Japanese companies are disclosing customer-data leaks at an unusual rate. On Friday 9 October the second-hand retailer Bookoff said up to about 6.43 million member records had been taken. On the same day the travel-booking site skyticket said about 14.64 million records had leaked or may have leaked, and the resort operator Resorttrust disclosed a leak of its own. In the past few weeks the car-sharing service Times Car, the convenience-store chain Lawson, the karaoke operator Daiichikosho and the travel agency H.I.S. have all published their own notices. Kyodo News reports that “dozens of Japanese companies” have revealed unauthorised access and leaks “in recent days”, prompting the government to urge businesses to tighten security (reported) [1].
These are separate incidents with different causes. Here is what each company has confirmed. TSN gives no technical detail beyond what the companies themselves say.
Bookoff: up to about 6.43 million member records
Confirmed (company notice). Bookoff Group Holdings says a third party accessed a member-management system run by one of its subsidiaries, and that member data was taken [2]. It confirmed the unauthorised access on Tuesday 6 October [2]. The number of records that may have leaked is “最大 約643万件”, up to about 6.43 million. The company stresses this counts member numbers, not the actual number of people [2].
The data may include names, dates of birth, gender, email addresses, phone numbers, postcodes and addresses, hashed passwords (stored in a form that cannot be read directly), point-card numbers and membership numbers [2]. Card and other payment details were not held in that system [2]. Bookoff says it has found no sign that the data has been published or misused, has blocked the route used and reported the incident to Japan’s privacy regulator [2]. Kyodo quotes the company: “We will endeavor to upgrade our security framework and work to prevent a recurrence” [1].
Times Car: about 6.6 million accounts
Confirmed (company notices). Times Car, the car-sharing service of the Park24 group, detected unauthorised access to its web system on 25 September [3]. It says about 6.6 million accounts’ data was taken, covering current and former members [3]. Depending on the person, that includes names, addresses, dates of birth, phone numbers, email addresses, driving-licence details and passwords stored in a form that cannot be reversed [3]. About 1.6 million accounts also had identity-document images leak, such as driving-licence photos and proof-of-address documents [4]. Credit-card data was not leaked [3]. Kyodo’s version is “about 6.6 million accounts”, “including images of 1.6 million driver’s licenses” [1].
Lawson: 2,155,345 Lawson ID records
Confirmed (company notice). Lawson said on 8 October that its Lawson ID account service was accessed without authorisation between 12 and 14 September, and its app pre-order service on 17 September; it found this in an investigation on 7 October [5]. Leaked for 2,155,345 Lawson ID records: email addresses and names, plus gender, phone number and address where users had entered them [5]. For 26 pre-order users, names, phone numbers and part of their card numbers leaked [5]. Lawson says it has found no misuse [5].
Daiichikosho: about 8.72 million records “may” have leaked
Confirmed (company notice). Daiichikosho, which runs the Big Echo karaoke chain, says a malware infection was found on 1–2 October on an employee computer at a contractor that handles its customer data, Nippon Columbia Group [6]. Names, gender, dates of birth, email addresses and phone numbers for about 8,724,000 records, including about 93,000 employee records, may have leaked [6]. Daiichikosho stresses that an actual leak has not been confirmed, no passwords were involved, and its own systems were not affected [6].
H.I.S.: up to 627 passport records
Confirmed (company notice). H.I.S. said on 7 October that a file server at its Thai subsidiary was accessed in December 2025 [7]. In February it found the server held passport details for up to 627 customers who travelled to Thailand. Those details include names, dates of birth, passport numbers and expiry dates, plus allergy information [7]. It says checking every file by hand is why disclosure took until now [7].
Adventure (skyticket): about 14.64 million records
Confirmed (company notice). Adventure Inc., which runs the travel price-comparison and booking site skyticket, said on 9 October that customer data had leaked, or may have leaked, in three separate incidents that each used a different route [8].
- Its servers (2–4 October, found 5 October). Some of skyticket’s admin functions were misused to reach other company servers and data stored in the cloud. This affected “約1,464万件”, about 14.64 million records of customers who had registered or entered details on skyticket. About 4.13 million of those records include member login passwords, stored hashed (scrambled so they cannot be read directly) [8]. Leaked fields include names (including as written on passports), dates of birth, email addresses, phone numbers, postcodes and addresses, and the names used for bank-transfer payments. The company says it has confirmed that passport numbers were not leaked [8].
- Its operations-management system (20 September, found 28 September). A vulnerability was exploited. This involves 17,780 records “including duplicates”, and further records are still being counted [8]. Names, phone numbers and refund bank-account details (bank, branch, account type, number and holder) leaked or may have leaked; for some customers, email addresses and dates of birth (68 records) and addresses (18) did too. The company says no leak of passport numbers has been confirmed for this incident and it is still checking [8].
- Bus bookings (3 August to 1 October). Bus-booking confirmation pages could be viewed without logging in, and a third party viewed them automatically. That covers about 12,000 bookings, and more people once travelling companions are counted. The company fixed this on 1 October [8].
Adventure says it does not store credit-card numbers or passport images, and that neither leaked in any of the incidents [8]. From about 18:00 Japan time on 7 October it switched off payment with saved cards and the saving of card details, to stop stolen logins being used for purchases [8]. It has reported the incident to Japan’s privacy regulator, the Personal Information Protection Commission [8]. Apart from one unauthorised login to a member’s account on 9 September, it says no harm from misuse of the data has been confirmed. It asks members to change their skyticket password, and the same password anywhere else it is used [8].
