capping and alerting on how many records are read is covered in the Yakiniku King app breach; here we add two angles specific to this notice: unused functions, and detection at the weekend.

1

List the software that makes up the service, and its functions

An app or online store is built from several pieces of software: an e-commerce package, admin screens, plugins and external libraries. Start by listing which software and which version you run. Free tools such as osv-scanner can check dependencies for known vulnerabilities on a schedule.

Beyond versions, also list the functions that run on the server: file uploads, bulk import and export, admin APIs, debug output and so on.

2

Turn off functions you do not use, and limit the rest to internal access

Functions that are on by default but never used are safest switched off. If you keep an admin function, do not leave it open to anyone on the internet; restrict where it can be reached from and require multi-factor authentication.

Risky defaults for each framework are collected in Security by framework.

3

Decide how to go from detection to blocking at weekends and at night

The company says it noticed suspicious access on a Saturday evening, suspended the service immediately and blocked outside access the same day. To be able to do the same on a holiday, decide in advance who receives alerts and who decides to stop the service.

As a first step, record each hour how many rows are read from the member database and how admin functions are used, and send an alert to the person on call when the numbers differ sharply from normal (background: Rate limiting and abuse control).

Sources (public record)

The facts in this article come from the public source below. Undisclosed methods or causes of the intrusion are not speculated on.

  • MrMax Co., Ltd., apology and notice regarding the leak of information due to unauthorized access (October 6, 2026, Japanese) — mrmax.co.jp (a PDF with the same content is also posted)

Update history

2026-10-06: First version, based on MrMax's notice of October 6. The company says it is investigating with an outside specialist organization and will announce any new facts; this article will be updated when they are published.

FAQ

QWhat was leaked in the MrMax breach?
A

According to MrMax Co., Ltd.'s notice of October 6, 2026, the member ID, name, email address and phone number of MrMax app and online store members leaked. The company says the items leaked vary with what each member registered.

QWhat was not leaked?
A

The company says it confirmed that addresses, dates of birth, credit card data, passwords and purchase history did not leak.

QAm I affected?
A

The affected people are those registered as MrMax app or online store members as of October 3, 2026, up to 1,735,154 people. The company says it will contact affected members individually by email from noreply@mrmax.jp. Sender addresses can be faked, though, so check in the official app or site you open yourself rather than logging in through a link in that email.

QShould I change my password?
A

The company says passwords did not leak, so according to the notice there is no need to change it right away. If you use the same password as your MrMax account on other services, though, this is a good moment to stop reusing it.

QWhat scams should I watch for?
A

The company warns that impersonation and phishing emails based on the leaked data may be sent, and asks members to watch for suspicious emails, texts, calls and postal mail claiming to be from the company or people connected to it. It says it will never ask for passwords or credit card numbers. A message that has your correct name and member ID is not proof that it is genuine.

QWhat caused the breach?
A

The company says a third party misused a function of the software that makes up the service to get into the server. Which software or function has not been disclosed. The company says it has reported to Japan's Personal Information Protection Commission, consulted the police, and is investigating in detail with the help of an outside specialist organization.