SHINDO5

Rakuten Mobile

Personal data~220,000accounts

LEAK CONFIRMEDPassword / Login ID / usernameAccount takeover · Investigating

Open in the live monitor ▶
Disclosed
Feb 27, 2025
Leak
Leak confirmed
Type
Account takeover
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

CredentialsLogin ID, Password

Not leaked

  • No evidence that credentials leaked from the company itself

How many

  • Credentials believed to have been used to log in to Rakuten Mobile without authorization (some duplicates) ~220,000 accounts
  • Mobile lines contracted fraudulently (per news reports) at least 2,500 accounts

Who is affected

  • Rakuten Mobile (Rakuten ID) users

Cause

Credential stuffing with a self-made program (built with help from generative AI) using about 3.3 billion ID and password pairs for many services obtained via Telegram and elsewhere. Lines were contracted on the hijacked accounts and resold

Timeline

  1. Intrusion began
  2. Rakuten Mobile issued a warning the same day police announced the arrests

Response

  • Phishing warning
  • New detection

Warned users about line contracts they did not make. Introduced SMS checks on line contracts and screening of suspicious documents

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources