Security Guides
Yellow Hat data breach (up to about 1.8 million people): names, phone numbers and emails may have leaked — what members should do
Yellow Hat's online work reservation system was attacked; names, phone numbers, emails and member numbers of up to 1,801,499 people may have leaked.
For: anyone who has booked a job at a Yellow Hat store through its website, anyone who used the 2rinkan app, and anyone who runs a booking system. This article is based on the company's official notice and does not cover attack or scam techniques.
What members should do today
Check whether you are affected
People whose details were registered in the Yellow Hat online work reservation system are in scope. The company says it will contact them individually by email, SMS, phone or letter.
According to the company, stores of other group brands use a separate management system, so people who only used those stores are not affected.
Do not reply to booking, inspection or apology messages through the message itself
With a name, phone number and email address, anyone can send you a text or email that uses your name, or call you. If you get a message about "confirming your booking", "an inspection reminder" or "an apology and compensation", do not use the links or phone numbers in it.
To check, contact the official website you open yourself, or the store you used. For fake links sent by text message, see What is phishing?
Do not give out your member number or card number
Member numbers are among the data that may have leaked. A message that shows your correct member number is not proof that it is genuine.
If you are asked for a card number, PIN or one-time code "to confirm your identity" or "to process a refund", stop the conversation there.
If you used the 2rinkan app, stop reusing that password
Yellow Hat says passwords were not stored in its work reservation system. In the separate April 2026 breach at the group company 2rinkan Yellow Hat, however, app passwords were leaked.
If you used your 2rinkan app password on other services, change it there. A password manager is the realistic way to keep a different password for each service.
If unsure, use the contact line listed on the official site
The company has set up a dedicated inquiry line. Use the number in the notice on the company's official website, not one written in a message you received (it is also listed under "What happened" below).
If you already opened a link and entered details, or paid money, contact your card issuer or bank right away. In Japan you can also call the police consultation line (#9110) or the consumer hotline (188).
What happened (from Yellow Hat's notice)
On August 28, 2026, Yellow Hat Ltd. posted a notice of apology on its official website about a possible personal data leak due to unauthorized access. Everything below is as stated in the company's notice.
Morning of Aug 18, 2026
An attack by a malicious program on the Yellow Hat online work reservation system was detected. The company cut off outside connections and shut the system down.Investigation
The company found that part of its member data may have leaked externally, and put security measures in place.Aug 28
The company published the notice. It says it reported to the Personal Information Protection Commission and consulted the police.When ready
The company says it will contact affected people individually by email, SMS, phone or letter.
- System
- Yellow Hat online work reservation system (used to book jobs at stores online)
- Count
- Up to 1,801,499 people
- Items
- Name, phone number, email address, member number
- Not included
- Credit card data, passwords, vehicle information (not held in this system)
- Cause
- An attack by a malicious program (route and method not published)
- Group companies
- Use a separate management system; the company says customers of other brands' stores are not affected
- Reported to
- Personal Information Protection Commission (Japan's data protection authority); police consulted
- Contact
- Dedicated line 0120-405-092 (toll-free in Japan; daily 10:00–19:00 until Oct 12, weekdays 10:00–19:00 from Oct 13)
The group's 2rinkan business had a separate breach in April 2026
2rinkan Yellow Hat, the group company that runs the "2rinkan" motorcycle-goods stores, announced unauthorized access to member data for its 2rinkan app on April 23, 2026. According to its final report of June 19, data on 3,179,454 people leaked.
The items were name, address, phone number, date of birth, gender, email address, member number, app user ID and password, points balance and vehicle information; credit card data was managed in a separate system and was not included. Yellow Hat's August notice does not discuss any link to that incident. If you used both stores, prepare on the assumption that both sets of data are out.
What is still unknown
As of October 3, the attack route, the number of records actually taken, and whether the data has been misused have not been published. This article will be updated when more is released.
Why a message with your name and member number can still be fake
It is tempting to think: "They know my name and member number, so it must be Yellow Hat." That assumption does not hold here, because name, phone number, email address and member number may all have leaked together.
Not proof that a message is genuine
- It shows your name and member number
- It reached your own phone number or email address
- It carries the store's name or logo, or mentions your car model
Things you can check yourself
- Whether the official website, opened by you, shows the same notice
- Whether the store you used, called on the number from the official site, says the same thing
- Whether the message asks for a card number, PIN or payment
The company itself says it will send individual notices by email, SMS, phone or letter, so an apology message may well be real. Even a real one will not need you to give a card number or password. Keeping that in mind makes fake messages easier to spot.
For those who run booking systems
The cause the company gave is "an attack by a malicious program", with no further detail. This section sticks to points worth checking for any booking system that holds customer contact details.
Decide how long to keep contact details after a booking is done
Booking systems tend to keep names and contact details long after the job is finished. Once the period needed for confirmations and same-day contact has passed, delete the contact details or move them to the member database, and automate it. Fewer records in the booking system means fewer people affected if it leaks.
Limit outbound traffic from the booking server to known destinations
The company cut off outside connections after detecting the attack. If outbound traffic is allowed only to set destinations (payment, email delivery and so on) from the start, a malicious program placed on the server has a harder time sending data out. In the cloud, this is a security group or firewall egress rule.
Get alerted when programs on the server appear or change
On the directories where your web application's code lives, add file change logging with alerts (file integrity monitoring). A good first rule: a daily alert for any file in the served directories that changed outside a deployment.
Publish how you will send apology notices before you send them
After a breach, fake apology messages tend to follow. Before sending individual notices, publish the sender address, SMS sender name and calling number on your official site so recipients can check for themselves. To reduce fake emails using your own domain, see Email spoofing and SPF, DKIM, DMARC.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed details of the intrusion are not speculated on.
- Yellow Hat Ltd., notice of apology on a possible personal data leak due to unauthorized access (August 28, 2026, Japanese) — yellowhat.jp
- 2rinkan Yellow Hat, notice on unauthorized access to the 2rinkan app (April 23, 2026; second report May 1; final report June 19; Japanese) — 2rinkan.jp
- ITmedia NEWS (August 28, 2026, Japanese) — itmedia.co.jp
Update history
2026-10-03: First version, based on Yellow Hat's notice of August 28 and 2rinkan Yellow Hat's final report of June 19. Will be updated when more is published.
Read next
- Follow-on scams: What is phishing? / Yamato Transport and Sagawa Express (fake delivery texts)
- Passwords: Choosing a password manager
- Other car-related services: The Times Car breach / Cariteco (Meitetsu Kyosho)
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat was leaked in the Yellow Hat breach?
According to Yellow Hat Ltd.'s notice of August 28, 2026, the data that may have leaked is the name, phone number, email address and member number registered in the Yellow Hat online work reservation system, for up to 1,801,499 people. Credit card data, passwords and vehicle information are not held in this system, so the company says they were not leaked.
QAm I affected?
People whose details were registered in Yellow Hat's online work reservation system are in scope. The company says it will contact affected people individually by email, SMS, phone or letter once it is ready. It also says other group brands use separate management systems, so customers of those brands' stores are not affected.
QShould I change my password?
The company says passwords were not held in this system and were not leaked. However, in the separate April 2026 breach at the group company 2rinkan Yellow Hat, passwords for the 2rinkan app were leaked. If you used your 2rinkan app password on other services, change it there.
QWas my vehicle information leaked?
According to the company, vehicle information is not held in this system and was not leaked. Even so, do not treat a message as genuine just because it mentions your car model.
QIs this related to the 2rinkan breach?
They are separate incidents. On April 23, 2026, 2rinkan Yellow Hat announced unauthorized access to member data for its 2rinkan app, and its final report of June 19 said data on 3,179,454 people had leaked. Yellow Hat's August 28 notice says it uses a management system independent of other group companies and does not discuss any link between the two.
QWhat caused the breach?
The company's notice describes it as an attack by a malicious program. Details of how the attackers got in have not been published. The company says it cut off outside connections, shut the system down, put security measures in place, reported to Japan's Personal Information Protection Commission and consulted the police.