Bookoff discloses breach of up to 6.43 million customer records in Japan
TLDR
- Japanese second-hand retailer Bookoff Group Holdings says unauthorised access to a subsidiary's member-data management system may have exposed up to 6.43 million customer records.12
- Exposed data includes names, birthdays, addresses, email addresses, membership numbers, reward-program IDs and hashed passwords; Bookoff says payment details such as credit card numbers were not stored in the affected system and were not compromised.12
- Bookoff confirmed the unauthorised access on Tuesday 6 October and says it has blocked the intrusion route and is reporting the breach to Japan's Personal Information Protection Commission; it has not confirmed any fraudulent use of the data so far.1
- The disclosure is one of dozens from Japanese companies in recent days, prompting the government to urge businesses to tighten security.2
Bookoff said it confirmed unauthorised access to its subsidiary's membership data management system on Tuesday, with subsequent investigation determining that members' personal information had been compromised.12 The company said the exposed information included members' names, birthdays, addresses, email addresses, membership numbers and reward-program identification numbers, along with hashed passwords; payment information including credit card numbers was not affected because the system in question did not store it.12 Bookoff said it had blocked the identified intrusion route and is taking steps to report the breach to the Personal Information Protection Commission, Japan's data-protection regulator.1 "We will endeavor to upgrade our security framework and work to prevent a recurrence," the company said in a statement.2
Kyodo News reports the disclosure landed the same day as a separate breach notice from East Japan Railway Co. (JR East), which said data for around 6.09 million accounts tied to its Viewcard credit-card service and Ekinet ticket-reservation platform was exposed, following a ransomware attack on SoftBank subsidiary IDC Frontier's cloud service that hosted the affected systems.2 Kyodo notes the Bookoff and JR East disclosures are among a run of Japanese breach notifications in recent days, including the "Times Car" car-sharing service exposing roughly 6.6 million accounts and 1.6 million driver's licence images, plus incidents at convenience-store chain Lawson, karaoke operator Daiichikosho, and travel agency H.I.S., which disclosed a passport-data leak from late last year only after taking months to assess its scope.2
Why it matters: a 6.43-million-record exposure that includes hashed passwords alongside names and contact details gives attackers a ready-made credential-stuffing list, and its arrival alongside dozens of other Japanese disclosures in the same week shows a national pattern of breaches surfacing in clusters rather than isolated incidents.