Skip to content
>_ITDITDWeb Security Platform

Security Guides

Murauchi.com data breach (7.7 million records): names, addresses and phone numbers leaked — past customers should watch for scam calls and mail

Japanese retailer Murauchi.com confirmed 7,716,811 records with names, addresses and phone numbers were taken. What leaked and what past customers should do.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 11 min read

For: anyone who has bought from Murauchi.com (a Japanese online shop for home electronics, PCs and similar goods), especially people who used it years ago, and anyone who runs an online shop. This article is based on the company's official notices and does not cover attack or scam techniques.

Quick check: are you affected?

What you want to knowWhat the company has said
Number of records leaked7,716,811
Items for everyone affectedName, address, phone number
Items for some peopleEmail address, date of birth, gender
Not includedCard numbers and other payment data, login IDs and passwords, registered delivery addresses
How many years of dataNot disclosed
Former members and long-inactive customersNot disclosed whether included
People who bought from its shops on online mallsNot disclosed whether included
Individual noticeNotification emails to affected customers, sent in stages from September 15

Given that there are more than 7.7 million records, it may not be limited to recent customers. If you remember ever buying from Murauchi.com, it is safest to assume you may be affected.

Notification emails can only reach people whose email address the company has. Email addresses are among the leaked items for only some of the affected people, so not receiving an email does not prove you are unaffected.

What to do today

1

Do not give personal data or money to callers claiming to be the company, a mall or a card issuer

The company warns customers to be careful with emails, text messages and phone calls claiming to be from Murauchi.com, an online mall operator or a card issuer. It also says it will never ask for card numbers or passwords by email or phone.

Even if a caller says there is "a refund because of the data leak" or "compensation to process", do not give card numbers, bank details or PINs on the spot. Hang up and contact an official number you look up yourself.

2

For letters and text messages too, do not use the contact details they give

Because home addresses leaked as well, fake notices may arrive as postcards or letters, not just email. Phone numbers leaked too, so text messages are also possible.

Do not use the URL, QR code or phone number in the notice; open the official website yourself and see whether the same notice is posted there. The company's official updates are collected on its page titled (in translation) "Apology and report on the leak of customer information due to unauthorized access" (how to spot fakes: What is phishing?).

3

Do not treat a correct name and address as proof

A message that shows your real name, address, phone number and perhaps even your date of birth looks genuine.

But with this leaked data, a fake message can also contain correct personal details. If an older family member used the shop in the past, tell them this.

4

Check any email from the company against its official page

To check whether a notification email from the company is genuine, use the notice page on the company's website that you open yourself, not the links in the email.

The company has paused its social media accounts to focus on handling inquiries and says it cannot answer direct messages during the pause (it plans to resume in November 2026). Be careful with accounts that claim to be the company and contact you individually on social media.

5

If you no longer use the shop, you can ask for your data to be deleted

The company's FAQ says that anyone who wants their registered personal data deleted should contact its dedicated address (privacy@murauchi.com), and that it will respond in line with the law and its own rules.

When you write, type the address yourself or copy it from the official page, rather than replying to an email you received.

6

No password change is needed, but stop reusing passwords

The company says login IDs and passwords were not targeted. Still, if an old account there used the same password as other services, now is a good time to change those (Choosing a password manager).

If you paid money or gave out your card number

If you gave out a card number, call your card issuer right away to stop the card. If you transferred or paid money, contact the receiving bank and the police as soon as possible.

In Japan, you can also call the police consultation line (#9110) or the consumer hotline (188). The sooner you report, the better the chance of stopping the loss.

What happened (from Murauchi.com's notices)

Murauchi.com Co., Ltd. posted a first notice on its website on July 24, 2026 and a second notice on September 15. Everything below comes from the company's notices.

  1. Early hours of July 15, 2026

    A failure occurred in an internal system.
  2. July 16

    During recovery work, traces of unauthorized access by a third party were found. External access was cut off and an investigation began.
  3. July 20

    Preliminary report submitted to Japan's Personal Information Protection Commission.
  4. July 23

    The company consulted the police.
  5. July 24

    First notice published; a dedicated inquiry contact opened.
  6. July 27

    Forensic investigation by an outside information security firm began.
  7. September 14

    Final report submitted to the Personal Information Protection Commission.
  8. September 15

    Second notice announced that 7,716,811 records had been taken out; notification emails to affected customers began in stages.
7,716,811
Records of personal data taken out
Not disclosed
How many years of data; whether former members are included
Not affected
Card and other payment data, login IDs and passwords
None confirmed
Follow-on harm (company FAQ, as of September 15)
Details of the leak (from the second notice and FAQ)
Company
Murauchi.com Co., Ltd. (operates the online shop Murauchi.com)
Records
7,716,811
Items
Name, address, phone number; for some people also email address, date of birth and gender
Not included
Card numbers and other payment data, login IDs and passwords (managed in separate systems); information registered as delivery addresses
Cause
The unauthorized access began with the exploitation of a vulnerability in part of a web system managed by the company, after which several systems were accessed without authorization
Follow-on harm
As of September 15, no misuse or phishing emails linked to the incident had been confirmed
Prevention measures
Review of access rights and credential management, stronger server and network monitoring and intrusion detection, regular vulnerability assessments
Operations
The main online shop remains open; the status of its shops on online malls varies by shop
Reports
Preliminary and final reports to the Personal Information Protection Commission; police consulted
Contact
Dedicated email address privacy@murauchi.com

What is still unknown

As of October 3, the company has not said how many years of customer data were involved, whether former members or people who bought through its online-mall shops are included, or how it will notify people whose email address it does not have. This article will be updated when more is published.

Why calls and mail are the concern

The core of what leaked is not email addresses but real names, home addresses and phone numbers. With all three, fake contact is not limited to email.

What this data makes possible

  • Phone calls that use your real name ("about Murauchi.com", "this is your card issuer")
  • Postcards or letters to your correct address, posing as refunds or compensation
  • Text messages to your phone number
  • Questions posing as identity checks, pretending to already know your date of birth

How to check for yourself

  • Hang up and call back on a number you looked up yourself
  • Do not use QR codes or URLs in letters; open the official website yourself
  • The company says it never asks for card numbers or passwords by email or phone
  • Receiving a refund or compensation does not normally require you to pay first

With a shop you used once long ago, you may not remember whether you really bought from it. So when a caller says "this is about your past purchase from Murauchi.com", you have no way to check, and the story is easier to believe. Treat not remembering as a reason to be more careful.

For those who run online shops

The cause the company published is that a vulnerability in its web system was the starting point, after which several systems were accessed. Further details have not been published, so this section sticks to points that can be drawn from the notices.

1

Decide how long to keep data on past customers

The company's notices do not say how many years of data were involved. The point here is general, not a judgment of how the company stored its data.

The longer an online shop has been in business, the more data it holds on customers who have not bought anything for years. If that data leaks, it affects people who no longer remember using the shop, and notices are harder to deliver. Japan's Act on the Protection of Personal Information also asks businesses to make efforts to delete personal data without delay once it is no longer needed (Article 22, a duty to make efforts).

Decide what happens to the data of customers whose last purchase was a set number of years ago (delete it, or remove names and contact details and keep only figures for statistics), and run it on a schedule rather than by hand.

2

Keep payment and login data in systems separate from customer records

According to the company, card numbers and other payment data and login IDs and passwords were managed in separate systems and were not affected.

Not holding card numbers yourself (leaving them to a payment processor) and keeping credentials in a separate system limit how much can leak when an intruder gets in.

3

Stop one web system from becoming a path to the others

In the company's account, a vulnerability in a web system was the starting point, after which several systems were accessed.

List the network paths and permissions that lead from public-facing web servers to customer databases and internal systems, and allow only the connections that are needed. The review of access rights and credential management that the company lists among its prevention measures relates to this point.

For another online-shop case, see the Abahouse data breach; for fake messages that use addresses and phone numbers, see the Yamato Transport and Sagawa Express incidents.

Sources (public record)

The facts in this article come from the public sources below. Undisclosed details of the intrusion and the period of data covered are not speculated on.

  • Murauchi.com Co., Ltd., apology and report on the leak of customer information due to unauthorized access (first notice July 24, 2026; second notice September 15, 2026; FAQ; Japanese) — murauchi.com
  • Security NEXT (September 17, 2026, Japanese) — security-next.com
  • Act on the Protection of Personal Information, Article 22 (Japanese) — e-Gov law search

Update history

2026-10-03: First version, based on Murauchi.com's first notice (July 24), second notice (September 15) and FAQ.

FAQ

QWhat was leaked in the Murauchi.com breach?
A

According to Murauchi.com Co., Ltd.'s second notice of September 15, 2026 and its FAQ, 7,716,811 records were confirmed leaked. They contain names, addresses and phone numbers, and for some people also email addresses, dates of birth and gender. The company says information registered as delivery addresses was not leaked.

QWere card details or passwords leaked?
A

According to the company, card numbers and other payment data, as well as login IDs and passwords, are managed in separate systems and it has confirmed they were not targeted by this unauthorized access.

QI bought something there only once, years ago. Could I be affected?
A

Possibly. The company's notices do not say how many years of data were involved, or whether former members and long-inactive customers are included. With more than 7.7 million records, it cannot be assumed that only recent customers are affected. If you remember ever buying from Murauchi.com, prepare as if you may be affected.

QWill the company contact me?
A

Since September 15, the company has been sending individual notification emails to affected customers in stages. However, email addresses are among the leaked items for only some of the affected people. Not receiving an email does not prove you are unaffected.

QCan I ask the company to delete my data?
A

The company's FAQ says that anyone who wants their registered personal data deleted should contact its dedicated address (privacy@murauchi.com), and that it will respond in line with the law and its own rules. If you no longer use the shop, you can ask for deletion.

QWhat caused the breach?
A

According to the company, the unauthorized access began with the exploitation of a vulnerability in part of a web system it manages, after which several systems were accessed without authorization. This was found by a forensic investigation (an analysis of logs and stored data to establish what happened) carried out by an outside information security firm.