Skip to content
>_ITDITDWeb Security Platform

Security Guides

If the security code is in scope, replace the card number — what APORITO Online Store customers and e-commerce operators should do

A malicious script planted on RIZAP's APORITO Online Store may have leaked card numbers, expiry dates and security codes of customers from May 1 to August 5, 2026. Based on the company's notices: what customers should do, and what e-commerce operators should review.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 15 min read

For: anyone who shopped or entered information on RIZAP's APORITO Online Store between May 1 and August 5, 2026, and anyone who runs an online store. This article is based on RIZAP Co., Ltd.'s official notices and does not cover attack techniques.

What customers should do today

1

Check whether you are affected — people who did not finish an order count

Affected people are those who placed an order or entered information on the APORITO Online Store between May 1 and August 5, 2026. Entering details without finishing the order still counts. On August 8 the company emailed people whose card data may have leaked. Search your inbox for "APORITO" first. If you find nothing but remember using the store in that period, go ahead with the steps below anyway.

2

Check your card statements and report unknown charges to the issuer immediately

The company asks customers to keep checking their card statements for charges they do not recognize. If you find one, call the issuer's number on the back of the card. Card issuers generally cover fraudulent use, but there is a reporting deadline (JCB, for example, requires notice within 60 days of the statement showing the charge). Small charges are easy to miss, so check unfamiliar charges of just a few hundred yen too.

3

Ask your card issuer to replace the number (reissue)

The company describes stopping or reissuing the card (changing the number) as an effective way to prevent secondary harm, and leaves the decision to each customer. This site recommends changing the number for anyone who used a card on the store during the period. The reasoning is in the next section; the short version is that the security code is among the items that may have leaked. The company says it will announce how reissue fees and similar costs will be handled after its investigation.

4

After replacing the card, update the services billed to it

Utilities, phone plans, subscriptions and other services that charge the old number automatically will fail until you switch them to the new one. Before requesting a reissue, make a list of recurring charges from your statement so none are missed.

5

Do not respond to calls or messages claiming to be the company, the police or your card issuer

With name, address, phone number and email address potentially exposed, a scammer can write very convincing messages. The company warns of calls, emails and texts that impersonate the company, the police or other public bodies, or card issuers in order to extract PINs or personal data, and states that it will never ask customers for a PIN. Do not open links about "refund procedures" or "re-registering your card"; if you need to check, contact an official number you looked up yourself (see What is phishing?).

6

If you will not use the store again, ask for your data to be deleted

The company accepts deletion requests and will reply individually after checking your usage and registration status. Requests go to the dedicated email address at the end of its notice. Some data may have to be kept for a period for the investigation or legal reasons, but getting an answer on what remains and until when is worth it on its own.

Why this site recommends replacing the number

Cases where watching statements is usually enough

  • Only part of the card number leaked
  • Expiry date and security code were not included
  • Any misuse would be small charges you would spot quickly

What is in scope here (per the company)

  • Card number, expiry date and security code together
  • Name, address, phone number and email address as well
  • Until the number changes, that combination stays usable

When you pay online, card number, expiry date and security code are the three basic items a checkout page asks for. In Japan, the industry guidelines require online merchants to adopt EMV 3-D Secure (cardholder authentication), so extra verification steps are more common than before. Still, not every transaction, and not every site in every country, triggers that extra check. Checking statements matters, but it is a way of noticing after the card has been used. Replacing the number makes the possibly leaked combination useless from that moment. Switching recurring payments is a chore, but it beats living for months with a card that might be used at any time.

How to read it: 'no misuse confirmed' does not mean 'safe'

The company says it has confirmed none of the following: misuse, secondary harm, or an actual leak of personal data. That means nothing has been found yet, not that nothing will be used later. Card data is sometimes used long after it is taken. Keep checking statements for at least several months.

What happened (from RIZAP's notices)

Everything below is as stated in the company's official notices.

