HomeAIJR East and Viewcard Say About 6.09 Million Accounts May Be Exposed...

JR East and Viewcard Say About 6.09 Million Accounts May Be Exposed After the IDC Frontier Attack

Japan’s biggest railway operator and its credit-card arm say customers’ email addresses, and for some members a little more, may have been exposed in the ransomware attack on the cloud provider IDC Frontier. It is the first large customer-data leak publicly tied to that attack. It is a possibility, not a confirmed theft.

What happened

IDC Frontier, a subsidiary of SoftBank, has been hit by ransomware since about 03:40 local time on Wednesday 7 October. Its own notices confirm the attack and say 495 companies and local authorities use the affected cloud region [1].

On Friday 9 October, East Japan Railway (JR East) and its group card company Viewcard said customer data may have been exposed as a result. Kyodo News reports that JR East said data for “around 6.09 million accounts” was exposed [2]. Japanese outlets report the same total, “延べ約609万件”, meaning a running total across services [3][4]. ITmedia says it comes from two announcements [3].

The numbers (reported)

  • Ekinet, about 1.67 million. This is JR East’s online booking service for Shinkansen and express trains. ITmedia and Nippon TV report that only email addresses are involved [3][4]. Kyodo describes “email addresses to email logs” [2].
  • Otona no Kyujitsu Club, about 390,000. This is JR East’s club for older travellers. The data may include email addresses, membership numbers, card expiry dates and dates of birth [2][3].
  • Viewcard, about 4.03 million. These are email addresses registered on its member website, VIEW’s NET. ITmedia reports Viewcard is still working out exactly who is affected [3].

Both companies say names, addresses, phone numbers and credit-card numbers were not involved [2][3]. According to ITmedia, the data was held in an outside service used to send emails to members, and the companies cannot rule out that a third party viewed or took it [3]. Mail delivery to members is partly disrupted, but Asahi reports that train tickets can be booked as normal [5]. JR East says it will email affected customers individually once ready [4].

What IDC Frontier has said (confirmed)

In its third notice, on 8 October, IDC Frontier said customer data in four zones of its East Japan Region 1 is expected to be hard to retrieve or restore, and that data can be recovered only from backups customers hold themselves [1]. Its fourth notice, on 9 October, describes an emergency response headquarters working with SoftBank, with outside security specialists investigating [6]. Neither notice says that data left its systems.

What this does not prove

  • That data was stolen. JR East and Viewcard say they cannot rule out that a third party viewed or took some customers’ email addresses. IDC Frontier has not confirmed that data was taken [1][3][6].
  • That 6.09 million different people are affected. The figure counts accounts across three services, and one person can hold several. Viewcard is still identifying who is affected [3].
  • That names, addresses or card numbers are at risk. The companies say they were not involved. That is their statement; TSN has not seen JR East’s own notice, which was blocked to TSN with an HTTP 403 error.
  • Who is behind it, or how they got in. IDC Frontier says the route is still under investigation [1].

The Bottom Line

The IDC Frontier attack now has a named knock-on leak. JR East and Viewcard say about 6.09 million accounts’ details, mostly email addresses, may have been exposed (reported). The practical risk is convincing phishing emails that look like JR East or Viewcard. If you use Ekinet, Otona no Kyujitsu Club or Viewcard, treat unexpected emails about your account with suspicion, and do not click links in them.

Earlier TSN coverage: Cyber breaches: the IDC Frontier attack, Qilin in Japan, Asos and Denmark. Related: Japan’s data-breach wave.

Sources

  1. IDC Frontier, “[Third report] Failure caused by unauthorised access to some of our service systems” (【第3報】当社サービスの一部システムへの不正アクセスによる障害について), 8 October 2026 (company notice, in Japanese; TSN’s translation; confirmed). https://www.idcf.jp/news/topics/20261008001
  2. Kyodo News, “Bookoff, JR East each report 6 mil. customer records leak in newest breach”, 9 October 2026, 09:51 BST (17:51 JST) (reported). https://english.kyodonews.net/articles/-/87669
  3. ITmedia NEWS (梅林日奈子), “JR東日本、「えきねっと」「ビューカード」などで漏えいか メルアドなど最大609万件 IDCFへの不正アクセスで【追記あり】”, 9 October 2026, 07:23 BST (15:23 JST), updated 09:58 BST (17:58 JST) (in Japanese; TSN’s translation; reports both companies’ notices). https://www.itmedia.co.jp/news/article/2610/09/2000002171/
  4. Nippon TV (NTV News NNN), “【速報】えきねっと会員と大人の休日倶楽部会員に電子メールを送るシステムにも不正アクセス 個人情報漏えいの可能性 JR東日本”, 9 October 2026, 06:18 BST (in Japanese; TSN’s translation; reported). https://news.ntv.co.jp/category/society/d0a74accb39041b69e1df75b968f00d1
  5. The Asahi Shimbun (吉田貴司), “JR東「えきねっと」「大人の休日倶楽部」で漏洩か のべ206万件”, 9 October 2026, 06:29 BST (in Japanese; TSN’s translation; reported). https://www.asahi.com/articles/ASVB91R1GVB9ULFA011M.html
  6. IDC Frontier, “[Fourth report] Response structure for the failure caused by unauthorised access” (【第4報】不正アクセスによる障害への対応体制について), 9 October 2026 (company notice, in Japanese; TSN’s translation; confirmed). https://www.idcf.jp/news/topics/20261009001

JR East’s own notice (jreast.co.jp) returned HTTP 403 to TSN, so the JR East and Viewcard figures are as carried by the news reports above.

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.