Japan
28 articles with this tag
Seicomart app breach (about 572,000 members): names, addresses and birth dates viewed — what members should do
On September 29, 2026, Seicomart Co., Ltd., which runs the Seicomart convenience-store chain in Japan, announced that a third party had gained unauthorized access to the server holding member data by way of the server behind its Seicomart smartphone app. Its third notice on September 30 said it had confirmed that data on 572,022 people who had registered with the app (49% of app members) was viewed: surname and given name, gender, date of birth, address, phone number, email address, and the dates they joined and left the Club Card program. Password data and purchase history were not leaked, and the company does not hold credit card data. No misuse of the Peco Mama Money e-money service has been found. This site's take: what was exposed is a set of personal details that cannot be changed, and the most likely next step is convincing emails, texts and calls that pose as the company. Do not follow links or instructions in such messages; check through the official app, in store, or with the customer service line. Also stop using your date of birth as a PIN or as an answer to identity checks.
E-store ShopServe data breach (up to 8.85 million records): partial card numbers and shop passwords leaked — what buyers and shop owners should do
On August 1 and 2, 2026, E-store Co., Ltd. announced that a third party had run a malicious program on the servers of ShopServe, its service for building online shops, and sent buyer data out between May 21 and August 1, 2026. Up to 8,853,839 records (duplicates possible) leaked: buyers' names, addresses, phone numbers, email addresses and workplaces; encrypted member IDs and passwords; cardholder names, part of the card number (first 6 and last 4 digits) and expiry dates; and, for merchants, login IDs and passwords for the admin panel, mail system and FTP, plus payout bank account details. Security codes were not stored and were not affected, and no secondary damage had been reported as of August 2. This site's take: most buyers shopped on each store's own site without ever hearing the name ShopServe. Even if you cannot tell which shop it was, treat messages that quote your real order details or the last four digits of your card with suspicion, check your card statements, and change reused passwords. Merchants should change their admin, mail and FTP passwords and check their shop pages for changes they did not make.
Abahouse data breach (count under investigation): order details may have leaked — how to handle fake refund emails
On October 2, 2026, Abahouse International Co., Ltd. announced that unauthorized access to its internal systems may have leaked member IDs, names, addresses, phone numbers, email addresses, dates of birth, gender and order details (order date and time, product names, amounts and delivery addresses). Everyone whose member data the company holds may be affected, as well as former members whose order data remained. No count has been announced. Card numbers and security codes are handled by a payment processor, and no leak of them has been confirmed. The breach came to light when several customers reported suspicious refund emails that matched their real orders. This site's take: a message that gets your order right is not proof it is genuine. Do not follow links or move to LINE from 'refund' or 'out-of-stock' emails; check your order history in My Page instead.
EPARK Relax & Esthe "PeakManager" data breach (about 22.18M records): health notes leaked too — what salon customers should do
EPARK Relax & Esthe Co., Ltd. announced that the database of PeakManager, the booking and customer-management system it provides to salons, was accessed without authorization and customer data was transferred outside. Its first notice (July 31, 2026) gave about 33 million records; after removing duplicates, its second notice (September 24) gave about 22.18 million records, which it says cannot be converted into a number of people. The leaked items are name and its phonetic reading, date of birth, gender, address, phone number, email address and a notes field where salons recorded handover notes for treatments, partly including health conditions and other sensitive personal information. The first notice also said encrypted passwords may have leaked and asked customers to change them. This site's take: PeakManager is each salon's own customer ledger, so people who never used EPARK can still be affected if they gave a salon their name or contact details. Do not respond to messages claiming to be from a salon or the company, and change your My Page password and anywhere you reused it.
