Incidents on Oct 5, 2026

Publication date: Dates are source publication dates (JST), not occurrence dates.

Details and evidence links

Filter incidents

Showing 7 of 7 incidents

Incidents on Oct 5, 2026
DateTargetSummaryClassificationSource links
LEAK-113Monogatari Corporation "Yakiniku King"S 10,788,963 recordsThe membership management system of the Yakiniku King official app was accessed without authorization, and a leak was confirmed on October 3, 2026. Member numbers, names, email addresses and phone numbers were leaked for 10,788,963 of 10,808,784 registered users.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-140Denmark's Central Person Register (CPR)S About 8,800,000 peopleA private Danish company's lawful access to search the CPR system was misused, and names, addresses and CPR numbers of about 8.8 million people were obtained without authorization. Irregular activity occurred during September 2026; the CPR administration became aware on October 2, learned the scope over the weekend, and the Ministry of Research, Higher Education and Digitalisation disclosed it on October 5. People registered with name and address protection are not affected. The company's access has been stopped, the police are investigating, and the case was reported to the Data Protection Agency (Datatilsynet).
Unauthorized access & data leakConfirmedOfficial statement
LEAK-111Daiwa SecuritiesA About 220,000 recordsThe server of Scala Communications, the provider of an external service used for inquiry management, was accessed without authorization from October 2 to 3, 2026, and about 220,000 records, including names and account numbers of about 110,000 customers, may have leaked.
Supply chainPossibleOfficial statement
LEAK-112Daiki Suisan "Daiki Suisan Official App"A 174,933 peopleThe official app's system was accessed without authorization, and the company announced it cannot rule out that names, phone numbers, addresses and other data of 174,933 users registered from November 2024 to September 15, 2026, including former members, leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-139Trustbank "Furusato Choice"D 254 recordsIn the Amazon Pay donation flow, insufficient checking in the process that restores application data after authentication meant another user's name, address, phone number, email address and gift delivery information could be shown on a different user's screen. Between November 13, 2025 and September 7, 2026, 254 applications were affected; 19 of them reached the application screen and 6 proceeded to payment, all operated with the person's own Amazon account. No charges to other people's cards or Amazon accounts have been confirmed. The company says the fault was not in Amazon Pay's payment function.
Misdelivery & accidental exposurePossibleOfficial statement
LEAK-004LEAN BODYUnauthorized access exploiting a vulnerability in Metabase, a tool used for internal data analysis, resulted in customer information such as email addresses and encrypted passwords being obtained for about 440,000 accounts, including those of former members.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-006White EssenceA vulnerability in the reservation site program was used as a foothold for unauthorized access to the core system, and data of about 1.05 million accounts, including names, addresses, email addresses and encrypted passwords, was taken out.
Unauthorized access & data leakConfirmedOfficial statement
Incidents on Oct 5, 2026