Lawson Data Breach Exposes 2.15 Million Customers’ Personal Information

From our other sites

The story

On October 8, convenience store giant Lawson announced that unauthorized access to its membership service “Lawson ID” had exposed the personal information of approximately 2,155,000 users. It marks a large-scale breach targeting the membership base of a major convenience store chain. On 5ch forums, users voiced frustration that companies aren’t investing enough in security, while others pointed out links to a string of recent breach disclosures at companies like Sagawa Express, Yamato Transport, and Japan Post. The thread was also abuzz with surprise that companies keep holding onto user data even after accounts are closed, as well as questions about the government’s response — with opinions split over whether the root cause is poor corporate security or increasingly sophisticated attackers.

Lawson announced on the 8th that its account service “Lawson ID” had suffered unauthorized access, leaking users’ personal information. The number of people affected totals approximately 2.155 million.

Source: news.yahoo.co.jp / Original article here

What people said

15AnonymousOct 8, 2026 20:52
With this much data leaking out, why won't they even try to protect it?
23AnonymousOct 8, 2026 20:53
Re: #15
That's because they're deliberately leaking the info to foreign countr—

oh, someone's at the door, gotta go
25AnonymousOct 8, 2026 20:53
I want a timeline summary of all these leaks.
35AnonymousOct 8, 2026 20:55
Re: #25
And include both the discovery date and the announcement date.
29AnonymousOct 8, 2026 20:54
Is the government taking the stance that this is a private-sector issue and none of their business?
This is clearly a cyberattack on our country.
40AnonymousOct 8, 2026 20:56
Re: #29
Yeah, because the head of the Digital Agency said everyone should protect their own personal information themselves.
41AnonymousOct 8, 2026 20:56
Isn't this actually a chance for us /nanj/ (5ch livejupiter board) guys to start our own security company?
There's probably more investigation requests coming in than existing security firms can even handle.
46AnonymousOct 8, 2026 20:59
Re: #41
The moment you leak something, you get hit with a massive damages payout.
44AnonymousOct 8, 2026 20:59
Say what you want, but actual IT companies aren't the ones leaking data — this is a technical competence problem on the company's end.
Don't go blaming AI for it.
47AnonymousOct 8, 2026 20:59
They just haven't disclosed it yet — everybody's leaking.

'Now's the time!' (lol), right?
49AnonymousOct 8, 2026 21:00
Re: #47
That's actually true — some companies are only disclosing now something that happened last year.
56AnonymousOct 8, 2026 21:03
Seriously, what is going on?
I've been deleting all my unnecessary accounts like crazy.
58AnonymousOct 8, 2026 21:05
Re: #56
Company: 'Even if your account's deleted, we're keeping your data on our servers anyway!'
66AnonymousOct 8, 2026 21:08
Re: #56
This is still just phase one.
Next they'll be breaching infrastructure and government agencies too.
149AnonymousOct 8, 2026 21:38
Re: #56
It doesn't get deleted from the company's servers, so deleting your account is pointless.
74AnonymousOct 8, 2026 21:10
Phew, close call…
I closed my account back in July.
76AnonymousOct 8, 2026 21:11
Re: #74
Since when did you think closing your account meant your data gets completely deleted?
89AnonymousOct 8, 2026 21:19
There's way too many of these lately.
Are they running automated AI attacks or something?
93AnonymousOct 8, 2026 21:21
Re: #89
Well yeah, if there are tens of thousands of AI agents running attacks, it's game over.
98AnonymousOct 8, 2026 21:23
There are probably way more companies leaking data that just haven't disclosed it.
104AnonymousOct 8, 2026 21:26
Re: #98
I work in systems administration, and honestly if someone got in and just quietly siphoned data out, there's no way I'd notice.
109AnonymousOct 8, 2026 21:27
Re: #98
Honestly I think they're doing well to disclose it at all — though being a big company, they probably couldn't hide it anyway.
117AnonymousOct 8, 2026 21:29
Re: #98
Just noticing the breach at all is already commendable.
111AnonymousOct 8, 2026 21:28
Here you go.


Asahi Shimbun @asahi (2026/10/08 20:16:04)
Daiichikosho, operator of karaoke chain "Big Echo," may have leaked 8.72 million pieces of personal information https://www.asahi.com/articles/ASVB83K0SVB8ULFA02WM.html
https://ohayua.cyou/card_img/2108154458291220480/BauPMuxg.jpg#.jpg
https://x.com/asahi/status/2108154454721851711
112AnonymousOct 8, 2026 21:28
I wish the companies that got breached would actually contact the users whose data might have leaked.
Lawson hasn't said a word, and neither has Sagawa.
119AnonymousOct 8, 2026 21:29
Re: #112
I'll just send it with everyone CC'd, that okay?
120AnonymousOct 8, 2026 21:29
Re: #112
Too much hassle, not gonna do it (lol)
138AnonymousOct 8, 2026 21:34
Re: #112
Amazon hasn't had one yet, but Yamato Transport and Japan Post got hit too.
At this point doesn't it cover basically every Japanese person?
116AnonymousOct 8, 2026 21:29
Isn't this turning into 'cross on a red light together and it's not scary' (lol) territory?

Why's this suddenly happening everywhere?
121AnonymousOct 8, 2026 21:29
Re: #116
I bet some of these get discovered because someone thinks 'wait, aren't we in trouble too?' and goes to check.
124AnonymousOct 8, 2026 21:30
Thought this had nothing to do with me, then it turns out a service I actually use got breached too.
It's all over, man.

Background and Key Points of Debate

This breach coincides with a string of data-leak disclosures from companies throughout 2026, including Sagawa Express, Yamato Transport, Japan Post, and major karaoke chain operator Daiichikosho. Opinion in the thread split over whether the root cause is “insufficient security investment by individual companies” or “increasingly automated, sophisticated attackers.” Another point of debate was how companies handle data from closed accounts — it’s common practice for many businesses to retain data for a set period after account closure due to legal retention obligations or internal policy. This is a point users often misunderstand, assuming that closing an account makes their data vanish immediately; it’s worth noting that the risk from unauthorized access isn’t automatically eliminated just because an account has been closed.

*This article is excerpted and summarized from the 5ch (Nanndemo Jikkyo G) thread “Unauthorized Access at Lawson, 2.15 Million Leaked LOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOL.”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *