SHINDO3

NIPPON Rent-A-Car

nipponrentacar.co.jp

Members (first incident)41people

POSSIBLE LEAKDriver's licence / Postal addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 26, 2026
Detected
Sep 25, 2026
Detection to disclosure
1 day
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
6011001018116

What leaked

IdentityFull name, Date of birth
ContactPhone number, Email address, Address
CredentialsLogin ID
Transactions & activityUsage history, Reservation information
ID documentsDriver's license number
Financial & paymentLast 4 digits of credit card number, Cardholder name

How many

  • Members (first incident) 41 people

Who is affected

  • Members

Cause

Unauthorized access by a third party to the NIPPON Rent-A-Car app system. The second incident (55 people) was a separate unauthorized access using a different method; access occurred 2026-09-19 to 21 and was discovered on 09-29

Timeline

  1. Detected
  2. First disclosure
  3. Company issued an update

Response

  • Password reset
  • Notified individuals

Asked affected members to reset their passwords

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
  4. Don't open links in emails from this company. The apology email itself may be fake
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Watch for unexpected mail or invoices; your address is hard to change
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources