Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Article

Book Off says up to 6.43 million member records were taken in breach

A third party took member data from a Book Off subsidiary's system, covering up to about 6.43mn records; the company says no payment data was held there and is still counting the people affected.

Loyalty point cards and a ledger beside a padlocked server cabinet in a secondhand bookstore backroom

Book Off Group Holdings said on 9 October 2026 that a third party took member information from a membership system run by one of its subsidiaries, and that up to about 6.43mn member records may have leaked.

The company confirmed the unauthorised access on Tuesday 6 October 2026, and its investigation found that member data held in the system had been obtained from outside. The figure is a count of member numbers that may have leaked, not the actual number of people affected, which the company says it is still working out.

What may have been taken

The notice lists names, dates of birth, sex, email addresses, phone numbers, postal codes and addresses, password hash values, point card numbers and member numbers. It describes the hashes as encrypted passwords that cannot be read as they stand. Credit card and other payment data were not held in the system, so they are not part of the leak, according to the company. It has seen no sign that member data was altered.

As of 9 October, Book Off had not confirmed that the leaked data had been published or misused by third parties.

Containment and warnings

After confirming the access, the company says it cut communications from the source of the attack, fixed the vulnerability and blocked external access to the affected system. It says the route of theft identified so far is contained and that monitoring continues. It has begun an emergency review of all its systems, covering networks and applications, and is reporting to the Personal Information Protection Commission.

Book Off warned members to expect possible emails, texts or calls posing as the group or its partners. It told them not to open links or attachments in unexpected messages or enter personal or login details, and said the group never asks for passwords, authentication codes, card details or bank account details by email, text or phone. Affected customers will be contacted individually as the investigation proceeds.

The notice does not name the subsidiary or give a cause of the breach. The company says it will issue a follow-up when it has the number of affected people and the exact data involved.