Skip to content
>_ITDITDWeb Security Platform

Security Guides

Card-Stealing Program on the PhotoGoods (Daiko Printing) Payment Page: What People Who Paid Between August 6 and September 11 Should Do

A program that steals card data was planted on the payment page of PhotoGoods, run by Daiko Printing. Card numbers, expiry dates and security codes entered from August 6 to September 11, 2026 may have leaked. What affected people should do today, and what is still unknown.

Published 2026-10-07 Updated 2026-10-07 Last verified 2026-10-07 14 min read

For: anyone who shopped on PhotoGoods (photo-goods.com) or entered a card on its payment page between August 6 and September 11, 2026, and anyone who runs an online store. This article is based on Daiko Printing Co., Ltd.'s official notice and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 7, 2026

Not yet known

  • Number of people affected
  • Actual scope of the leak
  • How the attacker got in
  • Compensation, including reissue fees
  • How to change the PhotoGoods password
  • When the service reopens

The company says that once the affected people and the scope are confirmed, it will send them an apology and guidance by email or other means, and that this may take time depending on the investigation. It says new facts and the reopening date will be posted on its website.

What people who used PhotoGoods between August 6 and September 11 should do today

1

Check whether you are affected (people who did not buy are included)

Per the company, people who entered card details on the PhotoGoods payment page between August 6 and September 11, 2026 may be affected. Even if you did not complete the purchase, you may be affected if you entered your card on the payment page.

The company plans to contact affected people one by one after the scope is confirmed. As of October 7, it had not announced that it had started doing so. If you remember using the site in that period, do the steps below without waiting.

2

Call your card issuer and ask about changing the number

The company asks people to check their statements and contact the issuer listed on the back of the card about any charge they do not recognize. This site recommends that anyone who entered a card in that period ask the issuer to change the number, even if no unknown charge has appeared yet.

The reason is that the security code is among the items that may have leaked. That combination stays usable until the number changes. Checking statements matters, but it only tells you after the card has been used (the reasoning is explained in more detail in our article on the APORITO Online Store card leak).

3

Keep checking your statements until the number changes

Check even small charges of a few hundred yen. Fraud protection has a reporting deadline set by each issuer's terms. After the number changes, update any service that charges the old card automatically, such as utilities and subscriptions.

4

If other services share your PhotoGoods password, change it there

The company says the password information that may have leaked is not the password itself but a converted form from which the original cannot be read directly. Even so, short or common passwords can sometimes be worked out from the converted value (how this works: What is password hashing?).

The company also asks people who use the same password elsewhere to consider changing it on each service's official site. It says the procedure for changing the PhotoGoods password itself will be announced once decided. A password manager is the practical way to stop reusing passwords.

5

Do not open links in apology or refund messages

Names, addresses, phone numbers and email addresses may also have leaked, which makes convincing fake messages possible. The company warns about suspicious emails, texts and calls pretending to be the company or PhotoGoods, and asks people not to open links or attachments or enter personal data, card details or passwords.

Because the company plans to contact affected people by email, fake "apology", "refund" or "re-register your card" messages imitating it are possible. Treat any message asking you to enter card details as fake, and check through the official website you open yourself (how to spot them: What is phishing?).

6

Use only the contact points in the official notice

The notice lists the PhotoGoods inquiry desk: phone 078-303-7383 (weekdays 10:00–18:00, Japan time) and email support@photo-goods.com (24 hours). The company asks people not to send card numbers, PINs, security codes or passwords by email when contacting it. For questions about an order already placed, it asks you to include the order number.

When the payment page itself is altered, the card leaks even if the shop never stores it

In this type of incident, card data is not stolen from the shop's database. Instead, a program is planted on the payment page where customers type their details, and what they enter is sent to another destination as well as the legitimate one.

That is why the card can leak even if the shop does not store card data on its own servers. It also means everyone who typed a card while the program was in place is in scope, which is why people who never completed a purchase are included this time.

A past case of the same type is the APORITO Online Store (RIZAP) incident disclosed in August 2026. There, a second notice followed about a week after the first, but even it did not disclose the number of people or details of the cause. That does not mean this case will go the same way.

What happened (per Daiko Printing)

The following is based on Daiko Printing's notice of September 16, 2026 and the notice shown on the PhotoGoods website (checked on October 7).

  1. August 6, 2026

    Start of the period in which the card-capturing program was in place (per the company's investigation).
  2. September 11

    The company was told that a suspicious external program was being loaded on PhotoGoods and immediately had its system management company investigate. The program was removed the same day.
  3. September 12

    Announced emergency maintenance for system checks and suspended the service.
  4. September 16

    Published its apology and notice about the unauthorized access and possible data leak.
  5. As of October 7

    No follow-up notice. The PhotoGoods site remains suspended and says safety checks and the investigation continue with specialist organisations and related companies. For some event-related sales, it says it is preparing to resume sales and extend the sales period.
37 days
Program in place (Aug 6 – Sep 11)
3 items
Card number, expiry date, security code
Investigating
Number of people affected (as of Oct 7)
Suspended
PhotoGoods service (no reopening date)
Data that may have leaked (per Daiko Printing)
Service
PhotoGoods (photo-goods.com). The company says its other services are not affected
Card data
Card number, expiry date, security code. People who entered a card on the payment page from August 6 to September 11 may be affected
Personal data
Name, address, phone number, email address (users of photo-goods.com)
Passwords
Information about member passwords: not the password itself, but a converted form from which the original cannot be read directly
Cause as disclosed
Confirmed unauthorized third-party access through system vulnerabilities and abuse of a file-upload function. Which vulnerability or upload function has not been disclosed
Actions taken
Suspended the service, stopped and removed the program, isolated the mechanism used for the access, disabled an unauthorized administrator account, restricted outside access, and investigated and preserved systems and logs
Next steps
Rebuilding the system in a safe environment, changing credentials and fixing vulnerabilities. The service will not reopen until its safety is confirmed

What is known and what is not

Status as of October 7, 2026. When a follow-up notice is published, we will update the status column.

ItemWhat the notice saysStatus
Period the program was in placeFrom August 6, 2026 until removal on September 11Confirmed (per the company's investigation)
Card data itemsCard number, expiry date, security codeMay have leaked
Personal data itemsName, address, phone number, email addressMay have leaked
PasswordsMember password information stored in converted formMay have leaked
People who did not buyMay be affected if they entered a card on the payment pageMay have leaked
CauseUnauthorized access through system vulnerabilities and abuse of a file-upload functionConfirmed (details not disclosed)
Number affected and actual scopeFinal investigation under wayUnder investigation
Fraudulent useNot mentioned in the noticeNot disclosed
Compensation such as reissue feesNot mentioned in the noticeNot disclosed
Individual notificationPlanned by email or other means after the scope is confirmedPlanned
ReopeningNot until safety is confirmed; date undecidedUndecided

How to read this: 'may have leaked' does not mean 'did not leak'

The company describes the items as data that "may have leaked". That means the actual scope is still being investigated, not that nothing leaked. Card data is sometimes used long after it is stolen, so until your number changes, keep checking statements for at least a few months.

What these combinations of data can be used for

In general, the following combinations can be misused as described. This does not mean it has happened in this case.

  • Card number + expiry date + security code: used for online shopping; on sites without extra identity checks, a payment can go through with just these
  • Name + address + phone number + email address: lets someone write a convincing "apology" or "refund" message with your correct name and address
  • Email address + converted password: if the password is easy to guess, logins to other services that use the same password may be attempted

For online store operators: two disclosed facts you can check against your own site

General defences against payment-page tampering (why not storing card data is not enough, the five items in Japan's Credit Card Security Guidelines, and monitoring scripts on the payment page) are covered in the APORITO article. Rather than repeat them, this section focuses on two facts in this notice, "abuse of a file-upload function" and "disabling an unauthorized administrator account", and what operators can check on their own sites.

Which upload function was abused, and how, has not been disclosed. This section does not assess the company's measures.

Notice: abuse of a file-upload function

↓

Are there non-image or executable files in the upload folder?

→ List it daily; alert on any file type you did not allow

Notice: unauthorized admin account disabled

↓

Has the list of admin accounts grown since yesterday?

→ Compare daily; alert the owner when it grows

Notice: discovered after an outside report

↓

Have the scripts loaded on the payment page changed?

