Security Guides
If the security code is in scope, replace the card number — what APORITO Online Store customers and e-commerce operators should do
A malicious script planted on RIZAP's APORITO Online Store may have leaked card numbers, expiry dates and security codes of customers from May 1 to August 5, 2026. Based on the company's notices: what customers should do, and what e-commerce operators should review.
For: anyone who shopped or entered information on RIZAP's APORITO Online Store between May 1 and August 5, 2026, and anyone who runs an online store. This article is based on RIZAP Co., Ltd.'s official notices and does not cover attack techniques.
What customers should do today
Check whether you are affected — people who did not finish an order count
Affected people are those who placed an order or entered information on the APORITO Online Store between May 1 and August 5, 2026. Entering details without finishing the order still counts. On August 8 the company emailed people whose card data may have leaked. Search your inbox for "APORITO" first. If you find nothing but remember using the store in that period, go ahead with the steps below anyway.
Check your card statements and report unknown charges to the issuer immediately
The company asks customers to keep checking their card statements for charges they do not recognize. If you find one, call the issuer's number on the back of the card. Card issuers generally cover fraudulent use, but there is a reporting deadline (JCB, for example, requires notice within 60 days of the statement showing the charge). Small charges are easy to miss, so check unfamiliar charges of just a few hundred yen too.
Ask your card issuer to replace the number (reissue)
The company describes stopping or reissuing the card (changing the number) as an effective way to prevent secondary harm, and leaves the decision to each customer. This site recommends changing the number for anyone who used a card on the store during the period. The reasoning is in the next section; the short version is that the security code is among the items that may have leaked. The company says it will announce how reissue fees and similar costs will be handled after its investigation.
After replacing the card, update the services billed to it
Utilities, phone plans, subscriptions and other services that charge the old number automatically will fail until you switch them to the new one. Before requesting a reissue, make a list of recurring charges from your statement so none are missed.
Do not respond to calls or messages claiming to be the company, the police or your card issuer
With name, address, phone number and email address potentially exposed, a scammer can write very convincing messages. The company warns of calls, emails and texts that impersonate the company, the police or other public bodies, or card issuers in order to extract PINs or personal data, and states that it will never ask customers for a PIN. Do not open links about "refund procedures" or "re-registering your card"; if you need to check, contact an official number you looked up yourself (see What is phishing?).
If you will not use the store again, ask for your data to be deleted
The company accepts deletion requests and will reply individually after checking your usage and registration status. Requests go to the dedicated email address at the end of its notice. Some data may have to be kept for a period for the investigation or legal reasons, but getting an answer on what remains and until when is worth it on its own.
Why this site recommends replacing the number
Cases where watching statements is usually enough
- Only part of the card number leaked
- Expiry date and security code were not included
- Any misuse would be small charges you would spot quickly
What is in scope here (per the company)
- Card number, expiry date and security code together
- Name, address, phone number and email address as well
- Until the number changes, that combination stays usable
When you pay online, card number, expiry date and security code are the three basic items a checkout page asks for. In Japan, the industry guidelines require online merchants to adopt EMV 3-D Secure (cardholder authentication), so extra verification steps are more common than before. Still, not every transaction, and not every site in every country, triggers that extra check. Checking statements matters, but it is a way of noticing after the card has been used. Replacing the number makes the possibly leaked combination useless from that moment. Switching recurring payments is a chore, but it beats living for months with a card that might be used at any time.
How to read it: 'no misuse confirmed' does not mean 'safe'
The company says it has confirmed none of the following: misuse, secondary harm, or an actual leak of personal data. That means nothing has been found yet, not that nothing will be used later. Card data is sometimes used long after it is taken. Keep checking statements for at least several months.
What happened (from RIZAP's notices)
Everything below is as stated in the company's official notices.
May 1, 2026
Start of the period in which data may have leaked.Aug 5
The company found a suspicious outbound-transmission program in the APORITO Online Store's system and, to prevent further harm, temporarily closed the site at 15:30 the same day. The affected period ends on this date.Aug 8
People whose card data may have leaked were notified individually by email.Aug 10
Public apology and report. The company said it had filed a preliminary report with the Personal Information Protection Commission and was dealing with the police and others as required by law.Aug 18
Second notice: the investigation with an outside third-party firm continues and the store remains closed. The company said it is strengthening security and reviewing monitoring ahead of reopening.
