1 article with this tag
On October 8, 2026, Lawson, Inc. announced that unauthorized third-party access to its account service Lawson ID, and to Lawson App Reservation (a service for reserving and paying for seasonal event products in the app), had leaked personal data. An investigation on October 7 found that Lawson ID was accessed without authorization from September 12 to 14 and App Reservation on September 17. The company confirmed leaks of 2,155,345 Lawson ID records (email address and name, plus gender, phone number, address and newsletter preference for people who had entered them) and 26 App Reservation records (name, phone number and part of the credit card number). The company says a system related to the Lawson app was misused, and that a mechanism meant to show information only to the user themselves in the app was accessed without authorization by a third party. Passwords are not among the listed items. As of October 8 no misuse or secondary harm had been confirmed, and as of October 10 there was no follow-up notice. This site's take: Lawson ID holders should not open links in emails or texts claiming to be Lawson or offering points or coupons, and should check through the official app they open themselves.