Commune Inc., a Tokyo company whose platform hosts online communities for businesses, said on 9 October 2026 that an outside party broke into its “Commune” and “Commune for Work” services and that member information for about 307,000 people leaked [1]. That is an estimate from its logs. It says it has found no misuse or secondary damage so far [1].
Confirmed: Commune’s own notice (in Japanese; TSN’s translation). All figures are estimates and may change.
What leaked
- About 126,000 members: information including email addresses. About 42,000 of these are Commune staff and test demo accounts [1], leaving roughly 84,000 other accounts (TSN’s arithmetic).
- About 181,000 members: no email address, but display names, self-introductions and private-group membership [1].
- Passwords: Commune says no password leak is confirmed, direct messages were not leaked, and it holds no card payment data. Separately, 144 members’ passwords were changed to temporary ones without their action; those have expired and must be reset [1].
How it happened
Commune says the attacker exploited a flaw in its system. They improperly obtained invite links to private communities, registered as ordinary members, then impersonated administrators to view member data and overwrite data [1].
An invite link is a web address that lets anyone holding it join a private community. Impersonating an administrator means the system treated the attacker as someone with management rights. Commune says customers’ settings were not the cause [1].
In Japan time, data leaked from about 18:00 on 5 October to about 21:00 on 6 October, and from 13:17 to 14:36 on 7 October [1]. Commune stopped all communities from about 21:00 on 6 October and has reopened them in phases from about 12:00 on 8 October; some are still in maintenance [1].
Customers named
Sansan says 1,325 Sansan User Forum members are confirmed leaked (email, display name, self-introduction, profile image, group membership) and 8,687 possibly (the same without email), with no passwords [2]. Nikkei reports about 10,000 people in total [3]. Panasonic says Commune reported about 2,000 LUMIX Community members and about 3,000 “Hair Supple by Panasonic Beauty” members had information including email addresses leaked [4]. Media name other customers; TSN has checked only these two.
What to watch for
Expect phishing: emails or texts using your name, employer or forum membership to look genuine. Do not click links or open attachments. Commune says it never asks for passwords by email or phone [1]. Change any forum password you reused elsewhere.
What is not known
- How the invite links were obtained. The notice does not say.
- The full customer list, with counts per community. Commune is telling affected customers privately [1].
- What was overwritten, and for which customers. The notice says data was overwritten and that it removed the attacker’s writes, but not where [1].
- Who was behind it.
Sources
- Commune Inc. (コミューン株式会社), “当社サービス「Commune」、「Commune for Work」への不正アクセスによる個人情報の漏えいに関するお詫びとお知らせ” (Apology and notice on personal-information leak after unauthorised access to our Commune and Commune for Work services), 9 October 2026 (company notice, in Japanese; TSN’s translation; times are Japan time). https://communeinc.com/ja/news/2026oct09
- Sansan, Inc., “オンラインコミュニティー「Sansan User Forum」における会員情報漏えいに関するお詫びとお知らせ” (Apology and notice on member-information leak at the online community Sansan User Forum), 9 October 2026 (company notice, in Japanese; TSN’s translation). https://jp.corp-sansan.com/news/2026/1009.html
- Nikkei, “Sansan、1万人の情報漏洩か 外部クラウドに不正アクセス” (Sansan: information of 10,000 people possibly leaked; unauthorised access to external cloud), 9 October 2026, 18:22 Japan time (in Japanese; headline and lead read, article body is subscriber-only). https://www.nikkei.com/article/DGXZQOMG00015_Z01C26A0000000/
- Panasonic Corporation, “外部委託先への不正アクセスによる当社コミュニティ会員情報の漏えいについて” (On the leak of our community members’ information through unauthorised access to an outsourced provider), 9 October 2026 (company notice, in Japanese; TSN’s translation). https://www.panasonic.com/jp/about/news/20261009.html
Related stories
- Pays ApS Confirms Its Access to Denmark’s CPR Register Was Abused; ‘123456’ Passwords Reported
- Cyber Breaches: SoftBank Cloud Ransomware, Qilin’s 53 Japanese Victims, Asos’s Bigger Leak and Denmark’s Register
- Temairazu Says Up to About 4.45 Million Guests’ Reservation Data May Have Been Viewed or Obtained
- JR East and Viewcard Say About 6.09 Million Accounts May Be Exposed After the IDC Frontier Attack
- Japan’s Data-Breach Wave: What Bookoff, Times Car, skyticket, Lawson, Resorttrust and Others Have Admitted