- Who
- People who placed an order or entered information on the APORITO Online Store between May 1 and August 5, 2026
- Personal data
- Name, address, phone number, email address
- Card data
- Card number, expiry date, security code
- Number affected
- Not disclosed
- Stated cause
- A third party planted a malicious script; a suspicious outbound-transmission program was found in the system. How it was planted and other technical details have not been disclosed
- Secondary harm
- The company says no misuse, secondary harm or actual leak of personal data has been confirmed
- Compensation and costs
- Handling of reissue fees and the compensation policy are under review; to be announced by email and on the company site
- Existing orders
- The company says the closure does not affect shipping; orders ship once stock is confirmed. Refund requests go to the dedicated email address
About a separate notice published the same day
Also on August 10, RIZAP published a separate notice that a company to which it outsources part of the APORITO business operations had suffered unauthorized access by ransomware, restricting some services (a second notice followed on August 14). The company's notices do not say whether the two are related. This article covers the malicious script on the online store.
For e-commerce operators: not storing card data does not protect the input page
The company has not disclosed what safeguards it had in place or how the script got there. This section does not evaluate its response; it sets out how to prevent the same kind of incident on your own site.
Customer's browser
Card details typed on the checkout page
↓→
Payment service provider
The legitimate destination
↓→
Not stored on your servers
= what non-retention protects
If a malicious script gets into the input page itself, what the customer types is also sent somewhere else on the spot
→ It leaks even though you store nothing. Defenders need to watch whether the page has changed
In Japan, Article 35-16 of the Installment Sales Act requires card merchants, including online stores, to take the measures necessary for proper management of card numbers, such as preventing leaks. The practical guide to that duty is the Credit Card Security Guidelines of the Council for Credit Transaction Security (secretariat: the Japan Consumer Credit Association). The guidelines state that taking the measures they list, or equivalent or stronger ones, is regarded as taking the "necessary and appropriate measures" the law requires.
Starting with version 6.0 in March 2025, the guidelines added "vulnerability measures" for online merchants, whether or not they retain card data. The stated reason: most leaks now happen at online merchants that have already achieved non-retention, through website vulnerabilities and similar causes. Version 6.1 (March 2026) keeps this unchanged. Five measures are required, all of them:
| # | Guideline item | What it says (summary) |
|---|---|---|
| 1 | Restrict access to the admin screen; manage admin IDs and passwords | Limit admin access by IP address (or basic authentication if that is not possible), use two-step or multi-factor authentication, lock accounts after 10 or fewer failed logins |
| 2 | Fix misconfigurations that expose data directories | Keep important files out of public directories; restrict the file types and extensions that can be uploaded |
| 3 | Address web application vulnerabilities | Run vulnerability assessments or penetration tests regularly and fix findings; keep plugins and software up to date; review source code of customized parts |
| 4 | Install and run antivirus software against malware | Keep signatures updated and run regular full scans |
| 5 | Counter malicious card-validity checks and "credit master" attacks | Implement at least one of the measures listed in the annex |
The guidelines' annex for online merchants says many leaks target misconfigurations and vulnerabilities in e-commerce packages and CMSs, and that cases of altered scripts leaking what members type, continuously, have been confirmed. It also says merchants that outsource building or running their site should require the contractor to understand these vulnerability measures.
This site's view: the five measures keep attackers out; add one way to notice when they get in
All five measures are about preventing intrusion or planting. But with this type of incident, everyone who types their card details before anyone notices is affected. So in general, how quickly you notice when prevention fails determines how many people end up in scope (which is why IPA's guideline makes file-tampering detection mandatory).
Other public standards already cover the "notice" side. IPA's (Information-technology Promotion Agency, Japan) e-commerce site security guideline lists, as mandatory operational requirements, regular diff checks of important files and monitoring with website tamper-detection tools. The card industry's international standard, PCI DSS, has since March 31, 2025 required authorization, integrity checks and an inventory of scripts running on payment pages (requirement 6.4.3) and a mechanism to detect unauthorized changes to payment pages (requirement 11.6.1).
For a small online store, start with these three:
List the scripts your checkout page loads
Write down every JavaScript file the checkout page loads, grouped as your own, your payment provider's, and analytics or other tags. Any script no one can explain — who added it and why — is the first thing to check. Only with a list can you notice that something was added or changed.
