Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Article

Temairazu says up to 4.45mn guests' booking data may have been exposed

Temairazu, a hotel reservation software provider, says a third party may have viewed or obtained booking records on up to about 4.45 million people, and that it cannot yet estimate the effect on earnings.

By Tokyo Brief DeskOct 9, 20262 min readTemairazu, Inc.2477
Illustration of hotel registration cards and room keys at a front desk, with some cards slipping through a broken padlock into a stream of data.

Temairazu, a TSE Standard-listed provider of reservation management software for hotels and inns, says booking information on up to about 4.45 million people may have been viewed or obtained by a third party. The company disclosed the figure on 9 October in a timely disclosure on its investigation into unauthorised access to its TEMAIRAZU system.

What may have been exposed

The data at issue is reservation information handled on the system: guests' names, phone numbers, email addresses and other contact details, along with accommodation names, check-in and check-out dates and room charges. The company calls 4.45 million the maximum number of people covered. It says the data "may have been" viewed or obtained, which is a statement of possible exposure, not confirmed theft of every record. Temairazu says it does not hold credit-card information.

Timeline and response

On 21 September, several hotels using the system told Temairazu that suspicious messages about bookings were being sent to their guests, and the company began an internal investigation. It then confirmed third-party unauthorised access, took steps to limit damage, found the point of entry and tightened access controls and monitoring. It says the cause identified so far has been fixed.

On 24 September the company suspended some functions of the system from about 10:58am and restored them at about 9:48pm the same day. During the suspension, some output, settings and checking tasks were restricted. Temairazu says the core engine linking reservations, inventory and rates was not shut down, and that the system is now running normally.

An outside security specialist has been engaged to verify the cause and scope of the breach. Temairazu has reported the incident to the Personal Information Protection Commission, Japan's data-protection regulator, and has consulted the police. It earlier posted notices on its own website on 28 September and 7 October.

The cost

Temairazu expects to bear costs for the outside investigation, security upgrades and handling of inquiries from hotels and guests. It says it cannot reasonably estimate the effect on earnings while it is still examining the scope and the related costs. If a guidance revision or another material effect emerges, it says it will disclose it promptly.