Multiple Japanese Companies Suffer Data Breaches, Millions of Records Exposed
Japanese firms including Lawson and JR Kyushu have reported significant data breaches affecting millions of customers. Personal information may have been compromised in separate incidents.
Several Japanese companies, including convenience store giant Lawson and Kyushu Railway Company (JR Kyushu), have announced substantial data breaches, exposing personal information of millions of customers and raising concerns about data security.
Lawson disclosed on October 8 that its "Lawson ID" membership account service was accessed illegally. The breach could have compromised approximately 2.155 million user accounts, with leaked data including email addresses, names, genders, phone numbers, and addresses. The unauthorized access reportedly occurred between September 12 and 14.
Other businesses have also faced similar attacks. Karaoke chain operator Dai-ichi Kousho revealed that up to 8.72 million customer records may have been leaked, potentially due to malware infecting an employee's terminal at an outsourced vendor. Affected information included customer names, birth dates, and email addresses.
East Japan Railway Company (JR East) also reported a potential leak of about 6.09 million personal information records linked to its "Viewcard" credit service. JR Kyushu stated that up to 1.3 million email addresses of its website members might have been compromised. Additionally, used goods dealer BOOKOFF Group Holdings and flight booking site skyticket reported their own breaches affecting millions of customer records.
Japan's minister in charge of cybersecurity, Shunji Furukawa, stated on October 9 that authorities would request swift countermeasures to address vulnerabilities and prevent the misuse of leaked data.