Key takeaways
- Lawson (ローソン), one of Japan's largest convenience store chains, said on October 8, 2026 that attackers took personal data tied to 2,155,345 accounts of Lawson ID, the account service used for its apps and web services.
- The data includes email addresses and names, and, for users who had entered them, for example to enter prize draws, gender, phone numbers, addresses and newsletter settings.
- A separate intrusion into Lawson App Reservation, a pre-order service in the app, exposed the names, phone numbers and part of the credit card numbers of 26 users.
- The access took place on September 12–14 and September 17, but Lawson only found it on October 7, more than three weeks later.
- Lawson says a mechanism its app uses to show users their own information was accessed without authorization. It has not explained further.
What happened#
According to Lawson:
| Date (2026) | Event |
|---|---|
| Sep 12 (Sat) to Sep 14 (Mon) | Unauthorized access to Lawson ID |
| Sep 17 (Thu) | Unauthorized access to Lawson App Reservation |
| Oct 7 | An investigation finds both intrusions |
| Oct 8 | Lawson discloses the breach |
Lawson has blocked the suspicious sources of access, suspended App Reservation until mid-October, posted a notice in its app and begun emailing affected users individually. It has reported the breach to the Personal Information Protection Commission and other relevant bodies. It says it has found no misuse of the data so far, and no other unauthorized access or malware infection.
Lawson has not said what prompted the October 7 investigation.
What was taken#
Lawson ID: 2,155,345 accounts
| Data | Notes |
|---|---|
| Email address, name | |
| Gender, phone number, address, newsletter settings | Only where the user had entered them, for example to enter a prize draw |
Lawson App Reservation: 26 users
| Data | Notes |
|---|---|
| Name, phone number | |
| Part of the credit card number |
Lawson does not mention passwords or full card numbers among the leaked data.
How it happened: what Lawson says#
Lawson's explanation is brief. It says the breach is believed to have been caused by misuse of a system related to the Lawson app, and that:
a security mechanism originally intended to display information to the user themselves in the app was accessed without authorization by a third party, and information was leaked.
It does not say what that mechanism is, how it was bypassed, or whether the flaw has been fixed. Its stated measures are general: stronger security and monitoring for the system, and a stronger incident response setup.
Our analysis#
What the "security mechanism" may mean#
This is our interpretation, not something Lawson has said. When an app shows a member their own profile, it typically asks a server, through an API, for that member's data. The server is supposed to check that the request really comes from that member before answering. If that check can be bypassed, for example by changing the member ID in a request or by obtaining tokens that the server accepts, an attacker can ask for other members' data one by one, at scale.
If that is what Lawson means, this breach fits the pattern that JPCERT/CC warned about on October 8: attackers analyzing public smartphone apps and abusing their APIs. It would also match the API abuse case the privacy regulator added to its list of breach patterns a day earlier. Other readings are possible, such as stolen API keys or a flaw in how login tokens are issued. Lawson's description would fit several of them, and that is the problem: it does not tell other companies what to check.
Three weeks unnoticed#
The intrusions took place in mid-September and were found on October 7. Lawson has not said what led to the discovery. Lawson has not described how it monitors the system. But data on more than two million accounts was taken over three days and not noticed for weeks, which raises the question of whether unusual volumes of requests were being watched for. Rate limits and monitoring of that kind are among the first defenses JPCERT/CC recommends.
Two incidents, one month#
This is Lawson's second security disclosure this month. On October 1, it said its own mail server had been misused to send about 700,000 scam emails on September 25–27, and that it had found no data leak. The October 8 notice does not mention the mail server incident, and Lawson has not suggested any connection between them. It says it has confirmed there was no unauthorized access other than the one now disclosed.
Part of a wave#
Lawson joins Times Car, Yakiniku King, Seicomart and others in a run of large breaches of consumer apps and member services in Japan this autumn. On the same day, karaoke chain operator Daiichikosho said data on about 8.72 million customers may have leaked after malware infected a contractor employee's device, and Uzabase, operator of the news app NewsPicks, disclosed a possible leak, according to Kyodo News. The government held its first inter-ministerial meeting on the wave of unauthorized access the same day, ITmedia reported, with the minister in charge of cybersecurity calling the situation "very urgent".
What this means for readers#
- If you have a Lawson ID, check for an email from lawson_id@mailservice.lawson.jp. Lawson says it is contacting affected users from that address.
- Expect targeted phishing. Messages that use your real name and know you shop at Lawson will look convincing. Do not follow links in unexpected messages about this incident; go to the Lawson app or website directly.
- If you used Lawson App Reservation, check your card statements. Only part of the card number was taken, but combined with your name and phone number it can make scam calls more convincing.
- If you run an app with member accounts, check that every API that returns personal data verifies, on the server, that the requester is allowed to see that specific record, and that unusual request volumes trigger an alert.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| ローソンID | Rōson ID | Lawson's account service for its apps and web services |
| ローソンアプリ予約 | Rōson apuri yoyaku | Pre-order service in the Lawson app |
| 不正アクセス | fusei akusesu | Unauthorized access |
| 個人情報漏えい | kojin jōhō rōei | Personal data leak |
| セキュリティ機構 | sekyuriti kikō | Security mechanism |
| 二次被害 | niji higai | Secondary damage, such as fraud using leaked data |