SHINDO3

Kansai Airport Washington Hotel

Account takeoverSize not disclosed

LEAK CONFIRMEDPayment data (unspecified) / Phone numberClosed (final report)

Open in the live monitor ▶
Disclosed
Feb 4, 2026
Detected
Jan 4, 2026
Detection to disclosure
31 days
Leak
Leak confirmed
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName, Nationality (possible)
ContactPhone number
Transactions & activityBooking date and booking number
Financial & paymentCredit card and payment information (possible)

Who is affected

  • Some guests with bookings from 4 January 2025 to 6 January 2026

Cause

An unauthorized login on an overseas booking site led to fake messages being sent to guests

Timeline

  1. Customer inquiries revealed messages leading to phishing sites
  2. Reported to authority
  3. Security NEXT report date

Response

  • Password reset
  • Phishing warning

Changed login passwords and checked PCs; warned guests about fraudulent payment requests

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources