Asia
Up to 2.06 million JR East Eki-net and club records may have leaked in IDC Frontier attack
Up to 2.06 million JR East Eki-net and club records may have leaked in the IDC Frontier attack. View Card reports 4.03 million email addresses.
2 min read
By Ellis
East Japan Railway (JR East) said on Friday that data on up to about 1.67 million Eki-net train reservation members and about 390,000 Otona no Kyujitsu Club members may have leaked in connection with unauthorised access at cloud provider IDC Frontier. The two figures add up to about 2.06 million records. That total is The Once Times's own sum: JR East gives none and has not said whether any people are in both groups.
For Eki-net members, excluding Business Eki-net, the data that may have leaked is email addresses. For club members it is email addresses, membership numbers, credit card expiry dates and dates of birth. JR East said there was no possibility that names, addresses, phone numbers or credit card numbers had leaked.
JR East said it could not rule out that email log data held by an outside email-sending service, including some customers' email addresses, was viewed or taken. Email delivery to members of both services is partly unavailable.
Its group card company, View Card, said separately on Friday that about 4.03 million email addresses registered on its VIEW's NET member site may have been viewed or taken in the same incident. It said no other personal data, such as names, addresses, phone numbers or card numbers, could have leaked, and that cards with the ii mark and View corporate cards were not covered. Identifying the people involved is still under investigation. Adding the three figures gives about 6.09 million, which is The Once Times's own calculation and may count people more than once.
IDC Frontier, a SoftBank subsidiary, said unauthorised access to part of its IDCF Cloud service, which it described as a ransomware attack, began at about 3.40am on Wednesday 7 October. Its notices do not name JR East, and neither JR East's nor View Card's notice mentions ransomware.
What to do: JR East and View Card said they will email affected people individually once ready. View Card said that, if the addresses leaked, suspicious emails could be sent to them. Its helpline, View Card Center, is 03-6685-7000 (9am to 5.30pm).
No source has linked this incident to the Lawson, Big Echo and Book-Off breaches, which are covered here: Lawson, Big Echo, Book-Off breaches: what leaked, and what customers should do now.
Related
Translations of Japanese-language notices are by The Once Times.






