Skip to content
Data Breach Exposes Over 6 Million Customer Records at Bookoff and JR East

Data Breach Exposes Over 6 Million Customer Records at Bookoff and JR East

First seen 9 Oct 2026, 15:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 16:35 UTC
  • •Bookoff and JR East reported breaches affecting over 6 million customer records each.
  • •The breaches involved unauthorized access to member data management systems.
  • •No payment details were compromised, but personal information was exposed.

On October 9, 2026, Bookoff Group Holdings Ltd. and East Japan Railway Co. reported significant data breaches affecting over 6 million customer records. Bookoff disclosed that up to 6.43 million accounts were compromised due to unauthorized access to its member data management system. The leaked information includes names, birthdays, addresses, email addresses, membership numbers, and reward program IDs, but not payment details. JR East reported a breach affecting approximately 6.09 million accounts, with email addresses and other personal data exposed, following a ransomware attack that disrupted a SoftBank subsidiary's cloud services. Both companies confirmed unauthorized access on October 6, 2026, and are working to enhance their security measures. This incident is part of a broader trend of data breaches affecting multiple Japanese companies in recent days.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
Unauthorized access confirmed
Bookoff and JR East confirmed unauthorized access to their systems, leading to data breaches affecting millions of accounts.
Mainichi.Jp
2026-10-09
Data breach announced
Both companies publicly announced the data breaches, detailing the extent of the compromised information.
English.Kyodonews

More articles in this cluster (2)

Following this threat?

Track Bookoff Group Holdings Ltd in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What types of information were leaked?
The leaked information includes names, birthdays, addresses, email addresses, membership numbers, and reward program IDs.
Have any fraudulent activities been confirmed?
As of now, both companies have not confirmed any fraudulent use of the compromised information.
What steps are being taken to improve security?
Both Bookoff and JR East have stated they will enhance their security frameworks to prevent future breaches.