→ Notice it yourself first (see the APORITO article)

Facts in this notice, and what an operator can check on their own site every day (a general mapping)
1

If customers upload files, check the upload function first

On sites where customer uploads are central to the service, such as photo goods or personalised printing, the upload function is an entrance open to every member, sometimes to the whole internet. Admin screens often have upload functions too, and both need checking.

What to check is whether uploaded files are stored where they cannot run: outside the publicly served folder, or in a location where scripts are not executed. The full design is in File upload vulnerabilities.

2

List the upload folder every day and alert on file types you did not allow

Even with the right settings, a gap in configuration or another route can leave a file that should never be there. List the files in the upload folder once a day and alert someone if there is any file type other than the ones you allow (for example jpg and png).

A scheduled job on the server (such as cron) that checks file extensions and actual file formats is enough to start. If you use rental hosting or an e-commerce platform, ask the provider whether it offers the same check.

3

Compare the list of admin accounts every day and alert when it grows

This notice included "disabling an unauthorized administrator account". In general, intruders sometimes create an admin account so they can get back in after the original entrance is closed (a kind of backdoor).

Export the list of admin accounts from the admin screen or database once a day, compare it with the day before, and send an alert to the owner's phone if it has grown. An account nobody created is, on its own, a sign of intrusion. If an outside company builds or runs your store, ask whether it can do this check for you.

This site's view: the time until an outside report arrives becomes the exposure window

The company says it began investigating after being told a suspicious external program was being loaded. With programs planted on the payment page, everyone who enters a card before anyone notices is in scope. The two checks above do not prevent intrusion; they are about noticing it yourself first. They cost almost nothing, and even a small online store can start today.

Sources (public record)

The facts in this article are based on the public information below. We do not speculate on undisclosed intrusion routes or techniques.

  • Daiko Printing Co., Ltd., "[Important] Apology and notice regarding possible leak of personal information due to unauthorized access to PhotoGoods" (September 16, 2026, Japanese) — daiko-printing.co.jp
  • Daiko Printing Co., Ltd., "PhotoGoods emergency maintenance notice" (September 12, 2026, Japanese) — daiko-printing.co.jp
  • PhotoGoods "service suspended" notice (checked October 7, 2026, Japanese) — photo-goods.com

Update history

2026-10-07: First version, based on Daiko Printing's notice of September 16 and the suspension notice on the PhotoGoods site (checked October 7). The company says it will announce the scope, reopening date and other details, and we will update this article when it does.

FAQ

QWhat leaked from PhotoGoods?
A

According to Daiko Printing Co., Ltd.'s notice of September 16, 2026, the data that may have leaked is credit card data (card number, expiry date, security code), personal data (name, address, phone number, email address) and information about member passwords. The company says this is not the password itself but information converted into a form from which the original password cannot be read directly. The actual scope is still under investigation.

QAm I affected?
A

For card data, people who entered card details on the PhotoGoods payment page between August 6 and September 11, 2026 may be affected. That includes people who entered a card but did not complete the purchase. The company is still determining the scope and says it will contact affected people by email or other means once it is confirmed.

QShould I get my card reissued?
A

The company asks people to check their card statements and contact their card issuer about any charge they do not recognize. This site recommends that anyone who entered a card on PhotoGoods in that period ask the issuer to change the number, because the security code is among the items that may have leaked and the combination stays usable until the number changes. As of October 7, the company had said nothing about reissue fees or compensation.

QShould I change my password?
A

The company says it will explain how to change the PhotoGoods password once a formal procedure is decided. It asks people who use the same password on other services to consider changing it on each of those services' official sites. Even a password stored in converted form can sometimes be worked out if it is short or common, so if you reused it, change it soon.

QWhat caused it?
A

The company says it confirmed unauthorized third-party access through system vulnerabilities and abuse of a file-upload function. Which vulnerability, which upload function, and how the program reached the payment page have not been disclosed. The company says it is working to identify the cause.

QWhat if someone contacts me claiming to be PhotoGoods or Daiko Printing?
A

The company warns that suspicious emails, text messages and calls pretending to be the company or PhotoGoods may arrive. It asks people not to open links or attachments in unexpected messages and not to enter personal data, card details or passwords. Treat any 'apology' or 'refund' message that asks for card details as fake, and check through the official website you open yourself.