Security Guides
Murauchi.com data breach (7.7 million records): names, addresses and phone numbers leaked — past customers should watch for scam calls and mail
Japanese retailer Murauchi.com confirmed 7,716,811 records with names, addresses and phone numbers were taken. What leaked and what past customers should do.
For: anyone who has bought from Murauchi.com (a Japanese online shop for home electronics, PCs and similar goods), especially people who used it years ago, and anyone who runs an online shop. This article is based on the company's official notices and does not cover attack or scam techniques.
Quick check: are you affected?
| What you want to know | What the company has said |
|---|---|
| Number of records leaked | 7,716,811 |
| Items for everyone affected | Name, address, phone number |
| Items for some people | Email address, date of birth, gender |
| Not included | Card numbers and other payment data, login IDs and passwords, registered delivery addresses |
| How many years of data | Not disclosed |
| Former members and long-inactive customers | Not disclosed whether included |
| People who bought from its shops on online malls | Not disclosed whether included |
| Individual notice | Notification emails to affected customers, sent in stages from September 15 |
Given that there are more than 7.7 million records, it may not be limited to recent customers. If you remember ever buying from Murauchi.com, it is safest to assume you may be affected.
Notification emails can only reach people whose email address the company has. Email addresses are among the leaked items for only some of the affected people, so not receiving an email does not prove you are unaffected.
What to do today
Do not give personal data or money to callers claiming to be the company, a mall or a card issuer
The company warns customers to be careful with emails, text messages and phone calls claiming to be from Murauchi.com, an online mall operator or a card issuer. It also says it will never ask for card numbers or passwords by email or phone.
Even if a caller says there is "a refund because of the data leak" or "compensation to process", do not give card numbers, bank details or PINs on the spot. Hang up and contact an official number you look up yourself.
For letters and text messages too, do not use the contact details they give
Because home addresses leaked as well, fake notices may arrive as postcards or letters, not just email. Phone numbers leaked too, so text messages are also possible.
Do not use the URL, QR code or phone number in the notice; open the official website yourself and see whether the same notice is posted there. The company's official updates are collected on its page titled (in translation) "Apology and report on the leak of customer information due to unauthorized access" (how to spot fakes: What is phishing?).
Do not treat a correct name and address as proof
A message that shows your real name, address, phone number and perhaps even your date of birth looks genuine.
But with this leaked data, a fake message can also contain correct personal details. If an older family member used the shop in the past, tell them this.
Check any email from the company against its official page
To check whether a notification email from the company is genuine, use the notice page on the company's website that you open yourself, not the links in the email.
The company has paused its social media accounts to focus on handling inquiries and says it cannot answer direct messages during the pause (it plans to resume in November 2026). Be careful with accounts that claim to be the company and contact you individually on social media.
If you no longer use the shop, you can ask for your data to be deleted
The company's FAQ says that anyone who wants their registered personal data deleted should contact its dedicated address (privacy@murauchi.com), and that it will respond in line with the law and its own rules.
When you write, type the address yourself or copy it from the official page, rather than replying to an email you received.
No password change is needed, but stop reusing passwords
The company says login IDs and passwords were not targeted. Still, if an old account there used the same password as other services, now is a good time to change those (Choosing a password manager).
If you paid money or gave out your card number
If you gave out a card number, call your card issuer right away to stop the card. If you transferred or paid money, contact the receiving bank and the police as soon as possible.
In Japan, you can also call the police consultation line (#9110) or the consumer hotline (188). The sooner you report, the better the chance of stopping the loss.
What happened (from Murauchi.com's notices)
Murauchi.com Co., Ltd. posted a first notice on its website on July 24, 2026 and a second notice on September 15. Everything below comes from the company's notices.
Early hours of July 15, 2026
A failure occurred in an internal system.July 16
During recovery work, traces of unauthorized access by a third party were found. External access was cut off and an investigation began.July 20
Preliminary report submitted to Japan's Personal Information Protection Commission.July 23
The company consulted the police.July 24
First notice published; a dedicated inquiry contact opened.July 27
Forensic investigation by an outside information security firm began.September 14
Final report submitted to the Personal Information Protection Commission.September 15
Second notice announced that 7,716,811 records had been taken out; notification emails to affected customers began in stages.
- Company
- Murauchi.com Co., Ltd. (operates the online shop Murauchi.com)
- Records
- 7,716,811
- Items
- Name, address, phone number; for some people also email address, date of birth and gender
- Not included
- Card numbers and other payment data, login IDs and passwords (managed in separate systems); information registered as delivery addresses
- Cause
- The unauthorized access began with the exploitation of a vulnerability in part of a web system managed by the company, after which several systems were accessed without authorization
- Follow-on harm
- As of September 15, no misuse or phishing emails linked to the incident had been confirmed
- Prevention measures
- Review of access rights and credential management, stronger server and network monitoring and intrusion detection, regular vulnerability assessments
- Operations
- The main online shop remains open; the status of its shops on online malls varies by shop
- Reports
- Preliminary and final reports to the Personal Information Protection Commission; police consulted
- Contact
- Dedicated email address privacy@murauchi.com
What is still unknown
As of October 3, the company has not said how many years of customer data were involved, whether former members or people who bought through its online-mall shops are included, or how it will notify people whose email address it does not have. This article will be updated when more is published.
Why calls and mail are the concern
The core of what leaked is not email addresses but real names, home addresses and phone numbers. With all three, fake contact is not limited to email.
What this data makes possible
- Phone calls that use your real name ("about Murauchi.com", "this is your card issuer")
- Postcards or letters to your correct address, posing as refunds or compensation
- Text messages to your phone number
- Questions posing as identity checks, pretending to already know your date of birth
How to check for yourself
- Hang up and call back on a number you looked up yourself
- Do not use QR codes or URLs in letters; open the official website yourself
- The company says it never asks for card numbers or passwords by email or phone
- Receiving a refund or compensation does not normally require you to pay first
With a shop you used once long ago, you may not remember whether you really bought from it. So when a caller says "this is about your past purchase from Murauchi.com", you have no way to check, and the story is easier to believe. Treat not remembering as a reason to be more careful.
For those who run online shops
The cause the company published is that a vulnerability in its web system was the starting point, after which several systems were accessed. Further details have not been published, so this section sticks to points that can be drawn from the notices.
Decide how long to keep data on past customers
The company's notices do not say how many years of data were involved. The point here is general, not a judgment of how the company stored its data.
The longer an online shop has been in business, the more data it holds on customers who have not bought anything for years. If that data leaks, it affects people who no longer remember using the shop, and notices are harder to deliver. Japan's Act on the Protection of Personal Information also asks businesses to make efforts to delete personal data without delay once it is no longer needed (Article 22, a duty to make efforts).
Decide what happens to the data of customers whose last purchase was a set number of years ago (delete it, or remove names and contact details and keep only figures for statistics), and run it on a schedule rather than by hand.
Keep payment and login data in systems separate from customer records
According to the company, card numbers and other payment data and login IDs and passwords were managed in separate systems and were not affected.
Not holding card numbers yourself (leaving them to a payment processor) and keeping credentials in a separate system limit how much can leak when an intruder gets in.
Stop one web system from becoming a path to the others
In the company's account, a vulnerability in a web system was the starting point, after which several systems were accessed.
List the network paths and permissions that lead from public-facing web servers to customer databases and internal systems, and allow only the connections that are needed. The review of access rights and credential management that the company lists among its prevention measures relates to this point.
For another online-shop case, see the Abahouse data breach; for fake messages that use addresses and phone numbers, see the Yamato Transport and Sagawa Express incidents.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed details of the intrusion and the period of data covered are not speculated on.
- Murauchi.com Co., Ltd., apology and report on the leak of customer information due to unauthorized access (first notice July 24, 2026; second notice September 15, 2026; FAQ; Japanese) — murauchi.com
- Security NEXT (September 17, 2026, Japanese) — security-next.com
- Act on the Protection of Personal Information, Article 22 (Japanese) — e-Gov law search
Update history
2026-10-03: First version, based on Murauchi.com's first notice (July 24), second notice (September 15) and FAQ.
Read next
- Follow-on scams: What is phishing? / Fake virus warnings (tech-support scams)
- Fake messages using addresses and order details: Yamato Transport and Sagawa Express / Abahouse
- Another Japanese case from the same period: The Times Car breach
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat was leaked in the Murauchi.com breach?
According to Murauchi.com Co., Ltd.'s second notice of September 15, 2026 and its FAQ, 7,716,811 records were confirmed leaked. They contain names, addresses and phone numbers, and for some people also email addresses, dates of birth and gender. The company says information registered as delivery addresses was not leaked.
QWere card details or passwords leaked?
According to the company, card numbers and other payment data, as well as login IDs and passwords, are managed in separate systems and it has confirmed they were not targeted by this unauthorized access.
QI bought something there only once, years ago. Could I be affected?
Possibly. The company's notices do not say how many years of data were involved, or whether former members and long-inactive customers are included. With more than 7.7 million records, it cannot be assumed that only recent customers are affected. If you remember ever buying from Murauchi.com, prepare as if you may be affected.
QWill the company contact me?
Since September 15, the company has been sending individual notification emails to affected customers in stages. However, email addresses are among the leaked items for only some of the affected people. Not receiving an email does not prove you are unaffected.
QCan I ask the company to delete my data?
The company's FAQ says that anyone who wants their registered personal data deleted should contact its dedicated address (privacy@murauchi.com), and that it will respond in line with the law and its own rules. If you no longer use the shop, you can ask for deletion.
QWhat caused the breach?
According to the company, the unauthorized access began with the exploitation of a vulnerability in part of a web system it manages, after which several systems were accessed without authorization. This was found by a forensic investigation (an analysis of logs and stored data to establish what happened) carried out by an outside information security firm.