Skip to content
>_ITDITDWeb Security Platform

Security Guides

E-store ShopServe data breach (up to 8.85 million records): partial card numbers and shop passwords leaked — what buyers and shop owners should do

A malicious program on E-store's ShopServe servers sent out up to 8.85M buyer records plus shop passwords. How to tell if a shop you used is affected, and what to do.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 14 min read

For: anyone who has shopped online in Japan (especially if you received a notice email from E-store) and anyone who runs a shop on ShopServe. This article is based on E-store's official notices and announcements by affected shops, and does not cover attack techniques.

What buyers should do today

1

Check whether you are affected — start from the shop names

E-store has not published a list of affected shops. You can check in three ways:

  • Look for a notice email from E-store (in sample texts shared by recipients, the shop's name is not given)
  • Check the official sites of online shops you have used for notices mentioning unauthorized access or E-store
  • Ask E-store's buyer contact (support@estore.co.jp)

At least one affected shop said its affected buyers go back to 2008. A purchase made years ago can still be included.

2

Be suspicious of messages that quote real order details or your card's last four digits

The leak includes names, addresses, phone numbers and email addresses, plus the cardholder name, first 6 and last 4 card digits, and expiry date. That means a fake message can say "your card ending in 1234" and get the details right.

E-store also warns people not to enter card details or passwords when asked to for re-payment, identity checks, refunds or account checks. If you get such a message, do not use its links or phone numbers; open the shop's or card company's official site yourself (see What is phishing?).

3

Check your card statements

According to the company, full card numbers and security codes were not included in the leak. Still, in case a fake message tricks someone into entering card details, check your statements this month and for the next few months.

If you see a charge you do not recognize, call the number on the back of your card. You can also ask your card company whether a replacement card is needed.

4

Change reused passwords

The company says member IDs and passwords were stored encrypted and judges the risk of misuse to be low. If you use the same email address and password on other services, change those. The company also recommends a different password for each service and multi-factor authentication.

Changing your member password at the shop you used is also sensible. A password manager is the practical way to keep track.

5

If you entered your workplace, watch for suspicious messages at work too

Buyer data includes workplace. If you had orders delivered to your office, messages combining your name and employer may arrive by work email or phone. Check anything about deliveries or payments through the shop's official site.

What shop owners should do today

According to E-store, merchants' IDs and passwords for the admin panel, mail system and FTP (the method used to update a shop's page files), as well as payout bank account details, also leaked. In this incident, shop owners have more to do right away than buyers.

1

Change admin, mail and FTP passwords and turn on two-step verification

E-store asked merchants to take steps such as changing passwords, and recommends two-step verification (asking for a code or similar in addition to the password) for the admin panel. If you used the same passwords elsewhere, change those too.

2

Check your shop pages for changes you did not make

With FTP IDs and passwords, a third party could be in a position to rewrite your shop's page files. Look at the list of recently changed files for files your team did not update and for scripts loaded from places you do not recognize.

If a malicious script is placed on a checkout page, card details are stolen as buyers type them. The APORITO online store card-data case explains what that looks like.

3

Check mailbox forwarding rules and your payout bank details

In case your shop mail password was used, check that no unknown forwarding or filtering rules have been added. If order and inquiry emails are being forwarded outside, information keeps flowing even after you change the password.

Also confirm that your registered payout bank details have not changed. Verify any request such as "please change the payout account" or "we need to confirm your account for a deposit" by a channel other than email (to protect your own domain, see SPF, DKIM and DMARC).

4

Post a notice for your own customers

Most buyers do not know the name ShopServe, so E-store's notice email alone does not tell them which shop it is about. A notice on your own site that states the affected period, the leaked items (including whether card data was involved) and a contact point lets buyers judge their own situation.

What happened (from E-store's notices)

E-store Co., Ltd., a subsidiary of BASE, Inc., published a first notice on August 1, 2026 and a second notice on August 2. The following is taken from the company's official notices.

  1. May 21 – August 1, 2026

    The period in which an outside third party ran a malicious program on ShopServe servers and sent buyer data out (second notice).
  2. August 1

    The company confirmed a leak of buyer data from unauthorized access to its servers and published its first notice. It said it had cut off communication with the attack source and confirmed that access was no longer possible.
  3. August 2

    Second notice. It set the period as starting May 21 and added partial card data and merchants' credentials and payout accounts to the leaked items.
  4. From August

    Affected shops began announcing the impact on their own sites. Announcements from shops saying E-store had informed them continued into September.
8,853,839
Maximum records leaked (may count the same person more than once — not a head count)
First 6 + last 4
Part of the card number (plus name and expiry). Full numbers not included
Not affected
Security codes (the company does not hold them)
None reported
Secondary damage (as of August 2)
What leaked (from E-store's second notice)
Buyer data
Name, address, phone and fax numbers, email address, workplace, and other information buyers chose to enter (including delivery details)
Member data
Registration data including newsletter subscribers; member IDs and passwords (both stored encrypted; the company judges the risk of misuse to be low)
Credit cards
Cardholder name, part of the card number (first 6 and last 4 digits), expiry date. Security codes were not held and are not affected
Merchant data
IDs and passwords for the admin panel, mail system and FTP; payout bank account details
Count
Up to 8,853,839 records (may include duplicates of the same person; no head count published)
Cause
An outside third party ran a malicious program on the servers and sent buyer data out. The detailed cause is under investigation, with nothing further published
Secondary damage
As of August 2, no specific secondary damage caused by the incident had been reported
Reporting
The company said it would report to the Personal Information Protection Commission; filing with the local police under consideration (first notice)
Contact
Buyers: support@estore.co.jp / Merchants: sp@estore.co.jp

Reading note: the leaked items differ by shop

E-store's notice lists everything that leaked across the whole service. Announcements by affected shops show that some included card data and some did not, and the affected purchase period also differs by shop.

The reliable way to know your own situation is the notice from the shop you used. If you cannot find one, ask the shop or E-store's contact.

Why one service leaked buyer data from many shops

In a service like ShopServe, many shops share the same servers and software. To a buyer they look like separate shops, but where order data is kept and the programs that handle it are shared.

Company A's online shop

Company B's online shop

Company C's online shop

↓ buyers see only each shop's name ↓

Shared servers (ShopServe)

every shop's buyer data, partial card numbers, merchant passwords

↓ May 21 – August 1, 2026: a malicious program sends data out ↓

Up to 8,853,839 records

Buyers see only each shop's name, but behind it many shops use the same servers. A malicious program running on those servers can reach every shop's buyer data.

This setup has advantages. Each shop does not need its own server, and security updates can be applied in one place. But when the shared servers are breached, it is not one shop's problem but every shop's buyers who are affected.

What makes it hard for buyers is that they remember which shop they bought from, but not which service that shop runs on. That is why it is difficult to tell whether you are affected in this incident.

Not proof a message is genuine

  • It shows your name, address and phone number
  • The last four digits or expiry date of your card are correct
  • It names a shop you have bought from

What you can check yourself

  • Whether My Page or a contact point opened from the shop's official site tells you the same thing
  • Whether the charge appears in your card company's official app or online statement
  • Whether the message is asking you to enter a card number or password

For anyone running a service that holds data for many shops

The company has not said how the malicious program came to run or how credentials were stored. This section sticks to general points that services of the same shape (one system holding data for many client businesses) can check.

1

Treat "one process read many shops' data" as an alert signal

Normal order processing handles one shop's data per operation. A single process or database connection reading many shops' data in a short time is unusual outside scheduled batch jobs.

A first step: from database audit logs, count "shops touched per hour" for each connection source, and alert when anything other than a known batch job goes over a limit (for example, 10 shops).

2

Limit outbound traffic from servers by destination

In this case, buyer data was sent out from the servers. Servers that process orders only need to reach a few destinations, such as payment processors and delivery companies.

Allow outbound traffic only to the destinations you need, and log and alert on traffic to anywhere else and on unusually large transfers. Firewalls and cloud network settings can do this.

3

Protect each shop's secrets separately from shop data

If merchants' FTP and mail passwords and payout accounts can be read from the same place as buyer data, they leave together. Store credentials in a form that cannot be restored, and keep anything that must be restorable in a separate store with a separate key.

