Skip to content
>_ITDITDWeb Security Platform

Security Guides

skyticket (Adventure Inc.) Data Breach (About 14.64 Million Records): Hashed Passwords and Refund Bank Details Exposed — What Users Should Do Today

Adventure Inc., which runs the travel booking site skyticket, disclosed three unauthorized-access incidents. The largest exposed about 14.64 million records (4.13 million with hashed passwords); others involved refund bank details and bus bookings. What to do today.

Published 2026-10-10 Updated 2026-10-11 Last verified 2026-10-11 17 min read

For: anyone who has registered or booked on skyticket (a Japanese site for comparing and booking flights, hotels, buses and more), anyone who gave a bank account for a refund, anyone who booked a bus through skyticket between August and October 2026, and anyone who runs a booking site. This article is based on Adventure Inc.'s official notices and does not cover attack techniques.

Developing: this article will be updated as the organisation publishes more

As of October 10, 2026

Not yet known

  • Remaining record count for the second incident (still being counted)
  • Whether passport numbers were exposed in the second incident
  • Actual number of people across all three incidents (without duplicates)
  • Details of how the administrative function was misused
  • When payment with saved cards will resume

The company began emailing affected people on October 8 and published the details and record counts of the three incidents on October 9. It says it will keep investigating and announce any new facts promptly. On October 10 it said a mail server outage caused by the surge in inquiries had been fixed.

What skyticket users should do today

1

Change your skyticket password from the official site or app

In the first incident, about 4.13 million member login passwords leaked in hashed form. Hashing converts a password into a form that is hard to turn back, but the company itself warns that passwords may be worked out through analysis and used for unauthorized logins (how hashing works: What is password hashing?).

The company asks members to change their password. Do it by logging in to the official skyticket site or app, not through a link in an email. The company says its emails do not contain any link asking you to enter a password.

2

Change the same password on every other service

The company asks people who use the same password elsewhere to change it there too. A recovered password can be tried together with your email address on other sites.

Start with the accounts that would hurt most if taken over: email, online banking and shopping sites. If you are not sure where you reused it, see how to check whether your password leaked and how to choose a password manager.

As of October 10, skyticket's notices say nothing about two-step verification. On the other services you change, turn it on if it is offered (see choosing multi-factor authentication).

3

Check your booking history and card statement

The company asks users to check the booking history in their account and their credit card statements. Card numbers did not leak, but if someone logs in to your account, a saved card could be used to book. To prevent this, the company suspended payment with saved cards and card saving at around 6 p.m. on October 7.

Report unknown bookings to the company's contact and unknown charges to your card issuer. The company says it confirmed one unauthorized login to a member account on September 9.

4

Ignore messages about refunds, compensation or booking changes

The company warns that emails, text messages, calls and letters pretending to be the company, banks, airlines or bus operators may arrive. With names, dates of birth, phone numbers and addresses exposed, such messages can look convincing.

The company says it will never ask for payment in connection with this incident. Treat any message asking you to transfer money, pay a fee or install an app in the name of a refund or compensation as fake. Do not use the links or phone numbers in it; check through the official site you open yourself (see What is phishing?).

The emails the company has been sending since October 8 come from info@skyticket.com, in four subject variants beginning "【重要】不正アクセスによるお客様情報" with an English line such as "[Important] Apology for Information Leak Due to Unauthorized Access". The company says mail from any other address, or mail asking you to enter a password, may be a fake.

5

If you gave a refund bank account, never share your PIN or one-time codes

In the second incident, refund bank details (bank name, branch, account type, account number and account holder name) leaked or may have leaked. The company says this information alone does not let anyone withdraw money immediately.

The danger is a contact posing as a refund process to obtain your PIN or online banking ID and password. The Japanese Bankers Association says it never asks customers for PINs or passwords, and Japan's National Police Agency says police officers never ask for PINs by phone. The same goes for one-time passwords: do not give them out by phone or text message.

Check your passbook or banking app for transactions you do not recognize, and contact your bank if you find any. We found no official guidance saying the account must be replaced only because the number leaked. If you are worried, call your bank using the number on your card or its official site.

6

If you booked a bus, check the booking in your official account

In the third incident, the bus booking completion page could be displayed without logging in between August 3 and October 1, 2026. Trip date and time, boarding and drop-off points, operator, service name and the operator's booking number were among the items viewed.

The company warns that someone with this information may pose as the company or the bus operator and ask you to change or cancel the booking or pay an extra fee. You can check or cancel bookings 24 hours a day under "予約確認" (booking confirmation) in your account. If a booking was changed or cancelled without your knowledge, contact the company.

7

Use the contact listed in the official notice

The contact in the company's notice is the "skyticket inquiry desk for the personal data leak" (email: info@skyticket.com). The company's October 8 notice on its corporate site gives hours of 10 a.m. to 6 p.m. daily. As of October 10, the company says inquiries are very high, phones are hard to reach and email replies are delayed. Do what you can yourself, such as changing your password, while you wait.

What happened (from Adventure Inc.'s notices)

The following is based on the October 8, 9 and 10 notices that Adventure Inc. posted on the skyticket site and its corporate website. The October 9 notice is identical on both sites.

  1. August 3 – October 1, 2026

    The bus booking completion page could be displayed without logging in (third incident). Found and fixed on October 1.
  2. September 9

    One unauthorized login to a member account confirmed.
  3. September 20

    Unauthorized access to the business management system (second incident). Found on September 28.
  4. October 2–4

    Unauthorized access to servers and cloud data, starting from misuse of an administrative function (first incident). Found on October 5.
  5. October 7, around 6 p.m.

    Payment with saved cards and card saving suspended.
  6. October 8, from around 7 p.m.

    Emails to affected people begin. The same day, a notice confirms these emails are genuine.
  7. October 9

    Details, record counts and exposed items of the three incidents published. The company says it has reported to the Personal Information Protection Commission.
  8. October 10

    The company says a mail server outage caused by the surge in inquiries has been fixed.
~14.64M
Records exposed in the first incident
~4.13M
Of those, records with hashed member passwords
17,780
Second incident: records incl. refund bank details (duplicates included, more being counted)
~12,000
Third incident: bus bookings viewed or possibly viewed
The three incidents and the data involved (from the company's notice)
First: access to company servers
October 2–4, 2026. Some skyticket administrative functions were misused, and from there other servers and data stored in the cloud were accessed. About 14.64 million records
Exposed in the first incident
Name (including passport spelling), date of birth, email address, phone number, postal code and address, remitter name for bank transfers, hashed member password (about 4.13 million records). Passport numbers confirmed not exposed
Second: business management system
September 20, 2026. A vulnerability in the business management system was exploited. 17,780 records (including duplicates; more still being counted)
Exposed or possibly exposed in the second
Name, phone number, refund bank details (bank, branch, account type, account number, account holder name) and more. For some people also email address and date of birth (68 records) and address (18 records)
Third: bus booking details viewed
August 3 – October 1, 2026. The booking completion page could be shown without logging in and was viewed by a third party in an automated way. About 12,000 bookings (more people when companions are counted)
Viewed or possibly viewed in the third
Booker's name (katakana), age, gender, date of birth (if registered), email, phone, member ID, device type used to book, payment method and amount, booking date, trip details (including the operator's booking number), companions' names, ages and genders
Not exposed
Credit card data (held by a payment service provider, not the company) and passport images were not exposed in any incident
Response
Access routes cut off and vulnerabilities addressed; saved-card payment suspended; affected people emailed in turn; reported to the Personal Information Protection Commission

What is known and what is not

Status as of October 10, 2026. When new notices come out, we will update the status column.

