TEMAIRAZU
Temairazu, Inc.
Personal dataat least71organizations
POSSIBLE LEAKPostal address / Full nameUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Sep 28, 2026
- Detected
- Sep 21, 2026
- Detection to disclosure
- 7 days
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Measures, no amount
- Compensation
- Not announced
What leaked
Not leaked
- We do not handle or retain credit card information.
How many
- Lodging operators and facilities that disclosed (by October 2, 2026) at least 71 organizations
Who is affected
- Guests and reservation holders
Cause
Unauthorized third-party access to the company's systems (per Temairazu). Notices from client hotels relay that a security problem existed in some of the functions making up an installation-type service the company used to provide (Anabuki Enterprise notice). The specific method was not disclosed
Timeline
- Client facilities began reporting suspicious messages from around late night
- Per notices to client facilities, the confirmed unauthorized access was limited to September 21
- Contained
- Reported to authority
- Service restored
- First disclosure
- English-language notice published
Response
- Blocked the entry point
- Patched
- Forensic investigation
- More monitoring
- Service stopped
- Password reset
- Phishing warning
Measures to stop further harm including blocking the access; identified and fixed the cause (completed September 26); strengthened access control and monitoring; resumed functions that had been suspended; asked an outside information security specialist to help investigate; asked client facilities to change admin passwords and similar; warned guests not to open links, not to enter card details and to check bookings through official channels. An emergency help desk was set up (email only)
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Temairazu, Inc. Official notice · Sep 28, 2026
- Temairazu, Inc. (English notice) Official notice · Sep 29, 2026
- Temairazu, Inc. company profile Official notice
- Anabuki Enterprise Co., Ltd. Official notice · Sep 28, 2026
- MIMARU (follow-up notice) Official notice · Sep 29, 2026
- Kamenoi Hotel (Iconia Hospitality) Official notice · Sep 30, 2026
- UDS HOTELS (follow-up notice) Official notice · Oct 1, 2026
- Smile Hotel (follow-up notice) Official notice · Sep 30, 2026
- piyolog Researcher · Sep 29, 2026
- Security Measures Lab (list of affected companies and hotels) Researcher · Oct 2, 2026
- Security Measures Lab Researcher
- Travel Voice News · Sep 29, 2026
- TRAICY News · Sep 29, 2026
- Global Agents Co., Ltd. (LIVELY HOTELS, second report) Official notice · Sep 30, 2026
- Fujita Kanko Inc. Official notice · Oct 2, 2026
- Hankyu Hanshin Hotels Co., Ltd. Official notice · Sep 30, 2026
- OneFive Hotels Co., Ltd. Official notice · Sep 30, 2026
- Karaksa Hotels (follow-up notice) Official notice · Sep 30, 2026
- gBizINFO Registry
- Fusaki Beach Resort Hotel and Villas Official notice · Sep 30, 2026