Resorttrust: about 26,000 member records and about 36,000 hotel bookings
Confirmed (company release). Resorttrust, which runs membership resorts and hotels, said on 9 October that an outside party accessed a website it manages [9][10]. It noticed “abnormal system activity” on 6 October that had taken place “between approximately 20:30 and 23:30 on October 5”, and confirmed a leak on 7 October [9]. The data confirmed as leaked is information on part of its group membership, “approx. 26,000 cases”, and reservation information for The Kahala Hotel & Resort Yokohama, “approx. 36,000 cases” [9].
The release does not list which fields were taken. It says the system did not hold usage history, medical information, card or bank-account details, email addresses or identity documents [9]. Its hotels are running normally, and it plans to contact affected customers individually [9].
What this does not prove
- That these incidents are linked. The companies describe different systems and causes [2]–[9].
- That 14.64 million, 6.43 million or 6.6 million people are affected. All three are record or account counts, and skyticket’s 17,780 figure includes duplicates [2][3][8].
- That Daiichikosho’s data actually leaked. The company says it cannot rule it out [6].
- That any of the data has been misused. Apart from one unauthorised login to a skyticket member’s account on 9 September, no company reports misuse [2][3][5][6][8][9].
- That skyticket’s passport numbers are all safe. Adventure confirms no leak for two of the three incidents and is still checking the third [8].
The Bottom Line
Seven well-known Japanese brands have disclosed customer-data leaks within a few weeks. skyticket’s about 14.64 million records, Bookoff’s up to about 6.43 million, Times Car’s about 6.6 million accounts and Daiichikosho’s possible 8.72 million are the largest. For customers, the immediate risk is phishing that uses real names and details, and for skyticket members, reused passwords and fake refund calls. Change any reused password, and be wary of unexpected emails, texts or calls that claim to come from these firms.
Sources
- Kyodo News, “Bookoff, JR East each report 6 mil. customer records leak in newest breach”, 9 October 2026, 09:51 BST (17:51 JST) (reported). https://english.kyodonews.net/articles/-/87669
- Bookoff Group Holdings Ltd., “不正アクセスによる個人情報漏えいに関するお詫びとお知らせ” (Apology and notice regarding a personal-data leak caused by unauthorised access), TSE disclosure, 9 October 2026 (company notice, in Japanese; TSN’s translation). https://ssl4.eir-parts.net/doc/9278/tdnet/2893077/00.pdf
- Times Car (Park24 group), “「タイムズカーWebシステム」への不正アクセスに関する調査結果および今後の対応について(第2報)” (Second report on investigation results and response), 28 September 2026, updated 1 October 2026 (company notice, in Japanese; TSN’s translation). https://share.timescar.jp/news/2026/0928/1815.html
- Times Car (Park24 group), “「タイムズカーWebシステム」への不正アクセスに関する調査結果および今後の対応について(第3報)” (Third report), 29 September 2026, updated 1 October 2026 (company notice, in Japanese; TSN’s translation). https://share.timescar.jp/news/2026/0929/1816.html
- Lawson, Inc., “第三者による不正アクセスに伴う個人情報漏えいに関するお詫びとお知らせ” (Apology and notice regarding a personal-data leak caused by third-party unauthorised access), 8 October 2026 (company notice, in Japanese; TSN’s translation). https://www.lawson.co.jp/contents/cont07/1533174_3310.html
- Daiichikosho Co., Ltd., “委託先における個人情報漏えいのおそれについて” (On a possible personal-data leak at a contractor), 8 October 2026 (company notice, in Japanese; TSN’s translation). https://www.dkkaraoke.co.jp/news/newsletter/261008_2.html
- H.I.S. Co., Ltd., “子会社ファイルサーバへの不正アクセスによる個人情報流出の可能性に関するお詫びとお知らせ” (Apology and notice on a possible personal-data leak from unauthorised access to a subsidiary’s file server), 7 October 2026, updated 19:30 JST the same day (company notice, in Japanese; TSN’s translation). https://www.his.co.jp/assets/20261007.pdf
- Adventure, Inc., “不正アクセスによるお客様情報の流出に関するお詫びとお知らせ” (Apology and notice regarding the leak of customer information due to unauthorised access), TSE disclosure, 9 October 2026 (company notice, in Japanese; TSN’s translation; PDF as hosted by Japan IR). https://japanir.jp/wp-content/uploads/2026/10/6030-20261009-01.pdf (summary page: https://japanir.jp/en/company/company-6030/ir/6030-20261009-01_wp_disclosure_update/)
- Resorttrust, Inc., “Apology and Notice Regarding Personal Data Leak Caused by Unauthorized Access to Our Website”, TSE disclosure (English version), 9 October 2026 (company release). https://fs2.magicalir.net/tdnet/2026/4681/20261009548973.pdf (also via MarketScreener: https://sa.marketscreener.com/news/resorttrust-apology-and-notice-regarding-personal-data-leak-caused-by-unauthorized-access-to-our-w-ce785ddfd18bf423)
- Resorttrust, Inc., “当社ウェブサイトへの一部不正アクセスによる個人情報漏洩に関するお詫びとご報告”, TSE disclosure (Japanese original), 9 October 2026 (company release). https://fs2.magicalir.net/tdnet/2026/4681/20261009548970.pdf

