SHINDO2

ABAHOUSE

abahouse.jp

Unauthorized accessSize not disclosed

POSSIBLE LEAKPostal address / Date of birthContained

Open in the live monitor ▶
Disclosed
Oct 3, 2026
Detected
Sep 28, 2026
Detection to disclosure
5 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced
Corporate number
1013201000361

What leaked

Account dataMember ID
IdentityFull name, Date of birth, Gender
ContactAddress, Phone number, Email address
Transactions & activityOrder information (order date and time, product name, amount, delivery address, etc.)

Not leaked

  • Credit card numbers and security codes are managed in the payment processor's system and are not stored in the company's systems
  • Credit card numbers and security codes are managed in the payment processor's system and are not stored in the company's systems

Who is affected

  • Members (ABAHOUSE Members Club)

Cause

Starting from an unauthorized login to an internal system, a flaw in the system was abused to install and run a malicious program, which then accessed the database holding member and online order information

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Detected
  4. Individuals notified
  5. Notice on the official website (dated 2026/10/03)

Response

  • Blocked the entry point
  • Password reset
  • Notified individuals
  • Phishing warning

Blocked the unauthorized access route. Contacted potentially affected customers individually by email and recommended changing the ABAHOUSE Members Club (AMC) login password as a precaution. Warned customers about suspicious refund emails

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources