Adventure, Inc., the Tokyo Growth-market company that runs the skyticket comparison-booking site, said third parties accessed its systems by three different routes, and that customer data was leaked or may have been. The largest incident covers about 14.64mn records. The company said the earnings impact is still being assessed.
The largest incident: company servers
The first incident ran from 2 to 4 October 2026 and was discovered on 5 October. Adventure said attackers manipulated some skyticket administrative functions and from there reached other company servers and data stored in the cloud.
The notice puts the affected customers, those who registered or entered information on skyticket, at about 14.64mn records. About 4.13mn of them include members' login passwords, which Adventure said were stored in hashed form. The leaked data covers names (including passport-style spelling), dates of birth, email addresses, phone numbers, postal codes and addresses, and the remitter name used for bank transfers. Adventure said passport numbers were not leaked.
Hashing converts a password into a form that is hard to turn back into the original. Adventure warns that the passwords could still be worked out through analysis and used to log in to skyticket or to other services where a customer reuses the same password.
Back-office system: refund account details
The second incident hit skyticket's business management system on 20 September and was discovered on 28 September. Adventure said a vulnerability in the system was exploited. It counts 17,780 affected records, including duplicates, and says more are still being counted.
The information leaked or possibly leaked includes names, phone numbers and refund-destination bank account details: bank and branch names, account type, number and holder name. Email addresses and dates of birth appear for 68 records and addresses for 18. Adventure has not confirmed a passport-number leak and says it is still checking whether one occurred. It also confirmed an unauthorised login to one member's account on 9 September.
Adventure said account details alone do not allow money to be withdrawn. It warns that customers may be contacted by people posing as refund handlers who try to obtain PINs or internet-banking credentials.
Bus bookings: pages viewable without login
The third incident involves skyticket's bus reservation service. From 3 August to 1 October, booking-completion pages could be displayed without logging in, and a third party viewed them by automated means. Adventure said it fixed the page on 1 October.
About 12,000 bookings are affected, and the count of people is higher once travelling companions are included. Viewed or possibly viewed data includes the booker's name in kana, age, sex, email address, phone number, member ID, payment method and amount, booking time and trip details such as operator, route and the operator's booking number. Companions' names, ages and sexes are also covered. Adventure said passport numbers were not leaked.
What Adventure says was not exposed, and what it did
Adventure said it does not store customers' credit card numbers or passport images, and that a payment-processing company, not Adventure, holds card data. It said no card data or passport images leaked in any of the three incidents.
As of the notice, Adventure had found no secondary harm from misuse of the leaked data apart from the single account login. Because members' stored cards could be used for fraudulent purchases, it stopped payment with saved credit cards and the card-saving feature at about 6pm on 7 October. It has reported the incidents to the Personal Information Protection Commission and is emailing affected customers. Members are asked to change their passwords.
The three counts are records, not unique customers, and the notice does not total them. Adventure said it is examining the effect on group results and will disclose anything required.
