From our other sites
The story
On October 4, 2026, a post appeared on a cybercrime forum claiming to be “selling approximately 101 million Rakuten member records for $700.” The sample data reportedly includes names, email addresses, home addresses, dates of birth, and Rakuten Point balances, but the source of the leak and the authenticity of the data remain unverified. On 5ch, the thread lit up with a mix of reactions — shock that the number approaches the size of Japan’s entire population, calm reminders of past phishing attacks targeting Rakuten, and debates about the limits of password-based authentication.
Hacker Claims to Be Selling Personal Data on 101 Million Rakuten Members — Sample Includes Name, Address, and Point Balance Info; Source and Authenticity Unverified
On October 4, 2026, a post titled “SELLING Rakuten Japan 101M” appeared on a cybercrime forum, offering for sale approximately 101 million records described as Rakuten member data.
The seller describes the data as a “rakuten.co.jp database,” listing the total record count as “101M” and the price as $700. The post includes several sample lines of data containing names, email addresses, phone numbers, home addresses, dates of birth, membership rank, Rakuten Point balances, and last login timestamps.
Source: rocket-boys.co.jp / Original article here
What people said
Sucks to be you guys 😂😂😂😂
You still handed over your personal info applying, so you're screwed too
Heard you can get approved even writing "sniper" in the occupation field
Quit writing garbage clickbait articles off unverified leaks
The fact-check-free trash media (masugomi) strikes again lol
But if Amazon ("Ama") gets hit too, I'll never be able to get married (´・ω・`)
Come on over, I'll take real good care of you~
The ID-and-password era is officially dead.
Yep, the era of text passwords being useless is here.
Came faster than expected, but it was bound to happen sooner or later.
A data leak barely surprises me at this point.
That one was a phishing scam, so plenty of other companies got hit too, not just Rakuten.
Feels like after that they bolted on biometric auth, two-factor auth, email alerts, then yet another layer of authentication on top.
Keep slacking off like that and the tokuryu (loosely organized scam crews recruited online) will come for you!
Even so, apparently it's way worse overseas.
Now I'm worried about Amazon.
Though it might be game over for all the smug cashless-payment show-offs.
Banks will get hit eventually too.
Mine's linked, but I've got biometric auth on everything so I don't think it can actually be used.
Plus I basically only use my bank account for automatic debits anyway, and I've set my daily withdrawal and transfer limits to the bare minimum.
Same thought lol
like, if only they'd wipe my debt clean.
Though surely that count is padded with a ton of duplicate accounts.
Foreign residents living in Japan can sign up too, you know.
Let's just go back to the Showa era.
That era was full of scams too, you know.
Switching back to paper forms would cut down on data leaks too.
Everything's optimized for offense these days.
Even US news coverage is all about the attacks, never the defense.
Big companies hold way more data, so the damage ends up bigger when they get hit.
Maybe they're just better at defending themselves? 🥺
Unlike Japanese companies, they actually take security seriously.
I mean, Japan can't even handle My Number (the national ID system) properly — that's hilarious lmao
That's probably counting duplicate sign-ups.
Most Rakuten members are Japanese, so if data on just over 100 million people got taken out of Japan's population of 120 million, that basically means most of the country's info is out there.
Background and Key Points of the Discussion
Posts advertising “data for sale” on cybercrime forums commonly inflate record counts and prices to lure buyers, so even if the sample rows turn out to be genuine, the authenticity and origin of the full dataset are a separate issue. The article makes no mention of any official breach disclosure from Rakuten, and the thread repeatedly circled back to the premise that “the source and authenticity remain unverified.” The figure of 101 million roughly matches Japan’s population of about 120 million, but as commenters noted, the total likely includes duplicate sign-ups from the same person as well as foreign residents, so reading it simply as “almost every citizen’s data was leaked” would be premature. Rakuten has also previously made headlines over phishing attacks targeting brokerage accounts — but that involved scammers tricking users into entering their own information on fake sites, not unauthorized access, a distinction that’s easy to confuse with this latest sales claim.
*This article is excerpted and summarized from the 5ch (News Speed+) thread “Hacker Claims to Be Selling Personal Data on 101 Million Rakuten Members — Sample Includes Name, Address, and Point Balance Info; Source and Authenticity Unverified.”
Leave a Reply