Security Guides
skyticket (Adventure Inc.) Data Breach (About 14.64 Million Records): Hashed Passwords and Refund Bank Details Exposed — What Users Should Do Today
Adventure Inc., which runs the travel booking site skyticket, disclosed three unauthorized-access incidents. The largest exposed about 14.64 million records (4.13 million with hashed passwords); others involved refund bank details and bus bookings. What to do today.
For: anyone who has registered or booked on skyticket (a Japanese site for comparing and booking flights, hotels, buses and more), anyone who gave a bank account for a refund, anyone who booked a bus through skyticket between August and October 2026, and anyone who runs a booking site. This article is based on Adventure Inc.'s official notices and does not cover attack techniques.
Developing: this article will be updated as the organisation publishes more
As of October 10, 2026Not yet known
- Remaining record count for the second incident (still being counted)
- Whether passport numbers were exposed in the second incident
- Actual number of people across all three incidents (without duplicates)
- Details of how the administrative function was misused
- When payment with saved cards will resume
The company began emailing affected people on October 8 and published the details and record counts of the three incidents on October 9. It says it will keep investigating and announce any new facts promptly. On October 10 it said a mail server outage caused by the surge in inquiries had been fixed.
What skyticket users should do today
Change your skyticket password from the official site or app
In the first incident, about 4.13 million member login passwords leaked in hashed form. Hashing converts a password into a form that is hard to turn back, but the company itself warns that passwords may be worked out through analysis and used for unauthorized logins (how hashing works: What is password hashing?).
The company asks members to change their password. Do it by logging in to the official skyticket site or app, not through a link in an email. The company says its emails do not contain any link asking you to enter a password.
Change the same password on every other service
The company asks people who use the same password elsewhere to change it there too. A recovered password can be tried together with your email address on other sites.
Start with the accounts that would hurt most if taken over: email, online banking and shopping sites. If you are not sure where you reused it, see how to check whether your password leaked and how to choose a password manager.
As of October 10, skyticket's notices say nothing about two-step verification. On the other services you change, turn it on if it is offered (see choosing multi-factor authentication).
Check your booking history and card statement
The company asks users to check the booking history in their account and their credit card statements. Card numbers did not leak, but if someone logs in to your account, a saved card could be used to book. To prevent this, the company suspended payment with saved cards and card saving at around 6 p.m. on October 7.
Report unknown bookings to the company's contact and unknown charges to your card issuer. The company says it confirmed one unauthorized login to a member account on September 9.
Ignore messages about refunds, compensation or booking changes
The company warns that emails, text messages, calls and letters pretending to be the company, banks, airlines or bus operators may arrive. With names, dates of birth, phone numbers and addresses exposed, such messages can look convincing.
The company says it will never ask for payment in connection with this incident. Treat any message asking you to transfer money, pay a fee or install an app in the name of a refund or compensation as fake. Do not use the links or phone numbers in it; check through the official site you open yourself (see What is phishing?).
The emails the company has been sending since October 8 come from info@skyticket.com, in four subject variants beginning "【重要】不正アクセスによるお客様情報" with an English line such as "[Important] Apology for Information Leak Due to Unauthorized Access". The company says mail from any other address, or mail asking you to enter a password, may be a fake.
If you gave a refund bank account, never share your PIN or one-time codes
In the second incident, refund bank details (bank name, branch, account type, account number and account holder name) leaked or may have leaked. The company says this information alone does not let anyone withdraw money immediately.
The danger is a contact posing as a refund process to obtain your PIN or online banking ID and password. The Japanese Bankers Association says it never asks customers for PINs or passwords, and Japan's National Police Agency says police officers never ask for PINs by phone. The same goes for one-time passwords: do not give them out by phone or text message.
Check your passbook or banking app for transactions you do not recognize, and contact your bank if you find any. We found no official guidance saying the account must be replaced only because the number leaked. If you are worried, call your bank using the number on your card or its official site.
If you booked a bus, check the booking in your official account
In the third incident, the bus booking completion page could be displayed without logging in between August 3 and October 1, 2026. Trip date and time, boarding and drop-off points, operator, service name and the operator's booking number were among the items viewed.
The company warns that someone with this information may pose as the company or the bus operator and ask you to change or cancel the booking or pay an extra fee. You can check or cancel bookings 24 hours a day under "予約確認" (booking confirmation) in your account. If a booking was changed or cancelled without your knowledge, contact the company.
Use the contact listed in the official notice
The contact in the company's notice is the "skyticket inquiry desk for the personal data leak" (email: info@skyticket.com). The company's October 8 notice on its corporate site gives hours of 10 a.m. to 6 p.m. daily. As of October 10, the company says inquiries are very high, phones are hard to reach and email replies are delayed. Do what you can yourself, such as changing your password, while you wait.
What happened (from Adventure Inc.'s notices)
The following is based on the October 8, 9 and 10 notices that Adventure Inc. posted on the skyticket site and its corporate website. The October 9 notice is identical on both sites.
August 3 – October 1, 2026
The bus booking completion page could be displayed without logging in (third incident). Found and fixed on October 1.September 9
One unauthorized login to a member account confirmed.September 20
Unauthorized access to the business management system (second incident). Found on September 28.October 2–4
Unauthorized access to servers and cloud data, starting from misuse of an administrative function (first incident). Found on October 5.October 7, around 6 p.m.
Payment with saved cards and card saving suspended.October 8, from around 7 p.m.
Emails to affected people begin. The same day, a notice confirms these emails are genuine.October 9
Details, record counts and exposed items of the three incidents published. The company says it has reported to the Personal Information Protection Commission.October 10
The company says a mail server outage caused by the surge in inquiries has been fixed.
- First: access to company servers
- October 2–4, 2026. Some skyticket administrative functions were misused, and from there other servers and data stored in the cloud were accessed. About 14.64 million records
- Exposed in the first incident
- Name (including passport spelling), date of birth, email address, phone number, postal code and address, remitter name for bank transfers, hashed member password (about 4.13 million records). Passport numbers confirmed not exposed
- Second: business management system
- September 20, 2026. A vulnerability in the business management system was exploited. 17,780 records (including duplicates; more still being counted)
- Exposed or possibly exposed in the second
- Name, phone number, refund bank details (bank, branch, account type, account number, account holder name) and more. For some people also email address and date of birth (68 records) and address (18 records)
- Third: bus booking details viewed
- August 3 – October 1, 2026. The booking completion page could be shown without logging in and was viewed by a third party in an automated way. About 12,000 bookings (more people when companions are counted)
- Viewed or possibly viewed in the third
- Booker's name (katakana), age, gender, date of birth (if registered), email, phone, member ID, device type used to book, payment method and amount, booking date, trip details (including the operator's booking number), companions' names, ages and genders
- Not exposed
- Credit card data (held by a payment service provider, not the company) and passport images were not exposed in any incident
- Response
- Access routes cut off and vulnerabilities addressed; saved-card payment suspended; affected people emailed in turn; reported to the Personal Information Protection Commission
What is known and what is not
Status as of October 10, 2026. When new notices come out, we will update the status column.
| Item | What the notice says | Status |
|---|---|---|
| First incident: count and items | About 14.64M records; name, date of birth, email, phone, address, remitter name and more | Leak confirmed (company) |
| Hashed passwords | About 4.13M of the first incident's records | Leak confirmed (company) |
| Second incident: bank details etc. | 17,780 records (including duplicates) | Leaked or possibly leaked (company) |
| Second incident: remaining count | "Some records are still being counted" | Under investigation |
| Third incident: bus bookings | About 12,000 bookings; more people with companions | Viewed or possibly viewed (company) |
| Credit card data | Not stored by the company; not exposed | Not leaked (company) |
| Passport images | Not stored by the company; not exposed | Not leaked (company) |
| Passport numbers (first incident) | Confirmed not exposed | Not leaked (company) |
| Passport numbers (second incident) | No exposure confirmed yet; still checking | Under investigation |
| People across all three | Only per-incident counts; no de-duplicated total | Not disclosed |
| Cause | Given per incident (misused admin function / system vulnerability / page visible without login) | Disclosed (no details) |
| Secondary harm | None confirmed apart from one unauthorized login (September 9) | One case confirmed |
| Saved-card payment | Suspended since around 6 p.m. on October 7 | Resumption date not set |
How to read this: the three counts cannot be added up
About 14.64 million, 17,780 and about 12,000 are counts for three different incidents. The second count "includes duplicates," and one person may appear in more than one incident. The company has not published a de-duplicated number of people, so this site does not give a total either.
What the exposed combinations can be used for
In general, the following combinations can enable the following misuse. This does not mean it has happened in this case.
Email address + hashed password
↓→
Recovered passwords tried on skyticket and other sites
→ Change the password and stop reusing it
Name + phone + refund bank details
↓→
"Refund" calls or texts that quote your real account number
→ Never give a PIN, login details or one-time code
Contact details + trip + operator booking number
↓→
"Change" or "extra fee" messages quoting your real booking
→ Check the booking in your official account
What the exposed data can enable
- Convincing emails, texts and calls that get your name or booking right
- Demands for transfers or fees in the name of a "refund" or "compensation"
- Logins to other services with a recovered, reused password
What the exposed data alone cannot do
- Withdraw money with only an account number and holder name
- Shop with a leaked card number (card data was not exposed)
- Pass identity checks with a passport image (images were not exposed)
Whether such misuse works usually depends on whether the recipient gives out a PIN or code or opens a link. A message being accurate does not prove it is genuine. Past cases of the same type include Lashinbang, where refund-style bank details leaked, and TEMAIRAZU, where fake messages quoting real bookings were sent.
For booking-site operators: what the three disclosed routes let you check
The company gave a cause for each incident but no details, such as how the administrative function was misused or which vulnerability was involved. This section sticks to what operators can check on their own sites based on what was disclosed. It is not an assessment of the company's response.
Never show a booking completion page without a login or an unguessable key
The company says the third incident's completion page could be shown without logging in and was viewed by a third party in an automated way during that period (August 3 to October 1). Completion pages and the pages linked from confirmation emails gather names, contact details and booking numbers in one place.
Check whether the page verifies who is looking. Require a login, or, if it must work without one, put a long unguessable string in the URL and give it an expiry. In general, if changing a number in the URL shows someone else's booking, that is a classic flaw called IDOR (background: authentication vs authorization).
Limit and alert on bulk requests to the same page
"Viewed in an automated way" means far more requests than a person would make. For a page like a booking completion page, which one person rarely needs to open repeatedly, cap the number of views per source and alert someone when the cap is hit.
You can measure in the application or in front of it, at the web server or CDN (content delivery network). How to start is covered in rate limiting and abuse control.
Be ready to switch off saved cards when passwords leak
After password hashes leaked, the company suspended payment with saved cards. If a hijacked account can pay with a saved card, fraudulent purchases happen even when no card number has leaked.
Check in advance whether your site can switch off saved-card payment on its own, or require the card issuer's authentication (3-D Secure) on each payment. If there is no switch, you will be building one on the day of the incident.
Decide how long to keep refund bank details
The second incident involved refund bank details held in a business management system. A refund is often a one-off process, so decide how long to keep bank details once the refund is complete, and delete them automatically when that time is up. Data you no longer hold cannot leak.
This site's view: check each kind of entry point separately
In this case, three incidents by different routes came to light within eight days, from September 28 to October 5. Fixing one problem does not reveal the others unless the admin functions, internal business systems and user-facing pages are each checked separately. Operators should list their externally reachable entry points in three groups: admin screens, internal systems, and pages visible without logging in.
Sources (public record)
The facts in this article come from the public sources below. We have not speculated about undisclosed intrusion routes or methods.
- Adventure Inc., "Apology and notice regarding the leak of customer information due to unauthorized access" (October 9, 2026, skyticket, Japanese) — skyticket.jp
- Adventure Inc., same notice on the corporate website (October 9, 2026, Japanese) — jp.adventurekk.com
- Adventure Inc., "About the 'notice of personal information leak' email sent by skyticket" (October 9, 2026, skyticket, Japanese) — skyticket.jp
- Adventure Inc., "About the 'notice of personal information leak' email sent by the company" (October 8, 2026, company website, Japanese) — jp.adventurekk.com
- Adventure Inc., "Notice of recovery from the mail server outage" (October 10, 2026, Japanese) — skyticket.jp
- Japanese Bankers Association, warning about fake sites and callers (Japanese) — zenginkyo.or.jp
- National Police Agency, warning about unauthorized withdrawals from bank accounts (Japanese) — npa.go.jp
Update history
2026-10-11: Corrected a source date (the notice about the emails was posted on October 8 on the company website and on October 9 on the skyticket site).
2026-10-10: First version, based on the company's notices of October 8 (emails to affected people), October 9 (details and counts of the three incidents) and October 10 (mail server recovery). We will update when the remaining count for the second incident, the passport-number check and other open items are published.
Read next
- Reduce password reuse: How to check whether your password leaked / Choosing a password manager
- A case with leaked bank details: Lashinbang data breach
- Fake messages using travel bookings: TEMAIRAZU breach / Spotting Booking.com scam messages
- Other 2026 incidents: Data breaches and cyberattacks of 2026
FAQ
QWhat leaked from skyticket?
According to Adventure Inc.'s notice of October 9, 2026, there were three separate incidents. The first (about 14.64 million records) exposed names (including passport spelling), dates of birth, email addresses, phone numbers, postal codes and addresses, the remitter name used for bank transfers, and hashed member passwords (about 4.13 million records). The second (17,780 records, including duplicates) exposed or may have exposed names, phone numbers and refund bank account details (bank name, branch, account type, account number and account holder name), among other items. The third (about 12,000 bookings) means bus booking details were or may have been viewed: the booker's name in katakana, contact details, member ID, trip details, and companions' names, ages and genders.
QAm I affected?
The first incident covers people who registered with or entered details on skyticket, about 14.64 million records, so the range is very wide. The company says it is emailing affected people in turn, and that its October 9 notice serves as notice for anyone the email does not reach. If you have ever registered or booked on skyticket, assume you are affected and change your password even if no email arrived. The second incident mainly concerns people who gave a bank account for a refund, and the third concerns bus bookings whose completion page was shown between August 3 and October 1, 2026.
QWere card numbers or passport numbers exposed?
The company says it does not store card numbers or passport images, and that neither was exposed in any of the three incidents. For passport numbers, the company confirmed they were not exposed in the first incident. For the second, as of October 10 no exposure had been confirmed, but the company says it is still checking. Separately, to stop saved cards being used through hijacked accounts, the company suspended payment with saved cards and card saving at around 6 p.m. on October 7.
QWhat caused it?
The company gives a different cause for each incident: some administrative functions of skyticket were misused, and from there other servers and data in the cloud were accessed; a vulnerability in a business management system was exploited; and the bus booking completion page could be shown without logging in and was viewed by a third party in an automated way (fixed on October 1). How the administrative functions were misused and which vulnerability was involved have not been disclosed.
QWhat if someone contacts me claiming to be skyticket or my bank?
The company warns that fraudulent emails, text messages, calls and letters pretending to be the company, banks, airlines or bus operators may arrive. It says it will never ask for passwords, card numbers or bank PINs, will not ask for any payment in connection with this incident, and that its emails contain no link asking you to enter a password. Do not use the links or phone numbers in a message; check through the official site or app you open yourself, or the contact in the official notice (info@skyticket.com).
QI gave a bank account for a refund. Should I close it?
The company says an account number alone does not let anyone withdraw money immediately, and warns about contacts that pose as a refund process to obtain your PIN or online banking ID and password. We found no official guidance saying the account must be replaced only because the number leaked. If you see a transaction you do not recognize, contact your bank, and never give your PIN, login details or one-time password to anyone by phone or email.