Key takeaways
- ABAHOUSE International (アバハウスインターナショナル), the Japanese fashion company behind the ABAHOUSE brand, said on October 2, 2026 that attackers broke into its systems and accessed the database holding member and online order data.
- It may cover every customer in the database, including former members: names, addresses, phone numbers, email addresses, dates of birth and order details. Card data is held by its payment processor and has not been found to be leaked.
- The company learned of the breach because several customers reported scam "refund" emails that matched their real orders, within a day of the intrusion.
- The attackers had turned the data into scams before the company knew it had been breached.
What happened#
According to ABAHOUSE's notice:
| Date (2026) | Event |
|---|---|
| Sep 27, late night, to Sep 28 | Unauthorized access to internal systems, by the company's estimate |
| Sep 28 | Several customers ask about suspicious refund emails that match their order information. ABAHOUSE investigates and finds traces of access to member and order data |
| Oct 2 | ABAHOUSE emails all customers who may be affected, including former members, and publishes its notice |
The company says the attackers logged in to an internal system without authorization, exploited a flaw in the system to install and run a malicious program, and used it to reach the database holding member and online order data. It says the access route it has found is blocked. It has reported the incident to the Personal Information Protection Commission.
What may have been exposed#
| Data | Status |
|---|---|
| Member ID, name, address, phone number, email address, date of birth, gender | May have leaked |
| Order details: date and time, item, amount, delivery address | May have leaked |
| Credit card number and security code | Held by the payment processor, not by ABAHOUSE. No leak found |
Because the attackers may have accessed the whole database, and the company cannot tell exactly what was taken, it is treating all customers whose member data it holds as potentially affected. That includes former members, because their past orders were still kept as order data. ABAHOUSE has not given a number.
The scam emails#
ABAHOUSE describes the fake emails in detail. They use pretexts such as a refund or an item being out of stock, and may include real order details. Warning signs it lists:
- Sent from an address unrelated to the company, such as a free email account
- Asking the customer to get in touch through an "official LINE" account
- Setting a deadline, such as "by next Wednesday", to rush the customer
The company asks customers not to use links or contact details in such emails, to check orders through My Page or its support center, and never to enter passwords or card details through a link. It also recommends changing the ABAHOUSE Members Club password and checking card statements.
What we don't know yet#
ABAHOUSE has not said:
- How many customers are affected
- How the attackers obtained the login to its internal system
- What the flaw they exploited was, and whether it has been fixed
- How many customers have received scam emails, and whether any have lost money
- Whether it has reported the incident to the police
Our analysis#
"No misuse confirmed" means nobody has complained yet#
Japanese breach notices very often include the same line: no misuse or secondary harm has been confirmed "at this time". This week alone, Dai-ichi Life, Benefit One and Nippon Rent-A-Car all said so.
ABAHOUSE shows what that line usually means in practice. Here, misuse was not a later risk. It was how the breach was discovered. Customers started receiving scam emails quoting their real orders, reported them, and only then did the company find the intrusion. If those customers had not reported the emails, or had simply deleted them, ABAHOUSE might still not know.
Companies rarely have a way to see misuse of leaked data directly. They learn about it when customers complain, banks report fraud, or the data appears for sale. "No misuse confirmed" usually means no one has reported any yet, not that none has happened. Readers should treat the line in other notices with that in mind.
Hours, not weeks#
By the company's estimate, the intrusion happened late on September 27 into the 28th, and customers were reporting scam emails on the 28th. The attackers turned stolen order data into scam emails within about a day. The usual assumption, that leaked data is sold on and misused weeks or months later, does not hold here. For anyone whose data was in this database, the scams have already started.
Order data is what makes the scam work#
A phishing email that says "your order has a problem" is easy to ignore when you have no order. One that names the item you actually bought, on the date you bought it, for the amount you paid, and offers a refund, is not. Order history, not just names and addresses, is what turned this breach into a working scam immediately. It is the same risk we described for Yamato's pay-later service, where item details and amounts may also have leaked.
A candid notice#
ABAHOUSE's notice deserves credit. It says plainly that the whole database may have been accessed, treats every customer as potentially affected rather than waiting for a count, notifies former members too, describes the scam emails with concrete warning signs, and gives the public consumer and police hotlines. It does not claim that no misuse has been found, because it cannot. That is more honest than a notice that leads with reassurance.
What this means for readers#
- If you have ever bought from ABAHOUSE's online store or registered as a member, including if you later left, assume your details and order history may be in the hands of scammers.
- Do not trust refund or out-of-stock emails, even if they show your real order. Check through My Page or the support center, and never move the conversation to LINE.
- Change your ABAHOUSE Members Club password, and any other account where you used the same password. Check your card statements.
- If you have already clicked or paid, contact your card company or bank immediately. In Japan, you can also call the police consultation line #9110 or the consumer hotline 188.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| アバハウスインターナショナル | Abahausu Intānashonaru | ABAHOUSE International Co., Ltd. |
| 不審な返金案内メール | fushin na henkin annai mēru | Suspicious refund notice email |
| 欠品 | keppin | Out of stock |
| 受注情報 | juchū jōhō | Order data |
| 二次被害は確認されていない | niji higai wa kakunin sarete inai | "No secondary harm has been confirmed" |
| 本人通知 | honnin tsūchi | Notification to the affected person (under Japan's privacy law) |
We will update this article if ABAHOUSE publishes the number of people affected or more about the cause.