HomeCybersecurityTemairazu Says Up to About 4.45 Million Guests' Reservation Data May Have...

Temairazu Says Up to About 4.45 Million Guests’ Reservation Data May Have Been Viewed or Obtained

On 9 October 2026 Temairazu, Inc., a Tokyo-listed company whose software runs hotel and inn bookings, said reservation details covering “up to about 4.45 million” people may have been viewed or obtained by a third party after unauthorised access to its system. That is a ceiling, not a count of stolen records.

What Temairazu does

Confirmed (company’s own pages). Temairazu makes “TEMAIRAZU”, a “site controller”: its site describes an online system that manages several accommodation booking sites in one place, covering room stock, plan prices and reservation details [4]. The filing calls it a reservation management system for accommodation providers [1].

What the filing says

Confirmed (company filing, 9 October). In Japanese: “第三者に閲覧または取得された可能性があることを確認しております。これらの情報に係る対象者数は、最大で約445万人です。” TSN’s translation: “We have confirmed the possibility that it was viewed or obtained by a third party. The number of people covered by this information is up to about 4.45 million.” [1]

The data is guests’ names, phone numbers, email addresses and other contact details, property name, check-in and check-out dates and charges [1]. The company adds: “当社はクレジットカード情報を保有しておりません” (TSN’s translation: “we do not hold credit card information”) [1]. It also holds no booking-site login details [2].

On 21 September several properties told Temairazu that suspicious messages were reaching guests; it then confirmed unauthorised access by a third party [1][3]. It briefly suspended some functions on 24 September [1]. It has reported the incident to Japan’s Personal Information Protection Commission (PPC), consulted police and hired outside security specialists [1]. The filing does not say how the access happened or who was behind it, and TSN does not speculate.

The messages guests received

Confirmed (company’s 7 October report). Guests received messages by WhatsApp, email and SMS impersonating properties or booking sites, asking them to visit outside sites for “advance check-in” or to keep a reservation valid, enter card details or pay. The company calls them apparent phishing scams, messages built to trick people into handing over card details or money [2]. Its own guidance: do not open links, reply, enter details or pay; check with the property or booking site through official contacts, not the message’s; if card details were entered, contact the card issuer [2].

What a reservation-system breach exposes

A booking system holds who is staying where, when, and how to reach them. The company said some messages appeared to contain reservation information [3]. It does not say how the senders got it; the filing calls the messages “believed to be related” to the access [1].

What this does not show

  • That 4.45 million people’s data was taken. The company says “up to”, and “possibly” [1].
  • Whether the figure counts people or bookings. The filing says “persons covered” [1].
  • The cause or the culprit. Neither is stated.

The Bottom Line

Temairazu confirms that a third party accessed its system and that guest names, contact details and stay dates may have been viewed or obtained, for up to about 4.45 million people. It says it holds no card data. The actual scale, cause and attacker are unconfirmed.

Related on TSN: Japan’s Data-Breach Wave: What Bookoff, Times Car, skyticket, Lawson, Resorttrust and Others Have Admitted; JR East and Viewcard Say About 6.09 Million Accounts May Be Exposed After the IDC Frontier Attack; Cyber Breaches: SoftBank Cloud Ransomware, Qilin’s 53 Japanese Victims, Asos’s Bigger Leak and Denmark’s Register

Sources

  1. Temairazu, Inc. (手間いらず株式会社), “当社システムへの不正アクセスに関する調査状況および対応について” (Status of investigation and response regarding unauthorised access to our system), 9 October 2026 (company filing, in Japanese; TSN’s translation; copy also at https://www.temairazu.co.jp/pdf/1212/ir-news). https://japanir.jp/wp-content/uploads/2026/10/2477-20261009-01.pdf
  2. Temairazu, Inc., “当社システムへの不正アクセスに関する経過および対応について(第二報)” (Progress and response, second report), 7 October 2026 (company notice, in Japanese; TSN’s translation; the English version is dated 8 October). https://www.temairazu.co.jp/pdf/1210/news-update ; English: https://www.temairazu.co.jp/pdf/1211/news-update
  3. Temairazu, Inc., “不審なメッセージおよび当社システムへの不正アクセスに関するお詫びとお知らせ” (Apology and notice on suspicious messages and unauthorised access), 28 September 2026 (company notice, in Japanese; TSN’s translation; English version 29 September). https://www.temairazu.co.jp/pdf/1206/news-update
  4. Temairazu, Inc., company overview and TEMAIRAZU service pages, read 10 October 2026 (company’s own descriptions). https://www.temairazu.co.jp/info ; https://www.temairazu.com/

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.