SHINDO2

Hotel Tavinos, Hotel Chinzanso Tokyo, Washington Hotel (franchise) and others

Unauthorized accessSize not disclosed

POSSIBLE LEAKContained

Open in the live monitor ▶
Disclosed
Oct 2, 2026
Detected
Sep 22, 2026
Detection to disclosure
10 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

UnspecifiedInformation of some customers who booked the facilities

Not leaked

  • Temairazu states it does not handle or retain credit card information.

Who is affected

  • Some customers who booked the facilities

Cause

Unauthorized access to an external reservation management system (the TEMAIRAZU series of Temairazu, Inc.)

Timeline

  1. Detected
  2. First disclosure

Response

  • Phishing warning

Posted a warning about suspicious emails and messages impersonating hotels and online travel agencies on September 23 to 24. On October 2 it disclosed the cause and the 13 affected facilities, advised customers not to open suspicious links or enter information and to contact their card company if they had entered card details on a phishing site, and referred inquiries to Temairazu's emergency help desk

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources