From our other sites
The story
On October 8, convenience store giant Lawson announced that unauthorized access to its membership service “Lawson ID” had exposed the personal information of approximately 2,155,000 users. It marks a large-scale breach targeting the membership base of a major convenience store chain. On 5ch forums, users voiced frustration that companies aren’t investing enough in security, while others pointed out links to a string of recent breach disclosures at companies like Sagawa Express, Yamato Transport, and Japan Post. The thread was also abuzz with surprise that companies keep holding onto user data even after accounts are closed, as well as questions about the government’s response — with opinions split over whether the root cause is poor corporate security or increasingly sophisticated attackers.
Lawson announced on the 8th that its account service “Lawson ID” had suffered unauthorized access, leaking users’ personal information. The number of people affected totals approximately 2.155 million.
Source: news.yahoo.co.jp / Original article here
What people said
That's because they're deliberately leaking the info to foreign countr—
oh, someone's at the door, gotta go
And include both the discovery date and the announcement date.
This is clearly a cyberattack on our country.
Yeah, because the head of the Digital Agency said everyone should protect their own personal information themselves.
There's probably more investigation requests coming in than existing security firms can even handle.
The moment you leak something, you get hit with a massive damages payout.
Don't go blaming AI for it.
'Now's the time!' (lol), right?
That's actually true — some companies are only disclosing now something that happened last year.
I've been deleting all my unnecessary accounts like crazy.
Company: 'Even if your account's deleted, we're keeping your data on our servers anyway!'
This is still just phase one.
Next they'll be breaching infrastructure and government agencies too.
It doesn't get deleted from the company's servers, so deleting your account is pointless.
I closed my account back in July.
Since when did you think closing your account meant your data gets completely deleted?
Are they running automated AI attacks or something?
Well yeah, if there are tens of thousands of AI agents running attacks, it's game over.
I work in systems administration, and honestly if someone got in and just quietly siphoned data out, there's no way I'd notice.
Honestly I think they're doing well to disclose it at all — though being a big company, they probably couldn't hide it anyway.
Just noticing the breach at all is already commendable.
Asahi Shimbun @asahi (2026/10/08 20:16:04)
Daiichikosho, operator of karaoke chain "Big Echo," may have leaked 8.72 million pieces of personal information https://www.asahi.com/articles/ASVB83K0SVB8ULFA02WM.html
https://ohayua.cyou/card_img/2108154458291220480/BauPMuxg.jpg#.jpg
https://x.com/asahi/status/2108154454721851711
Lawson hasn't said a word, and neither has Sagawa.
I'll just send it with everyone CC'd, that okay?
Too much hassle, not gonna do it (lol)
Amazon hasn't had one yet, but Yamato Transport and Japan Post got hit too.
At this point doesn't it cover basically every Japanese person?
Why's this suddenly happening everywhere?
I bet some of these get discovered because someone thinks 'wait, aren't we in trouble too?' and goes to check.
Background and Key Points of Debate
This breach coincides with a string of data-leak disclosures from companies throughout 2026, including Sagawa Express, Yamato Transport, Japan Post, and major karaoke chain operator Daiichikosho. Opinion in the thread split over whether the root cause is “insufficient security investment by individual companies” or “increasingly automated, sophisticated attackers.” Another point of debate was how companies handle data from closed accounts — it’s common practice for many businesses to retain data for a set period after account closure due to legal retention obligations or internal policy. This is a point users often misunderstand, assuming that closing an account makes their data vanish immediately; it’s worth noting that the risk from unauthorized access isn’t automatically eliminated just because an account has been closed.
*This article is excerpted and summarized from the 5ch (Nanndemo Jikkyo G) thread “Unauthorized Access at Lawson, 2.15 Million Leaked LOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOLOL.”

Leave a Reply