TEMAIRAZU breach (count under investigation): hotel booking data in Japan may have leaked — how to handle messages posing as your hotel
On September 28, 2026, Temairazu, Inc. announced unauthorized access to its TEMAIRAZU Series, a system hotels and ryokan use to manage bookings from many sources in one place. From late at night on September 21, guests of properties using the system began receiving suspicious messages via messaging apps such as WhatsApp, by email and by SMS. The messages appeared to know booking details and pushed recipients to fake websites to confirm a booking, re-enter card details or make an urgent payment. The company says it cannot rule out that some guest information was viewed or obtained by a third party; the scope is under investigation and no count has been announced. The company does not handle or hold credit card data. According to notices from hotels using the system, the cause was a security problem in part of an installed (on-premise) product the company provided in the past, and the fix was completed on September 26. This site's take: people who booked through a travel booking site may be affected too. If a message claiming to be your hotel asks you to re-enter card details or pay, do not do it, even if the details are right; check in the booking site's official app or by calling the number on the hotel's official website.
Yamato Transport and Sagawa Express breaches (count under investigation): addresses and purchases may have leaked — what parcel recipients should do
Yamato Transport found unauthorized access to its Kuroneko deferred-payment service on September 28, 2026, and Sagawa Express found unauthorized access to its parcel tracking service on September 30. On October 1-2, both said personal data may have leaked. These are separate incidents, and neither company mentions a connection. For Sagawa, the data covers names, addresses and phone numbers of senders and recipients of about 100 days of parcels; for Yamato, deferred-payment users' names and contact details plus billing amounts, outstanding balances and item details. Neither includes credit card data or passwords, and counts are under investigation. This site's take: with Sagawa, you can be affected just by having received a parcel, even if you never used the company yourself. Assume fake missed-delivery notices and payment demands may now carry your real name, address, and what you received or bought. Do not open links in such messages; check in the official app or in the order history of the shop you bought from.
Lashinbang data breach (count not disclosed): ID document numbers and bank details may have leaked — what sellers should do
On October 1, 2026, Lashinbang Co., Ltd. announced that unauthorized access to a service it operates, between September 14 and 16, 2026, may have leaked names, addresses, phone numbers, email addresses, dates of birth and occupations, along with the type and number of identity documents, the bank name, branch, account number and account holder entered when applying for a buyback (when customers sell items to the shop), images of buyback consent forms, and buyback and order details. No count has been announced. The company says no credit card information or passwords leaked and that it does not collect My Number (Japan's individual number). This site's take: under Japan's Secondhand Articles Dealer Act, most buyback sellers had to show ID, so they had little choice about handing this data over. An account number alone cannot be used to withdraw money, but do not respond to calls or emails that use your account or ID details to look genuine, and consider registering a self-declaration with Japan's credit bureaus.
Yellow Hat data breach (up to about 1.8 million people): names, phone numbers and emails may have leaked — what members should do
On August 28, 2026, Yellow Hat Ltd., a Japanese car-parts and car-service retailer, announced that its online work reservation system, used to book jobs at its stores, had been attacked by a malicious program, and that the names, phone numbers, email addresses and member numbers of up to 1,801,499 people may have leaked. The company detected the attack on the morning of August 18, cut the system off from outside connections and shut it down. Credit card data, passwords and vehicle information are not held in this system, so the company says they were not leaked. Separately, in April 2026, the group company 2rinkan Yellow Hat had a different breach that exposed data on about 3.18 million people, including app passwords. This site's take: what may have leaked is exactly the data needed to contact you directly. Do not reply to calls, texts or emails about bookings, inspections or apologies; check through the official website or the store instead.
Murauchi.com data breach (7.7 million records): names, addresses and phone numbers leaked — past customers should watch for scam calls and mail
On September 15, 2026, Murauchi.com Co., Ltd. announced that unauthorized access, which began with the exploitation of a vulnerability in part of its web system, led to 7,716,811 records of customer personal data being taken out (the first notice was on July 24). The data includes names, addresses and phone numbers, plus email addresses, dates of birth and gender for some people. Card and other payment data and login IDs and passwords are kept in separate systems and were not affected. The company has not said how many years of data were involved or whether former members are included. This site's take: the main risk is that real names, home addresses and phone numbers leaked together. Assume you may be affected even if you bought from the shop only once, years ago, and never hand over personal data or money in response to calls, mail or texts claiming to be from the company, an online mall or a card issuer.
If your Japanese driver's license data was leaked: what to do to prevent misuse (credit bureau alerts, reissue, where to get help)
A practical guide for people whose Japanese driver's license image or number was leaked by a company. The license number, name, date of birth and face photo cannot be changed by the holder, and a reissued license keeps the first 11 digits of its number (National Police Agency directive). At the same time, non-face-to-face identity checks for mobile phone and bank contracts are moving from sending document images to reading the card's IC chip (mobile phone online contracts from April 2026; transactions under the Act on Prevention of Transfer of Criminal Proceeds from April 2027, as scheduled). This site's take: there is no way to take leaked data back, so the core of the response is making sure you notice quickly if something is opened in your name. In practice that means registering an identity-fraud alert (honnin shinkoku) with all three Japanese credit bureaus (CIC, JICC and the Japanese Bankers Association's KSC), checking your own credit file, and ignoring messages that pose as the company that leaked the data. Reissuing the license and paid 'data deletion' services are low priority or useless.
Cariteco (Meitetsu Kyosho) Ransomware Attack: Possible Driver's Licence Data Leak and What Members Should Do
On July 2, 2026, Meitetsu Kyosho Co., Ltd. disclosed unauthorized access to its servers and a system outage detected on June 23, saying an investigation found traces of unauthorized access by ransomware. On August 4 it said it could not rule out a leak of the information members wrote on their application forms for its car-sharing service Cariteco — name, address, date of birth, phone number, email address, driver's license information and, for some members, credit card data — covering both current and former members. No count has been disclosed, and the company says no leak or misuse has been confirmed. This site's take: license data cannot be changed, so, as in the Times Car case, register a fraud alert with Japan's three credit bureaus and check your credit file. Two points are specific to this case: with ransomware, a possible leak can come to light only after the service has been restored; and some of the company's individual notices were undeliverable. Former members who have moved should contact the company rather than wait for a letter.
APORITO Online Store (RIZAP) Possible Card Data Leak: What Customers and Online Shops Should Do
According to RIZAP Co., Ltd., a third party planted a malicious script on its APORITO Online Store, and the names, addresses, phone numbers and email addresses — plus card numbers, expiry dates and security codes — of people who placed an order or entered information between May 1 and August 5, 2026 may have been sent outside. The company found a suspicious outbound-transmission program on August 5 and closed the store that day; as of August 18 the store remained closed and the investigation continued. It says no misuse or actual leak has been confirmed. This site's take: with the security code in scope, watching statements is not enough; ask your card issuer to replace the number. The lesson for e-commerce operators is that not storing card data ('non-retention') does not stop a malicious program from being planted in the input page. On top of the five vulnerability measures required by Japan's Credit Card Security Guidelines, have a way to detect changes to your payment page.
CAMPFIRE Breach (About 225,000 People): Customer Data Held Outside Production, and What Users and Developers Should Do
According to CAMPFIRE, a GitHub credential issued by an employee was misused by a third party; information visible on GitHub was then used to obtain credentials for a cloud environment the company uses for internal business operations, and part of its management area was accessed. Names, addresses, phone numbers, email addresses and bank account details of 225,846 people (project owners, supporters, partners) may have leaked; credit card data was not involved. The service platform runs in a separate environment and no misuse or tampering was found there. Users should watch for messages about refunds or payout account confirmation and check bank statements. Developers and operators get two lessons. Customer data also lives in internal business environments even when production is well protected. And work tokens can end up on machines the company doesn't manage, so organization settings must limit how long a token stays valid and what it can access.
Medica Shuppan Ransomware Attack (About 641,000 People): What Medical Readers, Authors and Publishers Should Do
According to Medica Shuppan Co., Ltd., it detected a system failure on March 13, 2026 that turned out to be unauthorized access involving ransomware. Its May 13 investigation report says the starting point was a third party entering the internal network with legitimate account credentials. No definitive evidence was found that personal data was taken out, but the possibility cannot be fully ruled out, so data of about 641,000 people (may include duplicates) is treated as 'at risk of leakage'. The data includes readers' names, contact details and email addresses, authors' bank account numbers and employees' HR records. The company does not hold credit card data. Emails impersonating the company have also been seen. This site's take: a specialist publisher's customer list is a list of medical professionals with their workplaces, so check any message about study materials, seminars, academic societies or manuscript fees on the official site you open yourself, not via a link. Authors should watch for messages that mention their account number to seem genuine and then ask for a PIN or online banking details.
