Incidents on Oct 9, 2026

Publication date: Dates are source publication dates (JST), not occurrence dates.

Details and evidence links

Filter incidents

Showing 21 of 21 incidents

Incidents on Oct 9, 2026
DateTargetSummaryClassificationSource links
LEAK-176BOOKOFF GROUP HOLDINGSS Up to about 6,430,000 recordsOn October 6, 2026, the company confirmed unauthorized third-party access to a system provided by a subsidiary that manages member information, and confirmed that member information had leaked outside. Up to about 6.43 million member records may be affected (a count of member numbers, not the actual number of people). The scope is names, dates of birth, gender, email addresses, phone numbers, postal codes and addresses, password hashes, point card numbers and member numbers. The system does not hold payment information such as credit card data. No publication or misuse of the leaked information has been confirmed. The company is proceeding with its report to the Personal Information Protection Commission.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-174Viewcard "VIEW's NET"S About 4,030,000 recordsFollowing unauthorized access at IDC Frontier, an external service used to send email to people registered on the member site "VIEW's NET" became partly unusable, and it came to light on October 7, 2026 that email addresses may have leaked. Viewcard says it cannot rule out that some customers' email addresses were viewed or obtained; about 4.03 million records are in scope, and the affected people are still being identified. It says names, addresses, phone numbers, credit card numbers and other personal information are not at risk of having leaked.
Supply chainPossibleOfficial statement
LEAK-178dip "Baitoru" and "Baitoru NEXT"S Up to 3,885,771 recordsOn October 6, 2026, dip confirmed unauthorized third-party access to a function of the "Baitoru" and "Baitoru NEXT" websites, and some members' email addresses were leaked. The access came from overseas and exploited a specification flaw in a function of the system; up to 3,885,771 records may have been leaked. Only email addresses are affected, and names, phone numbers, passwords and credit card information are not included. All access from overseas was blocked and the program was fixed. No misuse has been confirmed. The company reported to the Personal Information Protection Commission and the Kanto Bureau of Telecommunications of the Ministry of Internal Affairs and Communications, and consulted the police.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-152JR East "Eki-net" and "Otona no Kyujitsu Club"S Up to about 1,670,000 recordsFollowing unauthorized access at IDC Frontier, an external service used to send email to members of Eki-net and Otona no Kyujitsu Club became partly unusable, and JR East announced it cannot rule out that email log data, including members' email addresses, was viewed or obtained. The maximum scope is about 1.67 million records for Eki-net members (email addresses; Business Eki-net members are excluded) and about 390,000 records for Otona no Kyujitsu Club members (email addresses, member numbers, credit card expiry dates and dates of birth). JR East says names, addresses, phone numbers, credit card numbers and other personal information are not at risk of having leaked. In its second report on October 7, IDC Frontier said the outage in East Japan Region 1 of IDCF Cloud was caused by a third-party ransomware attack.
Supply chainPossibleOfficial statement
LEAK-153Sansan "Sansan User Forum"C 8,687 peopleThe external cloud service "Commune" (Commune Inc.), used for the user online community "Sansan User Forum", was accessed without authorization by a third party, and Sansan was notified by Commune on October 6, 2026. For 1,325 members, leakage of email addresses, account (display) names, self-introduction text, profile images and group membership within the community was confirmed. A possible leak was announced for 8,687 members, covering account (display) names, self-introduction text, profile images and group membership. Passwords are not included. Sansan says information held in services such as "Sansan", "Bill One", "Contract One" and "Eight" is not affected. The community was suspended on October 6, and Sansan reported to the Personal Information Protection Commission on October 9.
Supply chainConfirmedOfficial statement
LEAK-163Suzuki "Suzuki Village"C About 3,000 peopleCommune Inc., the service provider for the community site "Suzuki Village", was accessed without authorization by a third party from October 5 to 6, 2026, and Suzuki received an investigation report on October 7. Member information of about 3,000 people (email addresses, nicknames, join dates, gender, age group, prefecture of residence and car model owned) may have been viewed or obtained. Credit card and payment information is not included. No intrusion into Suzuki's own systems and no secondary damage has been confirmed. The site is suspended.
Supply chainPossibleOfficial statement
LEAK-173Panasonic "LUMIX Community" and "Hair Sapu by Panasonic Beauty"C About 3,000 peoplePanasonic was told by Commune Inc., to which it outsources the operation of the community services "LUMIX Community" and "Hair Sapu by Panasonic Beauty", that part of the community members' information had leaked to a third party because of unauthorized access to Commune's system. The scope is member information, including email addresses, of about 2,000 people in "LUMIX Community" and about 3,000 people in "Hair Sapu by Panasonic Beauty". Both communities are temporarily suspended.
