Mainichi.Jp Data Breach Exposes Over 6 Million Customer Records at Bookoff and JR East
Article Content
- •Bookoff and JR East reported breaches affecting over 6 million customer records each.
- •The breaches involved unauthorized access to member data management systems.
- •No payment details were compromised, but personal information was exposed.
On October 9, 2026, Bookoff Group Holdings Ltd. and East Japan Railway Co. reported significant data breaches affecting over 6 million customer records. Bookoff disclosed that up to 6.43 million accounts were compromised due to unauthorized access to its member data management system. The leaked information includes names, birthdays, addresses, email addresses, membership numbers, and reward program IDs, but not payment details. JR East reported a breach affecting approximately 6.09 million accounts, with email addresses and other personal data exposed, following a ransomware attack that disrupted a SoftBank subsidiary's cloud services. Both companies confirmed unauthorized access on October 6, 2026, and are working to enhance their security measures. This incident is part of a broader trend of data breaches affecting multiple Japanese companies in recent days.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Bookoff Group Holdings Ltd in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What types of information were leaked?
Have any fraudulent activities been confirmed?
What steps are being taken to improve security?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…