ItemWhat the notice saysStatus
First incident: count and itemsAbout 14.64M records; name, date of birth, email, phone, address, remitter name and moreLeak confirmed (company)
Hashed passwordsAbout 4.13M of the first incident's recordsLeak confirmed (company)
Second incident: bank details etc.17,780 records (including duplicates)Leaked or possibly leaked (company)
Second incident: remaining count"Some records are still being counted"Under investigation
Third incident: bus bookingsAbout 12,000 bookings; more people with companionsViewed or possibly viewed (company)
Credit card dataNot stored by the company; not exposedNot leaked (company)
Passport imagesNot stored by the company; not exposedNot leaked (company)
Passport numbers (first incident)Confirmed not exposedNot leaked (company)
Passport numbers (second incident)No exposure confirmed yet; still checkingUnder investigation
People across all threeOnly per-incident counts; no de-duplicated totalNot disclosed
CauseGiven per incident (misused admin function / system vulnerability / page visible without login)Disclosed (no details)
Secondary harmNone confirmed apart from one unauthorized login (September 9)One case confirmed
Saved-card paymentSuspended since around 6 p.m. on October 7Resumption date not set

How to read this: the three counts cannot be added up

About 14.64 million, 17,780 and about 12,000 are counts for three different incidents. The second count "includes duplicates," and one person may appear in more than one incident. The company has not published a de-duplicated number of people, so this site does not give a total either.

What the exposed combinations can be used for

In general, the following combinations can enable the following misuse. This does not mean it has happened in this case.

Email address + hashed password

↓

Recovered passwords tried on skyticket and other sites

→ Change the password and stop reusing it

Name + phone + refund bank details

↓

"Refund" calls or texts that quote your real account number

→ Never give a PIN, login details or one-time code

Contact details + trip + operator booking number

↓

"Change" or "extra fee" messages quoting your real booking

→ Check the booking in your official account

Combinations of exposed items and the matching action (general mapping)

What the exposed data can enable

  • Convincing emails, texts and calls that get your name or booking right
  • Demands for transfers or fees in the name of a "refund" or "compensation"
  • Logins to other services with a recovered, reused password

What the exposed data alone cannot do

  • Withdraw money with only an account number and holder name
  • Shop with a leaked card number (card data was not exposed)
  • Pass identity checks with a passport image (images were not exposed)

Whether such misuse works usually depends on whether the recipient gives out a PIN or code or opens a link. A message being accurate does not prove it is genuine. Past cases of the same type include Lashinbang, where refund-style bank details leaked, and TEMAIRAZU, where fake messages quoting real bookings were sent.

For booking-site operators: what the three disclosed routes let you check

The company gave a cause for each incident but no details, such as how the administrative function was misused or which vulnerability was involved. This section sticks to what operators can check on their own sites based on what was disclosed. It is not an assessment of the company's response.

1

Never show a booking completion page without a login or an unguessable key

The company says the third incident's completion page could be shown without logging in and was viewed by a third party in an automated way during that period (August 3 to October 1). Completion pages and the pages linked from confirmation emails gather names, contact details and booking numbers in one place.

Check whether the page verifies who is looking. Require a login, or, if it must work without one, put a long unguessable string in the URL and give it an expiry. In general, if changing a number in the URL shows someone else's booking, that is a classic flaw called IDOR (background: authentication vs authorization).

2

Limit and alert on bulk requests to the same page

"Viewed in an automated way" means far more requests than a person would make. For a page like a booking completion page, which one person rarely needs to open repeatedly, cap the number of views per source and alert someone when the cap is hit.

You can measure in the application or in front of it, at the web server or CDN (content delivery network). How to start is covered in rate limiting and abuse control.

3

Be ready to switch off saved cards when passwords leak

After password hashes leaked, the company suspended payment with saved cards. If a hijacked account can pay with a saved card, fraudulent purchases happen even when no card number has leaked.

Check in advance whether your site can switch off saved-card payment on its own, or require the card issuer's authentication (3-D Secure) on each payment. If there is no switch, you will be building one on the day of the incident.

4

Decide how long to keep refund bank details

The second incident involved refund bank details held in a business management system. A refund is often a one-off process, so decide how long to keep bank details once the refund is complete, and delete them automatically when that time is up. Data you no longer hold cannot leak.

This site's view: check each kind of entry point separately

In this case, three incidents by different routes came to light within eight days, from September 28 to October 5. Fixing one problem does not reveal the others unless the admin functions, internal business systems and user-facing pages are each checked separately. Operators should list their externally reachable entry points in three groups: admin screens, internal systems, and pages visible without logging in.

Sources (public record)

The facts in this article come from the public sources below. We have not speculated about undisclosed intrusion routes or methods.

  • Adventure Inc., "Apology and notice regarding the leak of customer information due to unauthorized access" (October 9, 2026, skyticket, Japanese) — skyticket.jp
  • Adventure Inc., same notice on the corporate website (October 9, 2026, Japanese) — jp.adventurekk.com
  • Adventure Inc., "About the 'notice of personal information leak' email sent by skyticket" (October 9, 2026, skyticket, Japanese) — skyticket.jp
  • Adventure Inc., "About the 'notice of personal information leak' email sent by the company" (October 8, 2026, company website, Japanese) — jp.adventurekk.com
  • Adventure Inc., "Notice of recovery from the mail server outage" (October 10, 2026, Japanese) — skyticket.jp
  • Japanese Bankers Association, warning about fake sites and callers (Japanese) — zenginkyo.or.jp
  • National Police Agency, warning about unauthorized withdrawals from bank accounts (Japanese) — npa.go.jp

Update history

2026-10-11: Corrected a source date (the notice about the emails was posted on October 8 on the company website and on October 9 on the skyticket site).
2026-10-10: First version, based on the company's notices of October 8 (emails to affected people), October 9 (details and counts of the three incidents) and October 10 (mail server recovery). We will update when the remaining count for the second incident, the passport-number check and other open items are published.

FAQ

QWhat leaked from skyticket?
A

According to Adventure Inc.'s notice of October 9, 2026, there were three separate incidents. The first (about 14.64 million records) exposed names (including passport spelling), dates of birth, email addresses, phone numbers, postal codes and addresses, the remitter name used for bank transfers, and hashed member passwords (about 4.13 million records). The second (17,780 records, including duplicates) exposed or may have exposed names, phone numbers and refund bank account details (bank name, branch, account type, account number and account holder name), among other items. The third (about 12,000 bookings) means bus booking details were or may have been viewed: the booker's name in katakana, contact details, member ID, trip details, and companions' names, ages and genders.

QAm I affected?
A

The first incident covers people who registered with or entered details on skyticket, about 14.64 million records, so the range is very wide. The company says it is emailing affected people in turn, and that its October 9 notice serves as notice for anyone the email does not reach. If you have ever registered or booked on skyticket, assume you are affected and change your password even if no email arrived. The second incident mainly concerns people who gave a bank account for a refund, and the third concerns bus bookings whose completion page was shown between August 3 and October 1, 2026.

QWere card numbers or passport numbers exposed?
A

The company says it does not store card numbers or passport images, and that neither was exposed in any of the three incidents. For passport numbers, the company confirmed they were not exposed in the first incident. For the second, as of October 10 no exposure had been confirmed, but the company says it is still checking. Separately, to stop saved cards being used through hijacked accounts, the company suspended payment with saved cards and card saving at around 6 p.m. on October 7.

QWhat caused it?
A

The company gives a different cause for each incident: some administrative functions of skyticket were misused, and from there other servers and data in the cloud were accessed; a vulnerability in a business management system was exploited; and the bus booking completion page could be shown without logging in and was viewed by a third party in an automated way (fixed on October 1). How the administrative functions were misused and which vulnerability was involved have not been disclosed.

QWhat if someone contacts me claiming to be skyticket or my bank?
A

The company warns that fraudulent emails, text messages, calls and letters pretending to be the company, banks, airlines or bus operators may arrive. It says it will never ask for passwords, card numbers or bank PINs, will not ask for any payment in connection with this incident, and that its emails contain no link asking you to enter a password. Do not use the links or phone numbers in a message; check through the official site or app you open yourself, or the contact in the official notice (info@skyticket.com).

QI gave a bank account for a refund. Should I close it?
A

The company says an account number alone does not let anyone withdraw money immediately, and warns about contacts that pose as a refund process to obtain your PIN or online banking ID and password. We found no official guidance saying the account must be replaced only because the number leaked. If you see a transaction you do not recognize, contact your bank, and never give your PIN, login details or one-time password to anyone by phone or email.