The Once Times

Asia

Lawson, Big Echo, Book-Off breaches: what leaked, and what customers should do now

Lawson, Big Echo and Book-Off have disclosed customer data breaches over two days. Here's what leaked and how to avoid the scams that may follow.

6 min read

A nighttime photo of the entrance to a Lawson convenience store in Fukuoka, Japan, showcasing its vibrant signage.
Photo by 떡이 민 on Pexels

Convenience store chain Lawson on Thursday confirmed that data from more than 2.1 million Lawson ID records had leaked, karaoke operator Daiichikosho said about 8.7 million records might have been exposed through a contractor, and secondhand retailer Book-Off said on Friday that member data had been taken from its systems, as the Japanese government held an emergency meeting on a run of cyber intrusions.

None of the three has found any misuse of the data so far. All are telling customers to watch for emails, texts and calls impersonating them.

Toshiharu Furukawa, Minister for Digital Transformation and Minister in charge of Cybersecurity, told an interministerial meeting on Thursday: "We are in an extremely critical situation. The whole government needs to work together on countermeasures."

What happened at each company

Lawson. A third party accessed the Lawson ID account service between 12 and 14 September and the Lawson app's pre-order service on 17 September, the company said. It found the access during an investigation on 7 October, more than three weeks after the first intrusion.

The 2,155,345 Lawson ID records include email addresses and names, plus sex, phone number, address and newsletter preferences where customers had entered them. A further 26 pre-order records include name, phone number and part of a credit card number. Passwords are not listed among the leaked data.

Lawson said a security mechanism meant to show app users only their own information had been accessed without authorisation, and that it found no malware. It has blocked the suspicious access, suspended pre-orders until mid-October and reported the case to the Personal Information Protection Commission (PPC).

Daiichikosho. The operator of the Big Echo karaoke chain said a leak was possible but not confirmed. A computer used by an employee of Nippon Columbia Group (NCG), which handles customer data for Daiichikosho under contract, was found to be infected with malware on 1 and 2 October. Customer data had been stored on it temporarily.

The company said it had not confirmed that any data had left the computer, but could not rule it out. About 8,724,000 records could be affected: about 8,631,000 customer records after duplicates are removed, most of them from Big Echo and the DK Dining restaurants, plus about 93,000 employee records. The data comprises name, sex, date of birth, email address and phone number. Passwords are not included, and Daiichikosho said the details alone could not be used to spend customers' points.

BIG ECHO logo in bold white text with Karaoke Entertainment above and a yellow and white curved underline on a red background
DAIICHIKOSHO CO.,LTD

Book-Off. Book-Off Group Holdings said in a stock exchange filing on Friday that it had detected unauthorised access to a subsidiary's member-management system on 6 October and that member data had been taken.

Up to about 6.43 million records may be affected, but the company said that figure counts member numbers, not people, and it is still working out how many customers are involved. The data includes name, date of birth, sex, email address, phone number, postcode and address, point-card and member numbers, and hashed passwords, which the company described as encrypted and unreadable as they are. Card and other payment details are not held in that system.

Book-Off said it had cut off the attacker's traffic, fixed the vulnerability and begun an emergency review of all its systems. It has not said when the intrusion began. "We will review our security systems and work to prevent a recurrence," the company said.

Records named in the three disclosures. Daiichikosho's leak is possible but not confirmed, and Book-Off's figure counts member numbers, not people. Chart: The Once Times, from company disclosures
Records named in the three disclosures. Daiichikosho's leak is possible but not confirmed, and Book-Off's figure counts member numbers, not people. Chart: The Once Times, from company disclosures

What customers should do

Scammers use names, email addresses and phone numbers to make fake messages convincing. Advice from the companies, the Council of Anti-Phishing Japan and the government's National Cybersecurity Office (NCO):

  • Don't tap links in messages that claim to be from these companies. Open the official app or type the website address yourself.

  • Know what the companies will and won't send. Lawson says it is contacting affected customers from lawson_id@mailservice.lawson.jp. Daiichikosho says it will never ask for passwords or credit card details, and Book-Off says it will never ask for passwords, authentication codes, card or bank details.

  • Don't reuse passwords, and switch on multi-factor authentication or passkeys where a service offers them. Book-Off has not told members to change passwords, but any password also used elsewhere is worth changing.

  • Check card statements. If you see a charge you don't recognise, ask your card company to stop the card and issue a new one.

  • Hang up on suspicious calls, look up the official number yourself and call back.

  • Get help. The consumer hotline is 188 and the police advice line is #9110; call 110 if money is being taken right now.

Daiichikosho's helpline is 03-3280-3702 (weekdays, 10am-5pm) and Book-Off's is 0570-01-2902 (10am-6.30pm).

BOOK-OFF storefront with orange logo sign, blue floor guide for Gomic and books, promo banners, steps and escalator inside.
BOOKOFF Osaka Shinsaibashi Store / Photo: bookoff.co.jp

Government response

Officials from 29 ministries and agencies attended Thursday's meeting, convened by the NCO, according to technology news site Impress Watch. Ministries will gather information on leaks at the businesses they oversee and pass it to the NCO.

"Government bodies and businesses entrusted with personal information must strengthen their measures as a matter of duty," Furukawa said, according to the Sankei Shimbun.

The government plans to ask businesses and their contractors to fix system vulnerabilities, strengthen authentication, prevent misuse of leaked data and delete personal data they no longer need, according to the Sankei and broadcaster TV Asahi. It will also step up its response with AI-enabled cyber attacks in mind, the Sankei reported. None of the three companies has said AI was involved in its case.

The NCO plans a public alert in the coming days on basics such as not reusing passwords. The PPC issued its own urgent alert to businesses on Wednesday.

Background

According to the NCO, unauthorised access to companies appears to have risen sharply since August, the Sankei reported. Park24 said last month that data from about 6.6 million accounts at its Times Car car-sharing service had leaked, including identity-document images such as driving licences for about 1.6 million. Yakiniku King operator Monogatari Corporation has disclosed a leak from about 10.8 million app accounts, and Sagawa Express a possible leak of customer data.

Separately, SoftBank subsidiary IDC Frontier said this week that a ransomware attack on part of its cloud service had affected 495 companies and local governments.

Worldwide, a Nikkei tally of disclosures since September puts the cumulative total at more than 300 million people. The count includes claims by attackers and third parties such as research firms, and the same person may be counted more than once.

No source has linked the Lawson, Daiichikosho and Book-Off cases to the same attacker.

Translations of Japanese quotes are by The Once Times.

You might like

Editor's Picks