Skip to content
>_ITDITDWeb Security Platform

Security Guides

NewsPicks Data Breach (Card Holder Names and Last Digits, up to 362,000 Records): What Leaked Through an Internal Admin Tool and What Users Should Do

At NewsPicks, run by Uzabase, an internal admin tool was accessed without authorization. Card holder names with the last 3–4 card digits (up to 362,000 records) and email addresses (up to 323,000) may have leaked. What users should do today, and what is still unknown.

Published 2026-10-10 Updated 2026-10-10 Last verified 2026-10-10 14 min read

For: NewsPicks users (especially those who paid by card on the web), staff at organisations using NewsPicks Enterprise or NewsPicks Education, and anyone who runs internal admin tools. This article is based on Uzabase, Inc.'s official notices and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 10, 2026

Not yet known

  • Actual number of people affected
  • Which admin tool, and what vulnerability
  • Actual scope of the leak
  • Findings of the outside specialists
  • Fundamental measures to prevent a recurrence

In its second notice the company says it is identifying the cause and the full picture, will provide an update taking into account advice from outside specialists, and will publish new facts promptly as they emerge. As of October 10, no third notice had been published.

What NewsPicks users should do today

1

Do not trust a message just because it knows your card's last digits

The items that may have leaked include card holder names and the last 3 or 4 digits of card numbers. Genuine messages from card issuers and services often show the last 4 digits so you can recognise your card. That makes a fake message with the correct last digits hard to tell apart from a real one.

If you receive something like "please confirm the card ending in XXXX" or "there is a problem with your payment", do not open the link. Check card matters with your issuer using the number on the back of the card, and NewsPicks matters in the official app (how to spot fakes: What is phishing?).

2

Check even the company's notice email on the official site, not through its links

The company says it began emailing affected users from October 9, in turn, from the NewsPicks support address (no-reply@newspicks.com). However, the sender shown in an email can be faked. Fake emails imitating the notice are possible, so the reliable way to check is the notices on an official site you open yourself.

The company says it will never ask for passwords or credit card numbers by email, text message, phone or post. If you are asked for them, you can treat the message as fake at that point.

3

Check your card statements

According to the company, full card numbers are managed by the payment processor and are not stored on its systems, and it does not store security codes. So the leaked data alone is unlikely to be enough to use the card.

Even so, if a fake message leads you to type in your full card number, that can lead to fraud. If your statement shows a charge you do not recognise, contact your card issuer even if it is small. Decide with your issuer whether to have the card reissued.

4

If your employer details may have leaked, watch messages at work too

The items that may have leaked also include affiliation (such as employer), the phone number of the affiliated organisation and a job-level category. Besides your personal email, calls or emails to your workplace claiming to be NewsPicks or a business partner are possible.

If you are asked to confirm an unexpected bill or "contract details", do not answer on the spot; call back on an official number you look up yourself. Staff managing NewsPicks Enterprise or NewsPicks Education for their organisation should share this warning with users there.

5

Handle your NewsPicks login through the official steps

The company says no password leak has been confirmed, and it has not asked users to change passwords. If you are concerned, or you use the same password elsewhere, you can change it in the official app under the account settings in "Settings and privacy" — not via a link in an email (steps on the company's help page Changing your password, in Japanese).

A password manager is the practical way to stop reusing passwords. To see whether your password appears in other leaks, see how to check if your password was leaked.

6

Use only the contact points listed in the official notice

The contact points in the company's notice are an email address (info@newspicks.com) and the inquiry form in the NewsPicks help centre. You never need to send your card number or password when you contact them.

What happened (per Uzabase)

The following is based on the company's first notice of October 8 and second notice of October 9.

  1. October 8, 2026, 12:48

    Unauthorized access detected; a response team set up.
  2. October 8, 14:01

    Internal investigation concludes it is unauthorized access by a third party. The server concerned is cut off immediately and steps taken to stop further damage.
  3. October 8, 21:44

    Preliminary report filed with Japan's Personal Information Protection Commission; the local police consulted.
  4. October 8

    First notice published, listing the items that may have leaked; counts under investigation.
  5. October 9

    Second notice published. The company says a vulnerability in the admin tool was exploited and gives maximum estimated counts per item. Emails to affected users begin in turn the same day.
  6. As of October 10

    No third notice. No secondary damage confirmed (second notice). The service continues to operate with defensive measures in place.
362,000
Card holder names, last 3–4 digits, etc. (max)
323,000
Email addresses (max)
65,000
Affiliation such as employer (max)
Not confirmed
Leak of full card numbers or passwords
Data that may have leaked (per Uzabase's second notice)
Entry point
An admin tool used in running NewsPicks. The company says a vulnerability in the admin tool was exploited
No intrusion confirmed
The NewsPicks service itself; Uzabase's other information systems
User data (maximum estimates)
Email addresses 323,000; names 59,000; dates of birth 28,000; delivery addresses and recipient names 31,000; affiliation (such as employer) 65,000; phone numbers of the affiliated organisation 29,000; job level in seven categories 273,000
Card data
Part of the card data used for web payments, 362,000 (card holder name, last 3 or 4 digits of the card number, etc.)
Not leaked / not confirmed
Full card numbers (managed by the payment processor, not stored on the company's systems); security codes (not stored); passwords; exchanges with client companies
Business contacts
Names and contact email addresses of the people managing NewsPicks Enterprise and NewsPicks Education accounts: 122 records
Actions taken
Blocked access to the admin tool and deleted its accounts; reissued the access keys for data the admin tool could reach; reduced the admin tool's data-access permissions to the minimum needed for the work; blocked the source of the unauthorized access across the whole NewsPicks service
Secondary damage
None confirmed (second notice). The first notice said there was also no confirmed public posting or misuse of the data

What is known and what is not

Status as of October 10, 2026. When follow-up notices appear, the status column will be updated.

ItemWhat the notices sayStatus
Entry pointA vulnerability in an admin tool used in operations was exploitedConfirmed (details not disclosed)
Intrusion into the service itself or other systemsNot confirmedNot confirmed
Items that may have leakedEmail, name, date of birth, delivery address and recipient name, affiliation, affiliated organisation's phone number, job-level category, card holder name and last 3–4 digits, etc.Possible leak
Counts per itemPublished as maximum estimates (e.g. 362,000 for card data)Published (maximums)
Actual number of people affectedNot publishedNot disclosed
Full card number and security codeNot stored on the company's systems; not leakedNot leaked (company's account)
PasswordsNo leak confirmedNot confirmed
Which admin tool, which vulnerabilityNot publishedUnder investigation
Secondary damageNone confirmedNot confirmed (as of Oct 9)
Contacting affected usersBy email, in turn, from October 9Under way
Recurrence preventionFundamental measures to be decided once the cause is clearUnder investigation

Reading note: phone numbers are described differently in the two notices

The first notice listed "phone number" among the items that may have leaked; the breakdown in the second notice lists "phone number of the affiliated organisation". Addresses are also given as "delivery address and recipient name" in the second notice. This article follows the more detailed second notice.

What card holder names, last digits and employer details can be used for

In general, when these combinations come together, the following misuse becomes possible. This does not mean it has happened in this case.

  • Card holder name + last digits + email address: fake messages that correctly say "your card ending in XXXX", used to lure people into typing their full card number
  • Name + date of birth + delivery address: phone calls or letters that pretend to verify your identity look more convincing
  • Affiliation + organisation's phone number + job-level category: calls or emails to the workplace claiming to be a business partner or service

This site's view: treat the last digits as data that can leak, not as proof of identity

The last 4 digits of a card are widely shown on statements and account pages so people can recognise their card. That makes it tempting to think "if they know the last digits, it must be real".

When those digits may have leaked, reverse the logic: what the other side knows is not evidence that they are genuine. Whether a message is real is settled by contacting the official channel yourself, not by what the sender knows.

For people who run internal admin tools

According to the company, the entry point was not the service itself but an admin tool used in its operations. Which tool, what vulnerability, and how it was exploited have not been disclosed. This section does not assess the company's handling; it sets out what operators can check in their own environment, based on the disclosed facts.

The NewsPicks service itself

No intrusion confirmed

Admin tool used in operations

Vulnerability exploited (per the company)

Uzabase's other information systems

No intrusion confirmed

↓ Data the admin tool could reach

User data (email, name, affiliation, card holder name and last digits, etc.)

The company has since reissued the access keys and cut permissions to the minimum needed

Layout as described in the company's notices. The vulnerability exploited was in an internal admin tool; no intrusion into the service itself or other information systems has been confirmed.
1

List your admin tools and put them under the same patching duty as public services

Admin and analytics tools used only by staff are often treated more lightly than the main service, and nobody may own their updates. Start by listing the admin tools you use and writing down, for each, who updates it and where vulnerability notices arrive (security inventory checklist, CVE remediation playbook).

2

Keep admin tool login pages off the open internet

Only staff should use an admin tool. Use the internal network, a VPN or source-address restrictions so the login page itself cannot be reached from outside. Then route logins through company single sign-on (SSO: one account that signs you in to several tools) and multi-factor authentication.

Some vulnerabilities sit in processing that happens before login, where passwords and MFA do not help. Keeping the tool unreachable from outside is the measure that still works in that case (defending against VPN appliance vulnerabilities).

3

Give admin tools the least access, and show the fewest fields

In general, what can leak from an admin tool is set by the data access you granted it. The company, too, says it reduced the admin tool's data-access permissions to the minimum needed for the work.

In your own environment, write down what data each admin tool's connection user or access key can read, and block fields the work does not need (card holder names, last digits, dates of birth and so on). Using views that expose only part of a table is explained in the Metabase exploitation breaches article; the idea of who may do what is covered in authentication vs authorization.

4

Be ready to reissue access keys quickly

The company reissued the access keys for data the admin tool could reach. When an admin tool is compromised, the keys it held must be assumed leaked and replaced. Keep a list of which keys are given to which tools, and decide the reissue procedure and who does it in advance, so the response on the day is fast.

A past case where an internal tool was the entry point is the exploitation of a Metabase vulnerability, where the organisations' data leaked from their analytics environments rather than their main services. This does not mean the course or cause here is the same. The minimum set of measures for an organisation is in security baseline for organizations.

Sources (public record)

The facts in this article are based on the following public information. We have not speculated about the name of the admin tool or how the intrusion worked.

  • Uzabase, Inc., "[Important] Apology and notice regarding possible leak of NewsPicks customers' personal information" (October 8, 2026, first notice; Japanese) — corp.newspicks.com
  • Uzabase, Inc., second notice (October 9, 2026; Japanese) — corp.newspicks.com
  • NewsPicks Help Center, second notice (same content as the second notice; Japanese) — newspicks.zendesk.com
  • NewsPicks Help Center, "Changing your password" (Japanese) — newspicks.zendesk.com

Update history

2026-10-10: First version, based on the company's first notice of October 8 and second notice of October 9 (maximum estimated counts per item, the admin tool vulnerability, and actions taken). Will be updated when the cause or recurrence-prevention measures are published.

FAQ

QWhat leaked from NewsPicks?
A

According to Uzabase, Inc.'s second notice of October 9, 2026, the data that may have leaked is: email addresses (323,000), names (59,000), dates of birth (28,000), delivery addresses and recipient names (31,000), affiliation such as employer (65,000), phone numbers of the affiliated organisation (29,000), job level in seven categories (273,000), and part of the card data used for web payments — card holder name and the last 3 or 4 digits of the card number, etc. (362,000). All are maximum estimated counts. The names and contact email addresses of account administrators for NewsPicks Enterprise and NewsPicks Education (122 records) are also included.

QAm I affected?
A

The company's October 8 notice says some of the people who used NewsPicks services up to October 8, 2026 may be affected. From October 9 it began emailing affected users in turn from the NewsPicks support address (no-reply@newspicks.com). Counts per item have been published, but the actual number of people affected has not.

QDid card numbers or passwords leak?
A

According to the company, full card numbers are managed by the payment processor and are not stored on its systems, so they did not leak. It does not store security codes either. It also says no password leak has been confirmed. What may have leaked is the card holder name and the last 3 or 4 digits of the card number, among other items.

QWhat caused it?
A

In its second notice the company says the intrusion exploited a vulnerability in an admin tool used in running NewsPicks. It says no intrusion into the NewsPicks service itself or into Uzabase's other information systems has been confirmed. Which admin tool and which vulnerability have not been disclosed. The company says it is identifying the cause with advice from outside specialists and will announce fundamental measures to prevent a recurrence.

QWhat if someone contacts me claiming to be NewsPicks or Uzabase?
A

The company says it will never ask for passwords or credit card numbers by email, text message, phone or post. It asks people not to open links or attachments in suspicious emails. Treat any message asking for card details or a password as fake, and check through the NewsPicks app or a bookmarked official site you open yourself.

QIf a message knows the last 4 digits of my card, is it genuine?
A

Not on that basis alone. The card holder name and the last 3 or 4 digits of the card number are among the items that may have leaked. A correct name or last digits only shows that the sender has that data; it is not proof that the message is real. Even if a message says something like 'the card ending in XXXX needs to be verified', do not open the link — contact your card issuer or NewsPicks through their official channels yourself.