Key takeaways
- Bookoff Group Holdings (ブックオフグループホールディングス), which runs one of Japan's best-known chains of used book, game, music and media stores, said on October 9, 2026 that attackers took member data from a member management system run by one of its subsidiaries.
- Up to about 6.43 million member numbers are affected. Bookoff says this is the number of member numbers, not people.
- The data includes names, dates of birth, gender, email addresses, phone numbers, postal addresses, point card numbers, member numbers and password hashes. Payment data was not held in the system.
- Bookoff found the intrusion on October 6. It says it has fixed a vulnerability, cut off the attackers and blocked outside access to the system, and is running an emergency review of all its systems.
- It has seen no sign so far that the data has been published or misused.
What happened#
According to Bookoff's notice:
| Date (2026) | Event |
|---|---|
| Oct 6 (Tue) | Bookoff confirms unauthorized access to a subsidiary's member management system. Investigation finds that member data was taken from outside |
| Oct 9 | Bookoff discloses the breach |
After finding the intrusion, Bookoff says it blocked communication from the attackers, fixed the vulnerability and blocked external access to the system. The path the attackers used to take data, as far as it is known, has been contained, and monitoring continues. It is also reviewing all of its systems, from both the network and the application side, and has reported the breach to the Personal Information Protection Commission. Affected customers will be contacted individually once the investigation is complete.
Bookoff does not name the subsidiary or the service, and does not describe the vulnerability. October 6 is the date it confirmed the intrusion. It has not said when the attack began, how long the attackers had access, or how it noticed.
What was taken#
Up to about 6.43 million member numbers. Bookoff is still working out how many people this covers and what data was taken for each.
| Data | Notes |
|---|---|
| Name, date of birth, gender | |
| Email address, phone number, postal code and address | |
| Password hash | Bookoff calls it "an encrypted password that cannot be read as it is" |
| Point card number, member number |
Not taken, according to Bookoff: credit card and other payment data, which the system did not hold. It has found no changes to member data.
Who is affected#
Bookoff's member services are mainly used in Japan. The group also runs Bookoff stores in the United States, where it opened its first store in New York in 2000, and Jalan Jalan Japan stores, mainly in Malaysia and Kazakhstan. Bookoff has not said which member system was breached, so we do not know whether any members outside Japan are affected.
What we don't know yet#
Bookoff has not said:
- When the unauthorized access began, and how long it lasted before October 6
- How it detected the intrusion: an alert, unusual load, an outside report or something else
- What the vulnerability was, and whether it was in a product or in its own application
- Which subsidiary and service were affected, and whether members outside Japan are included
- How the passwords were hashed
- How many people the 6.43 million member numbers represent
Our analysis#
"Taken", not "may have leaked"#
Many Japanese breach notices say data "may have leaked". Bookoff's is more direct: its investigation found that member data was taken from outside. The 6.43 million figure is still an upper bound, because it counts member numbers, but there is no doubt about whether the theft happened.
A password hash is only as good as how it was made#
Bookoff describes the stolen passwords as hashes that "cannot be read as they are". That is true of any hash. What matters is how they were hashed. A modern, slow algorithm with a unique salt per user, such as bcrypt or Argon2, makes cracking millions of passwords expensive. A fast, unsalted hash does not: common and weak passwords can be recovered quickly. Bookoff has not said which method it used. Until it does, members should assume their password could be recovered and change it anywhere they reused it.
A vulnerability, fixed#
Unlike many notices in this autumn's run of Japanese breaches, Bookoff says plainly that it fixed a vulnerability. It does not say whether this was a flaw in a product or in its own application. JPCERT/CC warned on October 8 that attackers are scanning Japanese organizations for known vulnerabilities and abusing app APIs, and an analysis by Macnica's security research center found that most disclosures do not explain the cause. Bookoff's notice goes a step further than most, but other companies still cannot tell from it what to check.
The timing offers one clue, though it is only our inference. Bookoff confirmed the intrusion on October 6 and, by the time it disclosed it three days later, said the vulnerability had been fixed. A flaw that can be corrected that quickly may have been a known vulnerability with an available update, or a specific, contained mistake in its own code, such as a missing access check, rather than a deeper design problem. Both are among the paths JPCERT/CC says attackers are probing. It is also possible that the "fix" is a first step, and more work will follow from the emergency review.
Part of a wave#
Bookoff's disclosure came a day after Lawson (2.15 million Lawson ID accounts) and karaoke chain operator Daiichikosho (about 8.72 million records possibly exposed through a contractor's infected PC), and follows Times Car and Yakiniku King. On October 8 the Japanese government held an inter-ministerial meeting on the wave of unauthorized access, according to Japanese media.
What this means for readers#
- If you are a Bookoff member, change your password if you used the same one anywhere else, starting with email, shopping and banking accounts.
- Expect convincing phishing. The stolen data includes your name, address, date of birth and phone number. Bookoff says it will never ask for passwords, verification codes, card details or bank details by email, SMS or phone.
- Wait for Bookoff's individual notice to learn what was taken for your account. It says it will contact affected members after its investigation.
- If you run a member system, check how your passwords are stored. If they are not hashed with a slow, salted algorithm, a breach of the database will expose many of them.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| 会員管理システム | kaiin kanri shisutemu | Member management system |
| 外部から取得された | gaibu kara shutoku sareta | Taken from outside |
| パスワードのハッシュ値 | pasuwādo no hasshu-chi | Password hash |
| 脆弱性を是正 | zeijakusei o zesei | Fix a vulnerability |
| 緊急総点検 | kinkyū sōtenken | Emergency review of all systems |
| 適時開示 | tekiji kaiji | Timely disclosure to the stock exchange |