HIS Passport Data for 627 Customers Possibly Leaked — 5ch: “We Checked and It Just Kept Coming”

From our other sites

The story

Travel agency HIS has announced the possible leak of passport information for 627 customers due to unauthorized access. According to Kyodo News, a long stretch of time passed between discovery and disclosure, and on the thread users pointed out that “it went undisclosed for about seven and a half months,” raising questions about the oddly timed announcement. Around the same period, leaks at several other companies — including Times Car, GMO, and Daiwa Securities — were also making headlines, sparking debate over why so many companies were disclosing breaches at the same time. Opinions split between those dismissing the small number of affected users as “pathetic” and those countering that a more narrowly targeted leak actually carries a higher risk of misuse.

HIS: Customer Passport Data Possibly Leaked — 627 People Affected, Unauthorized Access

Oct 7 (Wed), 15:43 JST

Kyodo News

Source: news.yahoo.co.jp / Original article here

What people said

9AnonymousOct 7, 2026 18:16
>627 people
Pretty pathetic. Is that really worth making news over?
54AnonymousOct 7, 2026 18:22
Re: #9
Actually, the smaller the pool, the higher the odds of misuse.
If it were something huge like 6.6 million, it'd be more like lottery odds.
11AnonymousOct 7, 2026 18:16
If you're gonna leak it, now's the time! (riffing on a famous Japanese cram-school ad slogan, "When? Now!")
33AnonymousOct 7, 2026 18:19
Re: #1-10
Re: #11-20





North Korea, Russia, and China: "Japan's cyber monitoring? Total pushover, lol"





.
17AnonymousOct 7, 2026 18:17
Why is every company confessing at the exact same time?
88AnonymousOct 7, 2026 18:26
Re: #17
The attacks started a few months back, and once everyone noticed and started checking, it just kept coming out.
I bet if they dig even deeper, way more will turn up.
109AnonymousOct 7, 2026 18:29
Re: #17
Probably the pattern where they saw it blowing up in the news, did a proper internal audit, and realized "oh, we got breached too."
189AnonymousOct 7, 2026 18:41
Re: #17
Same deal as that thing where, once 5ch is already in full-on uproar mode, it's the perfect moment to slip out bad news without anyone noticing.
46AnonymousOct 7, 2026 18:21
What's going on, what's going on?
I wonder what's happening?
Leaks are flying out at an insane rate lol
52AnonymousOct 7, 2026 18:22
Re: #46
This is news about a leak that actually happened a while back.
It's basically a corporate play of "if we announce it now, it probably won't get much attention."
51AnonymousOct 7, 2026 18:22
How do they even notice a leak happened?
Do they notice because the data's been tampered with or something?
106AnonymousOct 7, 2026 18:28
Re: #51
No idea, but I'd guess suspicious traces turn up in the access logs.
53AnonymousOct 7, 2026 18:22
Are they using AI to hit servers all at once or something?
76AnonymousOct 7, 2026 18:24
Re: #53
That might be true for the other recent leaks,
but HIS specifically "went undisclosed for about seven and a half months."
Feels like they used the current uproar as cover to sneak the announcement out.
120AnonymousOct 7, 2026 18:31
Every company always insists "no evidence the leaked data has been misused" — but can they really verify that so fast?
131AnonymousOct 7, 2026 18:32
Re: #120
It's basically like trying to prove a negative — impossible to confirm either way.
157AnonymousOct 7, 2026 18:36
Re: #120
Unless the criminals themselves announce "we're using data stolen from Company X to commit crimes," there's no way to pin it down.
Especially now, with leaks happening everywhere, there's no way to narrow down which breach is actually to blame.
153AnonymousOct 7, 2026 18:35
Apparently besides HIS, personal data has also leaked from Times Car, GMO, Daiwa Securities, Yakiniku Kingdom, Dai-ichi Life, Yamato Transport, and Avahouse.
My Number card (Japan's national ID) data has probably already leaked too — people just haven't noticed yet.
160AnonymousOct 7, 2026 18:37
Re: #153
I think they've noticed — they're just hiding it.
164AnonymousOct 7, 2026 18:37
Re: #153
I just saw that Sompo Japan got hit too.
176AnonymousOct 7, 2026 18:39
Time to buy security stocks lol
181AnonymousOct 7, 2026 18:39
Re: #176
That's insane lmaooooo
182AnonymousOct 7, 2026 18:40
Re: #176
Isn't the real issue that existing security *isn't* stopping this…?
187AnonymousOct 7, 2026 18:41
Re: #176
Trend Micro is screwed—————
183AnonymousOct 7, 2026 18:40
Truly, we live in the Great Age of Unauthorized Access—
199AnonymousOct 7, 2026 18:43
Re: #183
My tokens? If you want 'em, go ahead and take 'em… go look for them. I left every environment variable in this world sitting in public repos. (riffing on Gold Roger's famous "my treasure" line from One Piece)
203AnonymousOct 7, 2026 18:44
Re: #183
"Hacking… will never end!!!" (riffing on Whitebeard's dying words from One Piece)
252AnonymousOct 7, 2026 18:53
Isn't HIS's disclosure timing just weird?
Way too slow.
258AnonymousOct 7, 2026 18:55
Re: #252
They just timed it to get buried under all the other news — sneaky move from a shady company.
259AnonymousOct 7, 2026 18:55
Re: #252
Apparently the investigation only wrapped up today.

Background and Key Points of Debate

Under Japan’s Act on the Protection of Personal Information, companies that discover a data breach are generally required to notify the relevant authority in two stages — an initial report and a final report — but there’s no firm deadline for public disclosure, and investigations often drag on. On the thread, users pointed out that “HIS went roughly seven and a half months without disclosing the breach,” fueling suspicion that the announcement was timed to slip by unnoticed. At the same time, some posters floated the idea that the wave of near-simultaneous disclosures from multiple companies is a chain reaction: once one breach made headlines, other firms re-audited their own systems and kept turning up previously undisclosed leaks. One easily misunderstood point: the fact that “only 627 people” were affected doesn’t necessarily mean the risk is low. The more narrowly targeted a leak is, the higher the odds that misuse actually hits the right target, so judging the severity of a breach by headcount alone is premature. Note that some posts in the original thread veered into personal attacks on specific politicians and slurs against political parties; those replies have been excluded from this article.

*This article is compiled from excerpts and summaries of the 5ch (News Flash+) thread “[Unauthorized Access] HIS: Customer Passport Data Possibly Leaked — 627 People Affected.”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *