Skip to content
>_ITDITDWeb Security Platform

Security Guides

Yellow Hat data breach (up to about 1.8 million people): names, phone numbers and emails may have leaked — what members should do

Yellow Hat's online work reservation system was attacked; names, phone numbers, emails and member numbers of up to 1,801,499 people may have leaked.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 9 min read

For: anyone who has booked a job at a Yellow Hat store through its website, anyone who used the 2rinkan app, and anyone who runs a booking system. This article is based on the company's official notice and does not cover attack or scam techniques.

What members should do today

1

Check whether you are affected

People whose details were registered in the Yellow Hat online work reservation system are in scope. The company says it will contact them individually by email, SMS, phone or letter.

According to the company, stores of other group brands use a separate management system, so people who only used those stores are not affected.

2

Do not reply to booking, inspection or apology messages through the message itself

With a name, phone number and email address, anyone can send you a text or email that uses your name, or call you. If you get a message about "confirming your booking", "an inspection reminder" or "an apology and compensation", do not use the links or phone numbers in it.

To check, contact the official website you open yourself, or the store you used. For fake links sent by text message, see What is phishing?

3

Do not give out your member number or card number

Member numbers are among the data that may have leaked. A message that shows your correct member number is not proof that it is genuine.

If you are asked for a card number, PIN or one-time code "to confirm your identity" or "to process a refund", stop the conversation there.

4

If you used the 2rinkan app, stop reusing that password

Yellow Hat says passwords were not stored in its work reservation system. In the separate April 2026 breach at the group company 2rinkan Yellow Hat, however, app passwords were leaked.

If you used your 2rinkan app password on other services, change it there. A password manager is the realistic way to keep a different password for each service.

5

If unsure, use the contact line listed on the official site

The company has set up a dedicated inquiry line. Use the number in the notice on the company's official website, not one written in a message you received (it is also listed under "What happened" below).

If you already opened a link and entered details, or paid money, contact your card issuer or bank right away. In Japan you can also call the police consultation line (#9110) or the consumer hotline (188).

What happened (from Yellow Hat's notice)

On August 28, 2026, Yellow Hat Ltd. posted a notice of apology on its official website about a possible personal data leak due to unauthorized access. Everything below is as stated in the company's notice.

  1. Morning of Aug 18, 2026

    An attack by a malicious program on the Yellow Hat online work reservation system was detected. The company cut off outside connections and shut the system down.
  2. Investigation

    The company found that part of its member data may have leaked externally, and put security measures in place.
  3. Aug 28

    The company published the notice. It says it reported to the Personal Information Protection Commission and consulted the police.
  4. When ready

    The company says it will contact affected people individually by email, SMS, phone or letter.
1,801,499
People whose data may have leaked (maximum)
4 items
Name, phone number, email address, member number
Not held
Card data, passwords, vehicle information (not stored in this system)
Not affected
Customers of other group brands' stores (per the company)
What may have leaked (from the company's notice)
System
Yellow Hat online work reservation system (used to book jobs at stores online)
Count
Up to 1,801,499 people
Items
Name, phone number, email address, member number
Not included
Credit card data, passwords, vehicle information (not held in this system)
Cause
An attack by a malicious program (route and method not published)
Group companies
Use a separate management system; the company says customers of other brands' stores are not affected
Reported to
Personal Information Protection Commission (Japan's data protection authority); police consulted
Contact
Dedicated line 0120-405-092 (toll-free in Japan; daily 10:00–19:00 until Oct 12, weekdays 10:00–19:00 from Oct 13)

The group's 2rinkan business had a separate breach in April 2026

2rinkan Yellow Hat, the group company that runs the "2rinkan" motorcycle-goods stores, announced unauthorized access to member data for its 2rinkan app on April 23, 2026. According to its final report of June 19, data on 3,179,454 people leaked.

The items were name, address, phone number, date of birth, gender, email address, member number, app user ID and password, points balance and vehicle information; credit card data was managed in a separate system and was not included. Yellow Hat's August notice does not discuss any link to that incident. If you used both stores, prepare on the assumption that both sets of data are out.

What is still unknown

As of October 3, the attack route, the number of records actually taken, and whether the data has been misused have not been published. This article will be updated when more is released.

Why a message with your name and member number can still be fake

It is tempting to think: "They know my name and member number, so it must be Yellow Hat." That assumption does not hold here, because name, phone number, email address and member number may all have leaked together.

Not proof that a message is genuine

  • It shows your name and member number
  • It reached your own phone number or email address
  • It carries the store's name or logo, or mentions your car model

Things you can check yourself

  • Whether the official website, opened by you, shows the same notice
  • Whether the store you used, called on the number from the official site, says the same thing
  • Whether the message asks for a card number, PIN or payment

The company itself says it will send individual notices by email, SMS, phone or letter, so an apology message may well be real. Even a real one will not need you to give a card number or password. Keeping that in mind makes fake messages easier to spot.

For those who run booking systems

The cause the company gave is "an attack by a malicious program", with no further detail. This section sticks to points worth checking for any booking system that holds customer contact details.

1

Decide how long to keep contact details after a booking is done

Booking systems tend to keep names and contact details long after the job is finished. Once the period needed for confirmations and same-day contact has passed, delete the contact details or move them to the member database, and automate it. Fewer records in the booking system means fewer people affected if it leaks.

2

Limit outbound traffic from the booking server to known destinations

The company cut off outside connections after detecting the attack. If outbound traffic is allowed only to set destinations (payment, email delivery and so on) from the start, a malicious program placed on the server has a harder time sending data out. In the cloud, this is a security group or firewall egress rule.

3

Get alerted when programs on the server appear or change

On the directories where your web application's code lives, add file change logging with alerts (file integrity monitoring). A good first rule: a daily alert for any file in the served directories that changed outside a deployment.

4

Publish how you will send apology notices before you send them

After a breach, fake apology messages tend to follow. Before sending individual notices, publish the sender address, SMS sender name and calling number on your official site so recipients can check for themselves. To reduce fake emails using your own domain, see Email spoofing and SPF, DKIM, DMARC.

Sources (public record)

The facts in this article come from the public sources below. Undisclosed details of the intrusion are not speculated on.

  • Yellow Hat Ltd., notice of apology on a possible personal data leak due to unauthorized access (August 28, 2026, Japanese) — yellowhat.jp
  • 2rinkan Yellow Hat, notice on unauthorized access to the 2rinkan app (April 23, 2026; second report May 1; final report June 19; Japanese) — 2rinkan.jp
  • ITmedia NEWS (August 28, 2026, Japanese) — itmedia.co.jp

Update history

2026-10-03: First version, based on Yellow Hat's notice of August 28 and 2rinkan Yellow Hat's final report of June 19. Will be updated when more is published.

FAQ

QWhat was leaked in the Yellow Hat breach?
A

According to Yellow Hat Ltd.'s notice of August 28, 2026, the data that may have leaked is the name, phone number, email address and member number registered in the Yellow Hat online work reservation system, for up to 1,801,499 people. Credit card data, passwords and vehicle information are not held in this system, so the company says they were not leaked.

QAm I affected?
A

People whose details were registered in Yellow Hat's online work reservation system are in scope. The company says it will contact affected people individually by email, SMS, phone or letter once it is ready. It also says other group brands use separate management systems, so customers of those brands' stores are not affected.

QShould I change my password?
A

The company says passwords were not held in this system and were not leaked. However, in the separate April 2026 breach at the group company 2rinkan Yellow Hat, passwords for the 2rinkan app were leaked. If you used your 2rinkan app password on other services, change it there.

QWas my vehicle information leaked?
A

According to the company, vehicle information is not held in this system and was not leaked. Even so, do not treat a message as genuine just because it mentions your car model.

QIs this related to the 2rinkan breach?
A

They are separate incidents. On April 23, 2026, 2rinkan Yellow Hat announced unauthorized access to member data for its 2rinkan app, and its final report of June 19 said data on 3,179,454 people had leaked. Yellow Hat's August 28 notice says it uses a management system independent of other group companies and does not discuss any link between the two.

QWhat caused the breach?
A

The company's notice describes it as an attack by a malicious program. Details of how the attackers got in have not been published. The company says it cut off outside connections, shut the system down, put security measures in place, reported to Japan's Personal Information Protection Commission and consulted the police.