Supply chainConfirmedOfficial statement
LEAK-172JMA Management Center "Toki Labo"C 2,950 peopleJMA Management Center was told on October 7, 2026 by Commune Inc., the provider of the community service "Commune" used for its user community site "Toki Labo", that unauthorized third-party access had occurred on October 6. The site's administrator account was misused, and the company confirmed that information of some members was viewed, obtained and leaked. The scope is 2,950 people who registered after the site's renewal on May 12, 2026: display names, user names, email addresses and profile information (including names, addresses, ages and phone numbers). No payment information such as credit card data is held. No misuse or secondary damage has been confirmed.
Supply chainConfirmedOfficial statement
LEAK-156PROGRIT "ONE GRITTERS"C About 2,300 peopleCommune Inc., the outside contractor that provides "Commune", the platform for the "ONE GRITTERS" community, was accessed without authorization at around 18:00 on October 5, 2026, and PROGRIT was notified on October 7. According to Commune, a flaw in its system was exploited: an invitation link to the private community was obtained illegitimately to register as a member, and the attacker impersonated an administrator to view and obtain member information. User IDs, nicknames, account names, email addresses, usage data (join date, number of posts, points earned and so on) and profile information (self-introduction, purpose of learning English and so on) of about 2,300 members, including former members, were leaked. No leak of passwords themselves or of direct messages between members, and no unauthorized access to PROGRIT's own systems, has been confirmed. The community is suspended.
Supply chainConfirmedOfficial statement
LEAK-164Koikeya "Koikeya GOGO! Land"C Up to 1,800 recordsKoikeya was told that the system of Commune Inc., the contractor that provides the system for its fan site "Koikeya GOGO! Land", was accessed without authorization by a third party, that customer information stored there was viewed illegitimately and that some of it leaked. Suspicious access was found on October 5, 2026, and on October 7 it was found that the community's administrator privileges had been misused and information had leaked. Up to 1,800 records are affected: email addresses, nicknames, account names, self-introductions, points, last-active timestamps, registration dates, group memberships and custom profile items (gender, age group, prefecture and so on). The system does not hold credit card information, names, addresses or phone numbers. No unauthorized access to Koikeya's own systems has been confirmed. The company reported to the Personal Information Protection Commission and consulted the police.
Supply chainConfirmedOfficial statement
LEAK-168LY Corporation "DS.LAB"C 1,750 people"Commune", the platform from Commune Inc. used for "DS.LAB", the community feature inside "DS.INSIGHT", was accessed without authorization by a third party, and LY Corporation was notified on October 6, 2026. A flaw in the system was exploited, and the current investigation indicates that the nicknames, account names, names, self-introductions, icons, group memberships, email addresses, custom profile items, points and last-active timestamps of 1,750 people may have been viewed or obtained. No misuse or secondary damage, and no unauthorized access to LY Corporation's own systems, has been confirmed. DS.LAB is suspended.
Supply chainPossibleOfficial statement
LEAK-162Yamaha "Yamaha Network Engineer-kai (YNE)"C About 1,600 peopleYamaha was told by Commune Inc., which provides the platform for its social networking service "Yamaha Network Engineer-kai (YNE)", that registrants' information had leaked through unauthorized access to a server Commune manages. Yamaha was contacted on October 6, 2026, and the unauthorized access took place from around 11:59 to around 20:36 that day. Email addresses, display names, account names, self-introductions, icons and group memberships of about 1,600 people were leaked. No unauthorized access to Yamaha's own systems and no misuse of the leaked information has been confirmed.
Supply chainConfirmedOfficial statement
LEAK-155Softbrain "e-Sales Manager RemixCLOUD" user community siteC 1,164 peopleSoftbrain was notified on October 6, 2026 by Commune Inc., the provider of the cloud service used for its user community site, that unauthorized third-party access had occurred. The site's administrator account was misused, and the company names, names, account names, name readings (furigana), email addresses and profile information of 1,164 members may have been obtained or viewed. Commune suspended the site on October 6, and Softbrain reported to the Personal Information Protection Commission on October 9.
Supply chainPossibleOfficial statement
LEAK-169ZENB JAPAN "ZENB GARDEN"D Up to 949 peopleCommune Inc., the provider of the external service used for the online community "ZENB GARDEN", was accessed without authorization from around 18:00 on October 5 to around 21:00 on October 6, 2026, and ZENB JAPAN was notified on October 7. A third party impersonating an administrator viewed and obtained member information; the leak of 897 members' information has been confirmed, and the company expects it could extend to all 949 members at most. The scope is profile information such as email addresses, gender, nicknames, account names and self-introduction text. The community does not collect names, addresses, phone numbers or payment information. The company says passwords and information registered on the ZENB official site were not leaked.
Supply chainConfirmedOfficial statement
LEAK-170Chitose Group "Chitose Academy"D Up to 843 people"Commune", the community system from Commune Inc. used for the community site "Chitose Academy", was accessed without authorization, and Chitose was notified on October 7, 2026. Misuse of one administrator account was confirmed on October 6. Chitose says the attacker obtained the login signing key shared by all of Commune's communities and impersonated a community administrator, and that the attack is presumed to have been automated using AI or similar tools. At present, the names, name readings (furigana), gender, email addresses, profile information, usage data and other items of up to 843 people may have been viewed or obtained. It was confirmed that login passwords were not viewed or obtained. No payment-related information is held.
Supply chainPossibleOfficial statement
LEAK-171Doppuri Kochi Tabi Campaign "Kochi no Chi"D 358 peopleUnauthorized access by impersonation of the administrator account came to light through a notice from Commune Inc., which provides the platform for the Kochi Prefecture tourism fan site "Kochi no Chi". The email addresses, nicknames, account names, ages, gender, self-introductions, custom profile items, group memberships, points, icons and last-use timestamps of all 358 members may have been viewed or obtained. No leak of names or addresses has been confirmed so far, and the investigation is continuing. The site has been suspended as an emergency measure, with no date set for its return.
Supply chainPossibleOfficial statement
LEAK-165Morinaga Milk Industry "Mount Cafe-bu"D 291 people"Commune", the system from Commune Inc. used to run "Mount Cafe-bu", was accessed without authorization by a third party on October 6, 2026. Several flaws in the system were exploited, and the email addresses, display names, user names, self-introductions, custom profile items, group memberships, points and last-active timestamps of an estimated 291 members may have been viewed or obtained. The company says no leak to a third party has been confirmed.
Supply chainPossibleOfficial statement
LEAK-154Calbee "Zeppin-bu 'Yamerarenai, Tomaranai' Ka"The community system "Commune" provided by Commune Inc., used for the "Zeppin Kappa Ebisen" fan site "Zeppin-bu 'Yamerarenai, Tomaranai' Ka", was accessed without authorization from outside, and Calbee found that part of its members' information was viewed and obtained externally. The scope is the email addresses, display names, user names, self-introductions, profile items and group memberships registered as of October 5, 2026. No number of people was given. No leak of passwords themselves has been confirmed. Dates of birth, addresses, phone numbers and credit card information are not collected by the service and are out of scope. The service is suspended while Commune investigates.
Supply chainConfirmedOfficial statement
LEAK-166Bandai Namco Experience "Wangan Midnight Arcade Portal"Commune Inc., which provides "Commune", the platform for the "Wangan Midnight Arcade Portal", was accessed without authorization from outside, and it was confirmed that member information may have leaked. The scope is email addresses, nicknames, account names, self-introductions, profile items, group memberships, points and last-active timestamps. No number of people was given. No misuse has been confirmed. Emergency maintenance is continuing.
Supply chainPossibleOfficial statement
LEAK-167LIXIL "Sumai Hiroba" and "Nekokabe Hiroba"Unauthorized third-party access to "Commune", the system of the contractor Commune Inc. used for the community services "Sumai Hiroba" and "Nekokabe Hiroba", was confirmed around October 6, 2026. Several flaws in the system were exploited, and nicknames (display names), account names, email addresses, points earned, last-use timestamps, introductions, icons, group memberships and other items may have leaked. No number of people was given. No leak of post text or images, direct messages or passwords has been confirmed. Neither service holds addresses or payment information such as credit cards. Both services have been suspended since around 21:00 on October 6.
Supply chainPossibleOfficial statement
LEAK-177EnecomOn October 6, 2026, Enecom confirmed that a third party had been accessing part of its internal network from outside without authorization, and announced that there were signs that several electronic files had been taken outside. The files may have contained customer information, and their content and the scope of impact are under investigation. No leak of customer information related to "MEGA EGG" has been confirmed so far. There has been no system failure or impact on service provision, and no publication or misuse of the possibly leaked information has been confirmed. The company reported to and consulted the relevant ministries, the Personal Information Protection Commission and the police.
Unauthorized access & data leakPossibleOfficial statement

Showing 20 of 21 cases

Incidents on Oct 9, 2026