See storing passwords safely (hashing and salt) for storage, and the minimum security baseline for organizations for the wider picture.

4

Give client businesses what they need to explain a leak to their buyers

Buyers only know the name of the shop they used. A single service-wide notice from the operator does not let them tell whether they are affected.

Make sure you can quickly produce, per shop, the affected period, the leaked items and whether card data was involved, and include handing that to each client business so it can explain to its own buyers in your incident-response procedure.

For other online-shopping cases, see the Abahouse breach (order data and fake refund emails) and the APORITO online store (RIZAP); for other major Japanese breaches this year, see Japan's major data breaches of 2026.

Sources (public record)

The facts in this article come from the public sources below. Undisclosed methods or causes of the intrusion are not speculated on.

  • E-store Co., Ltd., apology and notice regarding a personal data leak from unauthorized access (August 1, 2026, Japanese) — estore.jp
  • E-store Co., Ltd., notice regarding a personal data leak from unauthorized access (second notice, August 2, 2026, Japanese) — estore.jp
  • Examples of announcements by affected shops (Japanese): Harima Chemicals Group, Inc. (second notice, August 10, 2026) — harima.co.jp / PFU Limited (September 18, 2026) — pfu.ricoh.com
  • Security NEXT (Japanese) — security-next.com
  • INTERNET Watch (Japanese) — internet.watch.impress.co.jp

Update history

2026-10-03: First version, based on E-store's notices of August 1 (first) and August 2 (second) and announcements by affected shops. The first notice placed the leak on the morning of August 1; the second set the period as May 21 to August 1 and added partial card data and merchant data to the leaked items. This article will be updated when the investigation results are published.

FAQ

QWhat leaked in the ShopServe breach?
A

According to E-store Co., Ltd.'s second notice of August 2, 2026, the leak covered buyer information (including delivery details) such as name, address, phone and fax numbers, email address and workplace; member information (including newsletter subscribers); encrypted member IDs and passwords; and cardholder name, part of the card number (first 6 and last 4 digits) and expiry date. For merchants it covered the IDs and passwords for the admin panel, mail system and FTP, and payout bank account details. The count is up to 8,853,839 records, which may include the same person more than once.

QWere full card numbers or security codes leaked?
A

According to the company, what leaked was part of the card number (first 6 and last 4 digits), the cardholder name and the expiry date. The company does not hold security codes (the 3 or 4 digits on the card), and they were not included. The last four digits and expiry date can still make a fake message look genuine, so checking statements and staying alert to suspicious contact is still needed.

QI have never heard of ShopServe. Am I affected?
A

ShopServe lets companies run online shops under their own names, and buyers usually see only the shop's name, so many people used it without knowing. E-store has not published a list of affected shops. You can check in three ways: look for a notice email from E-store, check the official websites of online shops you have used for announcements, or ask E-store's buyer contact. At least one affected shop said its affected buyers go back to 2008, so old purchases can be included.

QHas the data been misused?
A

E-store said that, as of August 2, 2026, no specific secondary damage caused by the incident had been reported. As of October 3, no later notice updating this appears on the company's press page. No reports so far does not mean the data will never be used.

QShould I change my password?
A

The company says member IDs and passwords were stored encrypted and judges the risk of misuse to be low for now. It still asks people who use the same email address and password elsewhere to set a different password for each service and to turn on multi-factor authentication where available. Changing your member password at the shop you used is also a good idea.

QWhat should shop owners do?
A

E-store asked merchants to take steps such as changing their admin, mail system and FTP passwords, and recommends turning on two-step verification for the admin panel. Merchants should also check their shop pages, which can be updated over FTP, for changes they did not make, look for unknown forwarding rules in their mailboxes, confirm their payout bank details have not been changed, and post a notice for their own customers.

QWhat caused the breach?
A

According to the company, an outside third party ran a malicious program on ShopServe servers and sent buyer data out. As of August 2 the detailed cause, such as how the program came to run, was still under investigation, and nothing further has been published. The company said it would report to Japan's Personal Information Protection Commission and is considering filing with the police.