  1. May 1, 2026

    Start of the period in which data may have leaked.
  2. Aug 5

    The company found a suspicious outbound-transmission program in the APORITO Online Store's system and, to prevent further harm, temporarily closed the site at 15:30 the same day. The affected period ends on this date.
  3. Aug 8

    People whose card data may have leaked were notified individually by email.
  4. Aug 10

    Public apology and report. The company said it had filed a preliminary report with the Personal Information Protection Commission and was dealing with the police and others as required by law.
  5. Aug 18

    Second notice: the investigation with an outside third-party firm continues and the store remains closed. The company said it is strengthening security and reviewing monitoring ahead of reopening.
97 days
Period in which data may have leaked (May 1 – Aug 5)
3 items
Card number, expiry date, security code
Not disclosed
Number of people affected (as of the Aug 18 notice)
Closed
Store status (as of the Aug 18 notice)
Data that may have leaked (from RIZAP's notices)
Who
People who placed an order or entered information on the APORITO Online Store between May 1 and August 5, 2026
Personal data
Name, address, phone number, email address
Card data
Card number, expiry date, security code
Number affected
Not disclosed
Stated cause
A third party planted a malicious script; a suspicious outbound-transmission program was found in the system. How it was planted and other technical details have not been disclosed
Secondary harm
The company says no misuse, secondary harm or actual leak of personal data has been confirmed
Compensation and costs
Handling of reissue fees and the compensation policy are under review; to be announced by email and on the company site
Existing orders
The company says the closure does not affect shipping; orders ship once stock is confirmed. Refund requests go to the dedicated email address

About a separate notice published the same day

Also on August 10, RIZAP published a separate notice that a company to which it outsources part of the APORITO business operations had suffered unauthorized access by ransomware, restricting some services (a second notice followed on August 14). The company's notices do not say whether the two are related. This article covers the malicious script on the online store.

For e-commerce operators: not storing card data does not protect the input page

The company has not disclosed what safeguards it had in place or how the script got there. This section does not evaluate its response; it sets out how to prevent the same kind of incident on your own site.

Customer's browser

Card details typed on the checkout page

↓

Payment service provider

The legitimate destination

↓

Not stored on your servers

= what non-retention protects

If a malicious script gets into the input page itself, what the customer types is also sent somewhere else on the spot

→ It leaks even though you store nothing. Defenders need to watch whether the page has changed

Where card data is protected and where it is not (general picture). Non-retention means not storing data on your servers; it does not cover an input page altered in the customer's browser.

In Japan, Article 35-16 of the Installment Sales Act requires card merchants, including online stores, to take the measures necessary for proper management of card numbers, such as preventing leaks. The practical guide to that duty is the Credit Card Security Guidelines of the Council for Credit Transaction Security (secretariat: the Japan Consumer Credit Association). The guidelines state that taking the measures they list, or equivalent or stronger ones, is regarded as taking the "necessary and appropriate measures" the law requires.

Starting with version 6.0 in March 2025, the guidelines added "vulnerability measures" for online merchants, whether or not they retain card data. The stated reason: most leaks now happen at online merchants that have already achieved non-retention, through website vulnerabilities and similar causes. Version 6.1 (March 2026) keeps this unchanged. Five measures are required, all of them:

#Guideline itemWhat it says (summary)
1Restrict access to the admin screen; manage admin IDs and passwordsLimit admin access by IP address (or basic authentication if that is not possible), use two-step or multi-factor authentication, lock accounts after 10 or fewer failed logins
2Fix misconfigurations that expose data directoriesKeep important files out of public directories; restrict the file types and extensions that can be uploaded
3Address web application vulnerabilitiesRun vulnerability assessments or penetration tests regularly and fix findings; keep plugins and software up to date; review source code of customized parts
4Install and run antivirus software against malwareKeep signatures updated and run regular full scans
5Counter malicious card-validity checks and "credit master" attacksImplement at least one of the measures listed in the annex

The guidelines' annex for online merchants says many leaks target misconfigurations and vulnerabilities in e-commerce packages and CMSs, and that cases of altered scripts leaking what members type, continuously, have been confirmed. It also says merchants that outsource building or running their site should require the contractor to understand these vulnerability measures.

This site's view: the five measures keep attackers out; add one way to notice when they get in

All five measures are about preventing intrusion or planting. But with this type of incident, everyone who types their card details before anyone notices is affected. So in general, how quickly you notice when prevention fails determines how many people end up in scope (which is why IPA's guideline makes file-tampering detection mandatory).

Other public standards already cover the "notice" side. IPA's (Information-technology Promotion Agency, Japan) e-commerce site security guideline lists, as mandatory operational requirements, regular diff checks of important files and monitoring with website tamper-detection tools. The card industry's international standard, PCI DSS, has since March 31, 2025 required authorization, integrity checks and an inventory of scripts running on payment pages (requirement 6.4.3) and a mechanism to detect unauthorized changes to payment pages (requirement 11.6.1).

For a small online store, start with these three:

1

List the scripts your checkout page loads

Write down every JavaScript file the checkout page loads, grouped as your own, your payment provider's, and analytics or other tags. Any script no one can explain — who added it and why — is the first thing to check. Only with a list can you notice that something was added or changed.

2

Diff your site files daily and alert on changes

For the files that make up the checkout page — themes, templates, JavaScript — record a hash (a kind of fingerprint) of the known-good state and compare once a day. If something changed when no one deployed, an alert goes to the person responsible. Also check whether your hosting or e-commerce platform offers a tamper-detection feature or add-on. If you run the server yourself, the thinking overlaps with file upload vulnerabilities.

3

Restrict the admin screen to your network and two factors

This is measure 1 itself. If the admin screen can be reached from anywhere with just a password, fix that first. If a contractor runs the site, confirm the contractor's admin logins meet the same conditions. The organization-wide minimum is in The minimum security baseline for organizations.

Sources (public record)

The facts in this article come from the public sources below. Undisclosed intrusion routes or methods are not speculated on.

  • RIZAP Co., Ltd., apology and report on unauthorized access to the APORITO Online Store (August 10, 2026, Japanese) — rizap.co.jp
  • RIZAP Co., Ltd., second notice on the same incident (August 18, 2026, Japanese) — rizap.co.jp
  • RIZAP Co., Ltd., notices on the system outage and service suspension in the APORITO business (August 10 and 14, 2026, Japanese) — rizap.co.jp / rizap.co.jp
  • Installment Sales Act, Article 35-16 (Japanese) — e-Gov Law Search
  • Council for Credit Transaction Security, Credit Card Security Guidelines version 6.1 (March 2026), revision notes, and the online-merchant security guide (Annex 20) (Japanese) — Japan Consumer Credit Association
  • IPA, E-commerce site construction and operation security guideline (March 16, 2023, Japanese) — ipa.go.jp
  • PCI Security Standards Council, "New Information Supplement: Payment Page Security and Preventing E-Skimming" (March 10, 2025) — blog.pcisecuritystandards.org / "Guidance for PCI DSS E-commerce Requirements Effective After 31 March 2025" — blog.pcisecuritystandards.org
  • Example of a reporting deadline for fraud compensation: JCB (Japanese) — jcb.co.jp

Update history

2026-09-30: First version, based on RIZAP's notice of August 10 and second notice of August 18. The company plans to publish technical findings, its compensation policy and a reopening date; this article will be updated when it does.

FAQ

QWhat happened at the APORITO Online Store?
A

According to RIZAP Co., Ltd.'s notice of August 10, 2026, a third party planted a malicious script on the APORITO Online Store it operates, and customers' personal and credit card data may have been sent outside. The company found a suspicious outbound-transmission program in the system on August 5 and temporarily closed the site at 15:30 that day. Its second notice on August 18 said the store remained closed while an outside investigation continued.

QAm I affected?
A

The company says affected people are those who placed an order or entered information on the APORITO Online Store between May 1 and August 5, 2026. That includes people who entered details but never completed an order. On August 8, 2026, the company emailed people whose card data may have leaked.

QWhat data may have leaked?
A

Per the company: personal data (name, address, phone number, email address) and credit card data (card number, expiry date, security code). The number of affected people has not been disclosed. The company says it has not confirmed any misuse, secondary harm, or actual leak of personal data so far.

QShould I get my card reissued?
A

The company describes stopping or reissuing the card (changing the number) as an effective way to prevent secondary harm, but leaves the decision to each customer and does not ask everyone to do it. This site recommends that anyone who used a card on the store during the period ask the issuer for a new number: the security code is among the items that may have leaked, and until the number changes, that combination stays usable. The company says it will announce how reissue fees and similar costs will be handled after its investigation.

QWill I get my money back if my card is misused?
A

The company notes that card issuers' compensation schemes generally apply to fraudulent use. Compensation has a reporting deadline set by each issuer's terms; JCB, for example, requires notice within 60 days of the statement showing the charge. If you see a charge you do not recognize, call the number on the back of your card right away.

QCan I have my data deleted?
A

The company says it accepts deletion requests and will reply individually after checking your usage and registration status. Requests go to the dedicated email address at the end of its notice. It adds that some data may need to be kept for a period for the investigation or legal obligations.

QWhat caused it?
A

As of the second notice on August 18, 2026, how the script was planted and other technical details had not been disclosed. The company is working with an outside investigator and says it will report confirmed facts, technical findings and the reopening date once the investigation and safety checks are complete.