Skip to content
RegionAsia-Pacific

MediumII Cyber Warfare & Critical Infrastructure9 October 2026, Friday

Skyticket's 14.64 million records top Japan's wave of data leaks

Four large Japanese companies disclosed unrelated data leaks on 8–9 October. The biggest involves 14.64 million records at Adventure, which operates skyticket; the National Cybersecurity Office held an emergency meeting on 8 October.

Location: TOKYO

According to Impress Watch, skyticket's servers were accessed without authorisation between 2 and 4 October, and the company detected the intrusion on 5 October. The attacker abused some of the site's administrative functions to reach other servers and data held in the cloud. The exposed data include names as spelled in passports, dates of birth, email addresses, phone numbers, addresses and the names of bank-transfer senders; about 4.13 million records also contain hashed passwords. The company said it does not store card numbers or passport images.

Other companies disclosed leaks over the same two days. Daiichikosho, which runs the Big Echo karaoke chain, said on 8 October that about 8.72 million records were at risk. Malware had infected a computer belonging to an employee of the Nippon Columbia group, to which it had outsourced data processing. Book Off disclosed up to about 6.43 million records in its membership system on 9 October, and Lawson about 2.16 million Lawson ID records on 8 October. According to a Jiji report carried by Nippon.com, none of the companies had confirmed misuse by third parties at the time of disclosure.

By our calculation, the four companies' figures add up to more than 31.9 million records; that is a count of records that may include duplicates, not of people. Book Off stressed that its figure refers to membership numbers rather than individuals and said it confirmed the access on 6 October. According to Rocket Boys, the company said it had closed the vulnerability but disclosed neither its type nor the attacker. Impress Watch reported that JPCERT/CC issued a warning about known vulnerabilities and abuse of application programming interfaces (APIs).

Talay assessment

Bottom line

Four independent leaks in the same week point not to a single gang but to Japanese companies keeping customer data scattered across admin tools, contractors and the cloud. At skyticket the entry point was an admin function; at Daiichikosho it was a contractor's computer. The likeliest path is binding government guidance on contractor and API security, with disclosures staying elevated for several weeks.

Likely effects

  • Japanese consumersNegativeWeeks

    Passport-spelled names and dates of birth exposed together in millions of records raise the risk of identity fraud and targeted phishing.

  • Japanese regulationUncertain1–6 months

    The National Cybersecurity Office's emergency meeting on 8 October raises the likelihood of binding guidance on contractor and API security.

  • Turkish travel platformsNegative1–6 months

    Travel sites holding passport-format names and bank-transfer details create the same data concentration on Turkish booking platforms.

Possibilities, ranked

  1. 1
    Disclosures stay high50%

    New company disclosures keep coming for several weeks, but misuse remains limited to isolated cases.

    Watch: Breach notifications filed with the Personal Information Protection Commission

  2. 2
    Common culprit emerges30%

    Investigators find the same vulnerability or the same group behind at least two of the companies.

    Watch: Forensic statements from JPCERT/CC and the companies

  3. 3
    Wave fades20%

    No further major disclosure follows and each incident is closed company by company.

    Watch: No new leak disclosure above 1 million records by the end of October

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • skyticket records▼ 14.64 million
  • Four-company total▼ 31.9 million+

Sources

  1. Impress Watch — Roundup of personal data leaks in early October (9 October 2026)
  2. INTERNET Watch — About 14.64 million personal data records leaked at skyticket
  3. nippon.com (Jiji) — JR East 6.09 million, Book Off 6.43 million: unauthorised access spreads
  4. Rocket Boys Security Lab — Unauthorised access to Book Off membership system