1 article with this tag
According to RIZAP Co., Ltd., a third party planted a malicious script on its APORITO Online Store, and the names, addresses, phone numbers and email addresses — plus card numbers, expiry dates and security codes — of people who placed an order or entered information between May 1 and August 5, 2026 may have been sent outside. The company found a suspicious outbound-transmission program on August 5 and closed the store that day; as of August 18 the store remained closed and the investigation continued. It says no misuse or actual leak has been confirmed. This site's take: with the security code in scope, watching statements is not enough; ask your card issuer to replace the number. The lesson for e-commerce operators is that not storing card data ('non-retention') does not protect the input page itself. On top of the five vulnerability measures required by Japan's Credit Card Security Guidelines, have a way to detect changes to your payment page.