SHINDO3
Beer no Engawa
HARADA CORPORATION
beer-engawa.jp
ID documents9people
POSSIBLE LEAKCard security code / Card numberUnauthorized access · Investigating
Open in the live monitor ▶- Disclosed
- Aug 18, 2026
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
- Corporate number
- 7120001077531
What leaked
IdentityFull name, Gender, Date of birth
ContactPhone number, Email address, Address
Financial & paymentCredit card number, Cardholder name, Expiry date, Security code
How many
- Customers whose information, including credit card data, may have leaked 9 people
- Of these, customers who completed payment 4 people
- Of these, customers who left the order without completing payment 5 people
Who is affected
- Customers who entered information on the order confirmation page
Cause
A vulnerability in part of the system used by the site was exploited, administrator privileges were obtained without authorization, and a malicious program may have been running. Information entered on the order confirmation page while it ran is affected
Timeline
- Malicious program started running
- Malicious program stopped running
- Service suspended
- First disclosure
- Update: cause announced, with 9 affected customers whose data, including card data, may have leaked
Response
- Service stopped
- Forensic investigation
Temporarily closed the site and continues an investigation by an outside specialist firm. Reported to the card companies, the payment processor and the Personal Information Protection Commission. Asked customers to check their card statements
What you should do
- Call your card issuer, reissue the card, check statements daily and turn on alerts
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Harada Corporation (first report) Official notice · Aug 18, 2026
- Harada Corporation (update) Official notice · Sep 14, 2026
- Security NEXT News · Aug 21, 2026
- ScanNetSecurity News · Aug 26, 2026
- gBizINFO Registry