SHINDO7
ShopServe
E-Store Co., Ltd.
shopserve.estore.jp
Personal dataup to8.9Mrecords
LEAK CONFIRMEDBank account / PasswordUnauthorized access · Investigating
Open in the live monitor ▶- Disclosed
- Aug 1, 2026
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Investigating
- Security spend
- Measures, no amount
- Compensation
- Not announced
- Corporate number
- 8010401058455
What leaked
IdentityFull name
ContactAddress, Phone and fax numbers, Email address
Employment & HREmployer
Communications & contentOther information customers entered voluntarily
Account dataMember ID and password
CredentialsMember ID and password, ShopServe admin login IDs and passwords, shop mail system IDs and passwords, FTP IDs and passwords, ShopServe admin login IDs and passwords, shop mail system IDs and passwords, FTP IDs and passwords
Financial & paymentCardholder name, Part of the card number (first 6 and last 4 digits), Card expiry date, Bank account details for payouts from E-Store
Not leaked
- E-Store does not hold card security codes (CVV/CVC), so they are not among the leaked data.
How many
- Purchaser records (cumulative count) up to 8.9M records
- Client shops that published their own notices (piyolog tally) at least 64 organizations
Who is affected
- Purchasers
- Members (including newsletter members)
- Shops (merchants)
Cause
Unauthorized external access to ShopServe servers ran a malicious program (details of the vulnerability not disclosed)
Timeline
- Intrusion began
- Intrusion stopped
- First disclosure
- Report No. 2 published
- Parent company BASE mentioned the incident in its interim earnings report
- Contained
- Reported to authority
- Individuals notified
- Company issued an update
- Company issued an update
Response
- Blocked the entry point
- Patched
- Password reset
- MFA
- Notified individuals
- Hotline
- Forensic investigation
Blocked communication from the attacker and confirmed access was no longer possible; fixed the vulnerability (completed 8/6); strengthened login authentication for the purchaser My Page (8/6); emailed affected purchasers (from 8/7); set up contact points for purchasers and shops. Purchasers and shops were asked to change passwords and use multi-factor authentication
What you should do
- Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
- Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
- Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- E-Store Co., Ltd. (first report) Official notice · Aug 1, 2026
- E-Store Co., Ltd. (second report) Official notice · Aug 2, 2026
- Security NEXT News · Aug 7, 2026
- piyolog Researcher · Aug 12, 2026
- Cybersecurity-jp.com News · Aug 7, 2026
- Security Measures Lab Researcher
- National Tax Agency Corporate Number Publication Site Registry