S About 14,640,000 recordsAdventure announced that the system of its comparison and booking site "skyticket" was accessed without authorization by third parties and that customers' personal information was leaked or may have been leaked. There were three incidents through different routes: (1) from October 2 to 4, 2026, some management functions were manipulated and data on its servers and cloud was accessed, leaking about 14.64 million records (about 4.13 million of them including hashed login passwords) with names (including passport spelling), dates of birth, email addresses, phone numbers, addresses, payer names for bank transfers and so on; (2) on September 20, a vulnerability in an operations management system was exploited, and 17,780 records with names, phone numbers, refund bank account details and other data were leaked or may have been leaked; (3) from August 3 to October 1, the bus booking confirmation page could be displayed without logging in, and about 12,000 bookings were viewed or may have been viewed. Credit card numbers and passport images are not stored and were not leaked. An unauthorized login to one member's account was confirmed. Payment with saved credit cards was suspended, and the company reported to the Personal Information Protection Commission.
Unauthorized access & data leakConfirmedOfficial statement
S About 8,724,000 recordsBetween October 1 and 2, 2026, an employee device (one PC) at Nippon Columbia Group, a contractor, was found to be infected with malware, and Daiichikosho was notified on October 5. The device temporarily held personal data related to work outsourced by Daiichikosho, which may have leaked outside. The scope is about 8,724,000 records in total: about 8,631,000 customer records (Big Echo, DK Dining, Karaoke CLUB DAM and others) and about 93,000 employee records, covering names (registered names), gender, dates of birth, email addresses and phone numbers. Passwords are not included. No actual leak outside and no misuse has been confirmed. The infection route is under investigation.
S 2,155,345 records"Lawson ID" and "Lawson App Reservation" were accessed without authorization by a third party, and Lawson confirmed that personal information was leaked. It came to light in an investigation on October 7, 2026; the unauthorized access took place from September 12 to 14 for Lawson ID and on September 17 for Lawson App Reservation. The scope is 2,155,345 records for Lawson ID (email addresses, names, gender, phone numbers and so on) and 26 records for Lawson App Reservation (names, phone numbers and part of the credit card number). Lawson believes a system related to the app was misused and the security mechanism for showing users their own information was accessed without authorization. No misuse or secondary damage has been confirmed. The Lawson App Reservation function was suspended, and Lawson reported to the Personal Information Protection Commission.
Unauthorized access & data leakConfirmedOfficial statement
A Up to 362,000 recordsUzabase announced that a management tool used in operating "NewsPicks" was accessed without authorization by a third party and that part of its customers' personal information may have leaked. The access was detected at 12:48 on October 8, 2026, and the server was cut off at 14:01. The second report (October 9) said a vulnerability in the management tool was exploited and gave maximum estimated figures, including 323,000 email addresses, 59,000 names, 273,000 job-title categories and 362,000 records of partial credit card information used for web payments (cardholder name and the last three or four digits of the card number). Full card numbers and security codes are not stored by the company. No leak of passwords and no intrusion into the NewsPicks service itself or other information systems has been confirmed. The company filed a preliminary report with the Personal Information Protection Commission and consulted the police.
Unauthorized access & data leakPossibleOfficial statement
A About 307,000 peopleFrom around 18:00 on October 5 through October 6, 2026, the community platforms "Commune" and "Commune for Work" were accessed without authorization by an outside third party, and Commune confirmed that part of the member information in some communities was leaked. The estimated number of affected members is about 307,000: about 126,000 whose leaked data included email addresses (about 42,000 of them Commune employees and test demo accounts) and about 181,000 whose leaked data did not include email addresses (display names, self-introductions, membership of private groups and so on). A flaw in its system was exploited: invitation links to private communities were obtained illegitimately to register as ordinary members, and the attacker impersonated administrators to view and obtain member information and overwrite data. All communities were suspended at around 21:00 on October 6, but on October 7 some further unauthorized registrations and viewing occurred through a communication path left open during maintenance. The passwords of 144 members were changed to temporary passwords without their action. No leak of passwords themselves or of direct messages between members has been confirmed. Commune first disclosed the case for Aomori Prefecture's "Aomori Biiki" on October 8 and published the overall notice on October 9. Communities have been reopening in stages since October 8.
Unauthorized access & data leakConfirmedOfficial statement
B 38,509 recordsA third party obtained customers' member-page login details, mainly by phoning them while posing as a sales caller for line switching, and logged in as those customers for 38,509 contracts. Names, addresses, phone numbers, email addresses, contract details and billing information may have been viewed. The figure counts contracts, not people. No system intrusion, exploited vulnerability or financial harm has been confirmed. Login by phone number, postal code and date of birth was discontinued.
Unauthorized access & data leakPossibleOfficial statement
C 2,950 peopleThe information server of Commune Inc., which manages and operates the prefecture's official fan community "Aomori Biiki", was accessed without authorization by a third party, and the service has been suspended since 21:00 on October 6. The first report (October 8) said member information of up to 2,950 people may have been viewed through unauthorized access to the administrator account. The follow-up report (October 9) said Commune's investigation found that member information of 2,950 people had leaked (the community had 15,847 members as of October 5). The scope includes email addresses, nicknames (some members registered their real names), account names, prefecture of residence, age group, gender, member IDs, self-introductions, icons, member rank, point balances and last-use timestamps.
C 2,950 people"Commune", the system from Commune Inc. used for the "VALX 'FUN' Community", was accessed without authorization from around 19:18 to around 20:17 on October 6, 2026. VALX says several flaws in the system were exploited and the attacker impersonated an administrator. It estimates that the member list information of 2,950 of its 3,813 members (email addresses, nicknames, account names, profile information, point balances and last-use timestamps) may have been viewed or obtained. No acquisition of passwords or direct message content has been confirmed. Names, addresses and payment information from the VALX Members Store are not included.
C About 1,200 peopleWingArc1st was notified on October 6, 2026 by Commune Inc., the provider of the cloud service used for its user networking site "nest Portal", that unauthorized third-party access had occurred. The site's administrator account was misused, and registered information of some members, such as company names, job titles, names, name readings (furigana), email addresses and addresses, may have been obtained or viewed. The current estimate is about 1,200 people, and the affected people and number are under investigation. Commune suspended the site on October 6, and WingArc1st reported to the Personal Information Protection Commission on October 8.
E 35 peopleStarting from a suspicious email from outside received by an employee, unauthorized access to an email account used by a bank employee occurred on October 7, 2026 and was discovered on October 8. The email addresses of 35 people may have leaked, and whether other information may have leaked is being checked. No misuse or other damage has been confirmed. The bank blocked access to the account, commissioned an investigation by an outside specialist and reported to the relevant authorities.
Unauthorized access & data leakPossibleOfficial statement
An external software supplier of PUBLICA, the Swiss federal pension fund, was hit by a cyberattack at the end of September 2026, and a data leak was confirmed. The supplier filed a criminal complaint and notified the relevant federal offices, PUBLICA and other customers. The Office of the Attorney General of Switzerland has opened an investigation. Which data is affected and to what extent is still being determined by the federal offices and the supplier; no number of people or data types has been announced. PUBLICA has informed its insured persons.
Future Shop "future Scenario Cast" and "futureCartRecovery"
IDCF Cloud, the platform on which the email delivery services "future Scenario Cast" and "futureCartRecovery" run, was hit by a ransomware attack, and email delivery was stopped from around 13:45 on October 7, 2026. The mail-sending server on IDCF Cloud held recipient email addresses and data contained in email bodies such as names, birthdays and member IDs, and whether any information leaked and the scope of impact are under investigation. The company says the data was automatically deleted 14 days after sending and was encrypted from the time it was stored. Addresses, phone numbers, login passwords and credit card information are out of scope. Delivery resumed on October 9 after switching to an environment in a different data center. The futureshop platform itself runs on separate infrastructure and is not affected.