Diff your site files daily and alert on changes
For the files that make up the checkout page — themes, templates, JavaScript — record a hash (a kind of fingerprint) of the known-good state and compare once a day. If something changed when no one deployed, an alert goes to the person responsible. Also check whether your hosting or e-commerce platform offers a tamper-detection feature or add-on. If you run the server yourself, the thinking overlaps with file upload vulnerabilities.
Restrict the admin screen to your network and two factors
This is measure 1 itself. If the admin screen can be reached from anywhere with just a password, fix that first. If a contractor runs the site, confirm the contractor's admin logins meet the same conditions. The organization-wide minimum is in The minimum security baseline for organizations.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed intrusion routes or methods are not speculated on.
- RIZAP Co., Ltd., apology and report on unauthorized access to the APORITO Online Store (August 10, 2026, Japanese) — rizap.co.jp
- RIZAP Co., Ltd., second notice on the same incident (August 18, 2026, Japanese) — rizap.co.jp
- RIZAP Co., Ltd., notices on the system outage and service suspension in the APORITO business (August 10 and 14, 2026, Japanese) — rizap.co.jp / rizap.co.jp
- Installment Sales Act, Article 35-16 (Japanese) — e-Gov Law Search
- Council for Credit Transaction Security, Credit Card Security Guidelines version 6.1 (March 2026), revision notes, and the online-merchant security guide (Annex 20) (Japanese) — Japan Consumer Credit Association
- IPA, E-commerce site construction and operation security guideline (March 16, 2023, Japanese) — ipa.go.jp
- PCI Security Standards Council, "New Information Supplement: Payment Page Security and Preventing E-Skimming" (March 10, 2025) — blog.pcisecuritystandards.org / "Guidance for PCI DSS E-commerce Requirements Effective After 31 March 2025" — blog.pcisecuritystandards.org
- Example of a reporting deadline for fraud compensation: JCB (Japanese) — jcb.co.jp
Update history
2026-09-30: First version, based on RIZAP's notice of August 10 and second notice of August 18. The company plans to publish technical findings, its compensation policy and a reopening date; this article will be updated when it does.
Read next
- Follow-on scams: What is phishing?
- Standards for card data: What is PCI DSS? / What is XSS (cross-site scripting)?
- For site operators: File upload vulnerabilities / The minimum security baseline for organizations
- Other Japanese cases this season: Cariteco (Meitetsu Kyosho): ransomware and a possible data leak / The Times Car breach
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat happened at the APORITO Online Store?
According to RIZAP Co., Ltd.'s notice of August 10, 2026, a third party planted a malicious script on the APORITO Online Store it operates, and customers' personal and credit card data may have been sent outside. The company found a suspicious outbound-transmission program in the system on August 5 and temporarily closed the site at 15:30 that day. Its second notice on August 18 said the store remained closed while an outside investigation continued.
QAm I affected?
The company says affected people are those who placed an order or entered information on the APORITO Online Store between May 1 and August 5, 2026. That includes people who entered details but never completed an order. On August 8, 2026, the company emailed people whose card data may have leaked.
QWhat data may have leaked?
Per the company: personal data (name, address, phone number, email address) and credit card data (card number, expiry date, security code). The number of affected people has not been disclosed. The company says it has not confirmed any misuse, secondary harm, or actual leak of personal data so far.
QShould I get my card reissued?
The company describes stopping or reissuing the card (changing the number) as an effective way to prevent secondary harm, but leaves the decision to each customer and does not ask everyone to do it. This site recommends that anyone who used a card on the store during the period ask the issuer for a new number: the security code is among the items that may have leaked, and until the number changes, that combination stays usable. The company says it will announce how reissue fees and similar costs will be handled after its investigation.
QWill I get my money back if my card is misused?
The company notes that card issuers' compensation schemes generally apply to fraudulent use. Compensation has a reporting deadline set by each issuer's terms; JCB, for example, requires notice within 60 days of the statement showing the charge. If you see a charge you do not recognize, call the number on the back of your card right away.
QCan I have my data deleted?
The company says it accepts deletion requests and will reply individually after checking your usage and registration status. Requests go to the dedicated email address at the end of its notice. It adds that some data may need to be kept for a period for the investigation or legal obligations.
QWhat caused it?
As of the second notice on August 18, 2026, how the script was planted and other technical details had not been disclosed. The company is working with an outside investigator and says it will report confirmed facts, technical findings and the reopening date once the investigation and safety checks are complete.