SHINDO3

TEMAIRAZU

Personal dataat least71organizations

POSSIBLE LEAKPostal address / Full nameUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 28, 2026
Detected
Sep 21, 2026
Detection to disclosure
7 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityName, Gender, Age
ContactPhone number, Email address, Address, Fax number
Employment & HRCompany name
Transactions & activityReservation information, Reservation number, check-in date, check-out date, facility name
Financial & paymentReservation amount

Not leaked

  • We do not handle or retain credit card information.

How many

  • Lodging operators and facilities that disclosed (by October 2, 2026) at least 71 organizations

Who is affected

  • Guests and reservation holders

Cause

Unauthorized third-party access to the company's systems (per Temairazu). Notices from client hotels relay that a security problem existed in some of the functions making up an installation-type service the company used to provide (Anabuki Enterprise notice). The specific method was not disclosed

Timeline

  1. Client facilities began reporting suspicious messages from around late night
  2. Per notices to client facilities, the confirmed unauthorized access was limited to September 21
  3. Contained
  4. Reported to authority
  5. Service restored
  6. First disclosure
  7. English-language notice published

Response

  • Blocked the entry point
  • Patched
  • Forensic investigation
  • More monitoring
  • Service stopped
  • Password reset
  • Phishing warning

Measures to stop further harm including blocking the access; identified and fixed the cause (completed September 26); strengthened access control and monitoring; resumed functions that had been suspended; asked an outside information security specialist to help investigate; asked client facilities to change admin passwords and similar; warned guests not to open links, not to enter card details and to check bookings through official channels. An emergency help desk was set up (email only)

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources