SHINDO5

Saga Hirakawaya Online Shop

Credit card records6,303recordsof up to 73,213 records affected in total

POSSIBLE LEAKCard security code / Card numberUnauthorized access · Closed (final report)

Open in the live monitor ▶
Disclosed
Jun 18, 2026
Leak
Leak possible
Type
Unauthorized access
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentCardholder name, Card number, Expiry date, Security code
IdentityName, Date of birth
ContactAddress, Phone number, Email address

How many

  • Personal records up to 73,213 records
  • Credit card records 6,303 records
  • Card users 5,783 people
  • Registered and ordering customers 30,170 people

Who is affected

  • Online shop customers

Cause

Attackers exploited a system vulnerability to alter the payment application, sending order-form input outside

Timeline

  1. Start of the customer-data period (card data from 21 March 2025)
  2. Exposure ended
  3. Security NEXT report date; whether an earlier notice (e.g. payment suspension) exists was not checked

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources