SHINDO5
Rakuten Mobile
Rakuten Mobile, Inc.
Personal data~220,000accounts
LEAK CONFIRMEDPassword / Login ID / usernameAccount takeover · Investigating
Open in the live monitor ▶- Disclosed
- Feb 27, 2025
- Leak
- Leak confirmed
- Type
- Account takeover
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
CredentialsLogin ID, Password
Not leaked
- No evidence that credentials leaked from the company itself
How many
- Credentials believed to have been used to log in to Rakuten Mobile without authorization (some duplicates) ~220,000 accounts
- Mobile lines contracted fraudulently (per news reports) at least 2,500 accounts
Who is affected
- Rakuten Mobile (Rakuten ID) users
Cause
Credential stuffing with a self-made program (built with help from generative AI) using about 3.3 billion ID and password pairs for many services obtained via Telegram and elsewhere. Lines were contracted on the hijacked accounts and resold
Timeline
- Intrusion began
- Rakuten Mobile issued a warning the same day police announced the arrests
Response
- Phishing warning
- New detection
Warned users about line contracts they did not make. Introduced SMS checks on line contracts and screening of suspicious documents
What you should do
- Change this password and every account that reused it now. Switch to a passkey where offered
- Check the company's notice to see if you're affected
Lessons for companies
- Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- piyolog Researcher · Feb 28, 2025
- Rakuten Mobile, Inc. (warning about unfamiliar line contracts) Official notice · Feb 27, 2025