SHINDO3

Hotto Motto

Unauthorized accessSize not disclosed

POSSIBLE LEAKCard number / Postal addressInvestigating

Open in the live monitor ▶
Disclosed
Jan 31, 2025
Detected
Jan 12, 2025 14:00 JST
Detection to disclosure
19 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress, Phone number, Email address
Financial & paymentCredit card information

Who is affected

  • Users of the delivery, for Biz and seasonal pre-order services of Hotto Motto online ordering

Cause

Outside attackers targeted the delivery, for Biz and seasonal pre-order services of Hotto Motto online ordering

Timeline

  1. Detected
  2. Second attack
  3. Date of the Security NEXT report

Response

  • Blocked the entry point
  • Service stopped
  • Forensic investigation
  • More monitoring

Blocked access and suspended credit card registration and payment. Strengthened blocking of malicious traffic and is investigating the cause and impact

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources