VOISING
VOISING Co., Ltd.
Affected records~170,000records
LEAK CONFIRMEDPostal address / Date of birthUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Aug 18, 2026
- Detected
- Aug 16, 2026 23:55 JST
- Detection to disclosure
- 2 days
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Measures, no amount
- Compensation
- Not announced
- Corporate number
- 9010401170416
What leaked
Not leaked
- Credit card number, expiry date and security code
- Credit card number, expiry date and security code
- Credit card number, expiry date and security code
- Payment data such as credit card numbers and bank account details, and customers' password data, were never held in the system that was accessed, so they did not leak
- No customer account passwords leaked at all.
How many
- Affected records ~170,000 records
- Records that may have been published on a particular website ~50,000 records
- Records confirmed as posted on social media 10 records
Who is affected
- Members of VOISING ID, fan clubs and related services
- Online store customers
Cause
A vulnerability in the BI (business intelligence) tool the company used was exploited. The unauthorized access happened before the fix was applied, and data stored in the tool was illegally downloaded
Timeline
- Intrusion began
- Data was illegally downloaded on August 16 between 18:47 and 20:21
- BI tool shut down
- Intrusion stopped
- First disclosure
- Emails sent to affected people in turn
- Second report: response status
- Preliminary report already filed with the PPC by the second report
- Already reported to the local police station by the second report
- Individual contact with the 10 people whose data was posted on social media
- Leaked data found posted on social media (10 records)
- Approx. 50,000 records may have been published on a particular website
- Third report: some data found published externally
- Fourth report: investigation results and prevention measures
Response
- Blocked the entry point
- Patched
- Revoked credentials
- Service stopped
- Forensic investigation
- Notified individuals
- Phishing warning
- Governance / committee
- Config review
Shut down the BI tool and disconnected it from the network, discarded the compromised environment, applied the vulnerability fix, invalidated or changed all passwords and access keys, investigated with an outside specialist organization, notified affected people by email, and reported to the police and the PPC. Prevention measures: a system for receiving vulnerability information with response deadlines by severity, a clearly named decision owner, and a redesign so internal tools are not exposed directly to the internet
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- VOISING (first report) Official notice · Aug 18, 2026
- VOISING (second report) Official notice · Aug 20, 2026
- VOISING (third report) Official notice · Aug 24, 2026
- VOISING (fourth report) Official notice · Sep 30, 2026
- Security Measures Lab Researcher · Sep 30, 2026
- National Tax Agency Corporate Number Publication Site Registry