Times Car data breach (6.6M accounts, 1.6M ID-document images): what leaked and what members and former members should do
Unauthorized access to the Times Car web system let a third party obtain data on about 6.6 million accounts of members, former members and unfinished applicants (name, address, date of birth, phone number, email address, driver's license information, passwords stored in a non-restorable form, and more). For about 1.6 million accounts, images of driver's licenses, proof-of-address documents and student IDs also leaked. The company does not hold credit card data at all. Affected people are receiving individual emails, and the content differs between people whose document images leaked and people for whom no image leak has been confirmed. This site's take: first check which email you received. If your images leaked, register a fraud alert with Japan's three credit bureaus and request your credit file; everyone should ignore messages claiming to be the company. Former members can ask through a dedicated form whether they are affected.
The Gyazo Breach (About 23.62 Million Records): User Data and Image Metadata Leaked — What Users Should Do Today
A vulnerability in Gyazo's image upload server was exploited, leaking about 23.62 million user records and metadata on about 490 million images, mostly uploaded before January 2019. This site's view: change your password and stop reusing it — that is the minimum. What is easy to miss is that the leak covers information about the images rather than the images themselves: text read from screenshots (OCR), photo location data and upload IP addresses. If a screenshot showed a secret, revoke that secret.
VPN Appliances Are the Main Way In for Ransomware: Remote Access Defense After Japan's Digital Agency Breach
A VPN appliance connects the internet to an organisation's internal network, and in Japan it is how attackers got in in roughly two thirds of ransomware cases where the route is known. The Digital Agency's GSS incident followed the same shape: in through a VPN vulnerability, then a maintenance operator's account used to reach a large volume of files. This site's view: only keep a VPN appliance if you can keep patching it, and defend it with three things: patch speed, narrow privileges after an intrusion, and detecting bulk access.
Japan's Four Major 2026 Data Breaches (KDDI, Aflac, Digital Agency, Sakura): Different Ways In, the Same Fix — Better Detection
KDDI (ISP mail platform, about 12.23 million people), Aflac Japan (about 4.4 million), Japan's Digital Agency (about 246,000 records) and Sakura Internet (up to about 1.36 million accounts). The ways in had nothing in common, yet KDDI, Aflac and Sakura all listed stronger detection in their remediation plans, and the Digital Agency case was caught through an anomaly in volume. This site's view: stop assuming intrusions can be fully prevented, and invest in watching volume and time, the only signals left when an attack looks like legitimate use.
How 2026 Breaches in Japan Got In: More Through Valid Credentials Than Vulnerabilities (A Cross-Case Analysis)
Classified by entry path, the major Japanese incidents disclosed in August 2026 skew toward credential-led intrusion rather than exploited vulnerabilities. The shared trait: the victim's own servers were untouched and the way in was a legitimate account on an outside service. This site's conclusion: flawless vulnerability management stops none of this, so the focus has to shift toward credential lifetime and scope, and an inventory of the vendors and SaaS that can reach your data.
When Your Web Hosting Provider Is Breached: What Customers Should Do
A provider-side compromise cannot be blocked by customer settings, so the defense shifts from prevention to limiting how much you can lose. The 10 September investigation results established the part that matters most: the intrusion into the sales management system ran from April 2023 to March 2026 — roughly three years — the affected hosting accounts rose from 583 to 951, and some initial passwords were not hashed. This site's view: treat everything on shared hosting as readable, push secrets, credentials and backups outside the provider, and change any initial password you are still using today.
Tsurugi Handa Hospital ransomware (2021) — an unpatched VPN CVE and backups encrypted along with production
The way in, per the expert committee's report, was an internet-facing VPN device left unpatched against a known vulnerability (CVE-2018-13379), reachable with leaked credentials. Short passwords, no account lockout, and users holding admin rights made it easy to spread to other machines in the hospital (lateral movement). Decisively, the primary system and its backup were on the same network and both were encrypted. A backup that isn't isolated and offline can't be relied on for recovery. EMR recovery took about two months. Defend by patching internet-facing VPNs fast, revoking leaked/reused credentials, and keeping isolated, offline, 3-2-1 backups.
Osaka General Medical Center ransomware (2022) — a contractor's VPN as the way in, and hospital BCP
The way in was not the hospital itself but a meal-service contractor's remote-maintenance VPN device, which was unpatched and reachable using leaked credentials, the investigation committee found. Because the hospital and contractor were constantly connected, and because servers/PCs shared passwords, users held broad admin rights, EMR servers lacked antivirus, and the network wasn't segmented, the encryption spread across the EMR system. Outpatient care, surgery, and emergency intake were restricted; full recovery took over two months. Defend by treating contractor links as your own attack surface: patch internet-facing VPNs, end credential reuse, least privilege, segment, and build a medical BCP (paper fallback, tested restore).
Takufile-bin Data Leak (2019) — Why Plaintext Password Storage Is Fatal, and the Hashing Defense
A server vulnerability was exploited for unauthorized access, and ~4.8 million records (names, emails, login passwords, dates of birth, including withdrawn customers) leaked. The decisive failure was that login passwords were stored unencrypted, in plaintext. Once leaked, they were immediately usable and could be used for account takeover on other sites where people reused them. Defend by storing passwords as a one-way salted hash, holding no data you don't need, patching vulnerabilities, and preparing for reuse (2FA).
Benesse Data Leak (2014) — Why an Insider Couldn't Be Stopped, and the Least-Privilege Defense
A dispatched systems engineer at an outsourced group company used legitimately granted database access to copy customer data in bulk, transfer it to a personal smartphone, and sell it to data brokers. The monitoring software blocked writes to USB storage but did not block transfer to a smartphone (MTP). Up to ~35 million records leaked. Defend by minimizing privilege (least privilege / need-to-know), closing every exfiltration path with DLP, detecting bulk access, and extending oversight all the way to contractors and sub-contractors.
KADOKAWA / Niconico Ransomware (2024) — Why It Spread Company-Wide, and Network Segmentation & BCP
The way in was described as phishing that stole an employee's credentials; from there the internal network was breached and ransomware ran, taking down many of the group's services (including Niconico) for months and leaking ~250,000 people's data. Reporting and analysis attribute the company-wide spread to systems of very different criticality sharing the same network, reportedly with too little segmentation. Defend by segmenting the network by criticality, using phishing-resistant authentication, and preparing business continuity (BCP) and recovery.
7pay Fraud (2019) — How a Payment App With No 2FA Got Taken Over
Account takeovers began the day after launch; ~808 users lost ~¥38.6M. The core failure was authentication design: (1) no two-factor authentication, so login needed only ID + password, and (2) a password reset that could send the new password to an email address other than the registered one — so fragments of personal data were enough to hijack an account. Defend by requiring 2FA on sensitive actions, restricting password reset to registered channels, detecting and locking credential-stuffing, and having auth flows reviewed by a second set of eyes before launch.
Capcom Ransomware (2020) — Why an Old VPN Device Was the Way In, and the Double-Extortion Defense
The way in was an old backup VPN device that had been left running at a North American subsidiary after newer units replaced it. From there the network was breached, data was stolen, and then ransomware encrypted systems (double extortion). Up to ~390,000 people's personal data was potentially exposed (no payment-card data). Capcom refused to pay, restored from backup, and disclosed transparently. Defend by decommissioning unused gear, patching edge devices, and covering both theft and encryption (segmentation, detection, backups).
Coincheck NEM Heist (2018) — How ~$530M Was Stolen, and the Key-Management Defense
The entry point was reported to be spear-phishing / malware aimed at employees, which stole the private key of an internet-connected hot wallet; ~523 million XEM (~$530M at the time) was then moved out in a single transfer. The core failure was keeping a huge, instantly-spendable balance in an online wallet with no multisig, so a single stolen key moved almost everything. Defend by keeping important keys offline or in a dedicated key store (HSM/KMS), minimizing the hot balance, removing single points of failure (multi-approval), and detecting and stopping abnormal bulk operations.