Security Guides
TEMAIRAZU breach (count under investigation): hotel booking data in Japan may have leaked — how to handle messages posing as your hotel
A booking system used by many hotels in Japan was breached; bookings made via travel sites may be affected. How to handle fake hotel messages, and what hotels should check.
For: anyone who has booked a hotel or ryokan in Japan (including through a travel booking site), and anyone who runs an accommodation business. This article is based on Temairazu, Inc.'s official notice and on notices from hotels that use its system, and does not cover attack or scam techniques.
What guests should do today
Know whether you could be affected — booking-site bookings are included
According to notices from hotels using the system, the bookings in scope are those made by September 21, 2026 for stays on or after September 21. That includes not only people who booked directly with the hotel but potentially also those who booked through a travel booking site (the next section explains why).
You usually cannot tell from outside whether your hotel uses TEMAIRAZU. Some hotels have posted notices on their websites, but the absence of a notice does not mean you are safe. Handle every message claiming to be from a hotel with the steps below.
Do not open links in the message, and do not reply
The messages the company has seen appear to know booking details and ask recipients to confirm or finalize a booking, re-enter card details, or make an urgent payment, leading them to suspicious websites. They have arrived through messaging apps such as WhatsApp and WeChat, by email and by SMS.
The company gives four pieces of advice:
- Do not open any URLs or links
- Do not enter card details or personal information
- Do not reply
- Do not pay or transfer money as the message instructs
Check through the booking site's official app or the hotel's official number
To check the status of a booking, use an official channel you open yourself, not the links or phone numbers in the message.
- If you booked through a booking site: open the booking from the app on your home screen (or the official website you bookmarked yourself) and check the payment method and status
- If you booked directly: find the hotel's official website through a search and call the number listed there yourself
If you are asked for a payment that is not in your booking confirmation, that alone is reason enough to refuse. The same scam pattern is covered in detail in the Booking.com booking data breach.
If you entered details or paid, contact your card issuer immediately
The company says that if you entered card or other details on a suspicious website, you should contact your card issuer promptly. Ask for the card to be blocked and reissued, and check your statements for charges you do not recognize.
In Japan you can also call the police consultation line (#9110) or the consumer hotline (188). If you entered your booking-site password, change it and turn on two-step verification (see Choosing multi-factor authentication).
Tell the people traveling with you
Tell family members and anyone else staying at the same hotel, not only the person who made the booking. These messages have also arrived through WhatsApp and WeChat. Travelers tend to trust messages that arrive in the app they use every day, so make sure everyone knows to check the same way whichever app a message arrives in.
What a channel manager is, and why booking-site bookings are affected
Many hotels and ryokan in Japan list their rooms on several travel booking sites (OTAs, online travel agencies) as well as on their own website. When a room sells on one site, the hotel has to reduce availability on the others, or it will sell the same room twice.
The system that does this automatically is called a channel manager (in Japan, usually a "site controller"). TEMAIRAZU is one of them; the company describes it as a system for managing accommodation bookings in one place.
Booking site A
Guest books in the app
Booking site B
Guest books on the web
Hotel's own website
Direct booking
↓ bookings, availability and rates passed along together
Channel manager (TEMAIRAZU)
Booking data from many hotels gathered in one system → unauthorized access confirmed here
↓
Each hotel's management screen
Name, contact details, stay dates, booking number, etc.
So booking data can be taken from the system a hotel uses even when the booking site itself has no problem. Not hearing from your booking site is not proof that you are safe.
What happened (from Temairazu, Inc.'s notice)
Temairazu, Inc. published a notice of apology about suspicious messages and unauthorized access to its system on September 28, 2026 in Japanese and on September 29 in English. Two points below — the September 26 date and that the unauthorized access took place on September 21 — come from notices posted by hotels using the system.
Sep 21, 2026
According to hotels' notices, the day the unauthorized access took place.From late night, Sep 21
Several properties report to the company that guests are receiving suspicious messages. While investigating, the company confirms unauthorized access to its system.Sep 26
According to hotels' notices, the cause was identified and the fix completed.Sep 28
The company publishes its notice, saying it is reporting to the Personal Information Protection Commission and has reported to and consulted the police.Sep 29
English version of the notice published.
- System
- TEMAIRAZU Series, a system for managing accommodation bookings in one place
- What happened
- Unauthorized access to the company's system. The company cannot rule out that some guest information was viewed or obtained by a third party
- Items
- Not listed in the company's notice. Some hotels' notices list name, phone number, email address, booking number, check-in and check-out dates and property name; some also list address, age and company name (varies by property)
- Count
- Not announced (scope under investigation)
- Credit cards
- The company says it does not handle or hold card data
- Secondary harm
- Suspicious messages that appear to know booking details, via messaging apps such as WhatsApp and WeChat, email and SMS. The company believes they may stem from the unauthorized access and is investigating the link
- Cause
- The company says it identified and fixed the cause but will not disclose the method. According to hotels' notices, a security problem in part of an installed product (software run on the property's own computers) the company provided in the past
- Response
- Access blocked; access controls and monitoring strengthened. Temporarily suspended functions have been restored and the service is operating normally (company notice)
- Reported to
- Steps under Japan's personal data law, including a report to the Personal Information Protection Commission; police report and consultation; an outside information security firm asked to assist
- Contact
- The company's emergency help desk (listed in the official notice)
What is unusual here: fake messages arrived before the announcement
According to the company, properties began reporting suspicious messages from late at night on September 21, and the announcement came on September 28. So messages that arrived before the announcement need the same care.
If you remember entering card details in response to a message from a "hotel" in late September, contact your card issuer now.
What is still unknown
As of October 3, the company has not announced the number of people affected, the exact data items, the number of properties involved, or whether anyone has lost money to the fake messages. It also says it will not disclose details of the cause for security reasons. This article will be updated when more is published.
For those who run accommodation businesses
What the company asks of properties using its service
Change your TEMAIRAZU login password
As a precaution, the company asks properties to change their TEMAIRAZU login password. If the same password is used on other admin screens (booking-site extranets, email and so on), change those too.
Check the management screen for unrecognized logins or changes
The company asks properties to contact it promptly if they see logins they do not recognize or unintended changes to registered information in the management screen. Check your booking-site admin screens as well, for login history, permission settings and registered details such as the bank account for payouts (the same items the company asks booking sites and integration partners to check).
Give guests one consistent answer
The company asks properties to tell guests who get in touch not to open the URLs in suspicious messages and not to enter personal or card details.
So that the front desk and call center give the same answer, agree on one sentence, such as "We will never ask you by message to re-enter card details or make a payment", plus the correct contact point. Notifying guests in the affected period in advance, through the booking sites' messaging features, helps reduce harm.
A check specific to this case: are old products or connections still in place?
According to hotels' notices, the cause lay in part of an installed product the company provided in the past. Old products you think you no longer use, or the connection settings made for them, can remain in place without anyone noticing.
Things a property can check on its own side:
- List every system that handles booking or guest data, and for each write down the current version, who manages it, and whether any old versions or integrations are still left behind
- For old products no longer in use, confirm with the provider, then uninstall them and shut down the related accounts and connections
- Ask the provider whether any old-version connections or integrations remain on your account, and whether there is anything else you should check in light of this incident
If the management screen supports a check beyond the password (multi-factor authentication), turn it on. If staff share a single login, giving each person their own makes it possible to see in the login history who did what.
For another case where hotel guest data leaked, see the Quest Apartment Hotels breach in Australia; for how to spot scam messages from someone who knows your booking, see the Booking.com booking data breach.
Sources (public record)
The facts in this article come from the public sources below. The number affected and the intrusion method, which have not been published, are not speculated on.
- Temairazu, Inc., notice of apology regarding suspicious messages and unauthorized access to its system (September 28, 2026, Japanese) — temairazu.co.jp
- Temairazu, Inc., "Notice and Apology Regarding Suspicious Messages and Unauthorized Access to TEMAIRAZU" (September 29, 2026, English) — temairazu.co.jp
- Examples of notices from properties using the system (date of access, bookings in scope, cause; Japanese): Hotel Fukushima Green Palace — fukushimagp.com / MIMARU — mimaruhotels.com
- piyolog (September 30, 2026: a roundup of properties' notices, Japanese) — piyolog.hatenadiary.jp
Update history
2026-10-03: First version, based on Temairazu, Inc.'s notices of September 28 (Japanese) and September 29 (English) and on notices from properties using the system. Will be updated when the count or investigation results are published.
Read next
- The same scam pattern: The Booking.com booking data breach / What is phishing?
- Another accommodation case: Quest Apartment Hotels (Australia, card and passport numbers)
- Other Japanese cases from the same period: The Abahouse data breach / The Times Car breach
- Protecting your accounts: Choosing multi-factor authentication / Choosing a password manager
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat is TEMAIRAZU?
TEMAIRAZU is a booking management system for accommodation, provided by Temairazu, Inc. in Japan. Hotels and ryokan (traditional Japanese inns) use it to manage the rooms, rates and bookings they list on several booking sites and on their own website from one place. This kind of system is called a channel manager (in Japan, a site controller). Bookings made on travel booking sites also pass through it on their way to the hotel.
QWhat was leaked?
Temairazu, Inc.'s notice of September 28, 2026 says it cannot rule out that some guest information was viewed or obtained by a third party, but it does not list specific items. Notices from some hotels using the system list guest name, phone number, email address, booking number, check-in and check-out dates and property name; some also list address, age and company name. The company says it does not handle or hold credit card data.
QHow many people are affected?
As of October 3, 2026, no number has been announced. The company says it is investigating the scope.
QI booked through a travel booking site. Could I be affected?
Yes. If the hotel uses TEMAIRAZU, bookings received through booking sites are pulled into this system too. According to notices from hotels using it, the bookings in scope are those made by September 21, 2026 for stays on or after September 21. It is usually impossible to tell from outside whether your hotel uses TEMAIRAZU, so treat every message claiming to be from a hotel with the same care.
QA hotel asked me on WhatsApp to re-enter my card details. Is it genuine?
Do not respond. For messages asking you to confirm or finalize a booking, re-enter credit card details or make an urgent payment, the company advises: do not open any links, do not enter card or personal details, do not reply, and do not pay or transfer money. Check your booking through the official contact channels of the property or the booking site.
QWhat if I already entered card details on a fake site?
The company says that if you entered credit card or other details on a suspicious website, you should contact your card issuer promptly. Ask for the card to be blocked and reissued, and check your statements for charges you do not recognize. In Japan you can also call the police consultation line (#9110) or the consumer hotline (188).
QWhat caused the breach?
The company says it identified the cause and completed the fix, but it will not disclose the method for security reasons. According to notices from hotels using the system, the unauthorized access took place on September 21, 2026, and the cause was a security problem in part of the functions of an installed product the company provided in the past. The company has reported the incident to Japan's Personal Information Protection Commission and to the police.