SHINDO4

Charm main store

www.charm.co.jp

Customer records~230,000records

POSSIBLE LEAKPostal address / Date of birthUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Aug 13, 2026
Detected
Aug 11, 2026
Detection to disclosure
2 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
5070001019706

What leaked

IdentityFull name, Date of birth, Gender
ContactAddress, Phone / fax number, Email address
Account dataPoints balance
Transactions & activityInternal customer-service records
CredentialsPassword hash values

Not leaked

  • Credit card information (stated as not included)

How many

  • Customer records ~230,000 records

Who is affected

  • Customers of Charm main store No. 1 and No. 2

Cause

Unauthorized access by a third party (method not disclosed)

Timeline

  1. Period in which unauthorized logins were confirmed
  2. Detected
  3. Exposure ended
  4. Intrusion stopped
  5. Service suspended
  6. Reported to authority
  7. First disclosure

Response

  • Blocked the entry point
  • Service stopped
  • Notified individuals
  • Hotline
  • Password reset

Blocked all access to the related servers; closed the Charm main store and stopped order taking and shipping; reported to the PPC and JIPDEC; individual notices planned; password-change instructions to follow. Helpline 0120-89-4828 (8:00-17:00, every day)

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources