SHINDO7

PeakManager

Personal data~22.2Mrecords

LEAK CONFIRMEDHealth / medical / treatment / Card numberUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Jul 31, 2026
Detected
Jul 27, 2026
Detection to disclosure
4 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
8013301038345

What leaked

IdentityFull name, Name reading (furigana), Date of birth, Gender
ContactAddress, Phone number, Email address
CredentialsEncrypted passwords
Special-care dataPartly includes special-care personal information such as health conditions
Financial & paymentFive entries contained information that may be credit card information

Not leaked

  • Customers' credit card information and My Number information are not included

How many

  • Affected records after de-duplication (second report) ~22.2M records
  • Affected records as of the first report ~33M records

Who is affected

  • Customers of member salons that use PeakManager

Cause

Unauthorized third-party access transferred data out of the database that stores customer information (method withheld to prevent copycat attacks)

Timeline

  1. Detected
  2. Reported to authority
  3. First disclosure
  4. Second report: approx. 22.18 million records after de-duplication

Response

  • Forensic investigation
  • Hotline

Investigation with outside specialists; security review and hardening. Dedicated helpline (0120-206-460, weekdays 10:00-17:00)

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  3. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  4. Don't open links in emails from this company. The apology email itself may be fake
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Watch for unexpected mail or invoices; your address is hard to change
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources