Key takeaways

  • Lawson (ローソン), one of Japan's largest convenience store chains, said on October 1, 2026 that a third party had misused its own mail server to send about 700,000 suspicious English-language emails.
  • The emails went out for about 50 hours, from Friday afternoon, September 25, to Sunday evening, September 27. Most went to addresses overseas, some to Japan.
  • This was not a fake email pretending to be from Lawson. The emails came from Lawson's real server, but the sender name was disguised as someone else, so recipients may not see any link to Lawson.
  • Lawson says it has found no leak of personal data and no intrusion into its data center. It has not said how the server was misused.

What happened#

According to Lawson's notice:

Period About 15:00, Fri Sep 25 to about 17:15, Sun Sep 27, 2026
System Lawson's mail server
Emails sent About 700,000 (estimate)
Recipients Mostly overseas addresses, some in Japan
Response Server settings changed and communications restricted on Sep 27

Lawson says it will investigate the cause and put in place permanent measures to prevent its mail server from being misused.

The emails#

The emails Lawson has identified:

  • Have the subject "Mutual Benefit" or "RE"
  • Are written in English
  • Suggest the recipient can receive money, and ask them to reply by email or provide personal information

Lawson says other versions may also have been sent. The description matches a familiar type of advance-fee scam, in which the victim is promised a large sum and then asked for personal details or "fees".

Lawson also warns that in some of the emails, the sender's address was disguised to look like it came from someone else. Recipients cannot rely on the sender display to tell whether an email is part of this incident.

Lawson asks anyone who received an unexpected English email in that period not to reply, click links, open attachments, pay money or enter personal information, and to delete it.

What Lawson says was not affected#

At the time of the notice, Lawson says it has not confirmed:

  • Any leak of personal or other data
  • Any intrusion into its data center
  • Any tampering with data
  • Any malware infection

What we don't know yet#

Lawson has not said:

  • How the third party was able to use its mail server
  • How it noticed, and why it took about two days to stop the sending
  • Whether Lawson's own emails to customers, such as app or membership messages, were affected
  • Whether it has informed the police or other authorities

What public records show#

Lawson has not said which server or domain was involved. Public DNS records show that mail for lawson.co.jp is received by servers in an IP range registered to Lawson itself, and that its SPF record authorizes Lawson's own addresses as well as Microsoft 365 and several outside email services. Which of these was misused is not known.

Our analysis#

Not a fake Lawson email, and that is the problem#

Most warnings about "Lawson emails" are about phishing that pretends to be Lawson. This is the reverse. The emails really came from Lawson's server, but did not look like Lawson.

That undermines the usual advice. "Check the sender" works against impersonation, when the sender address gives the scam away. Here, Lawson itself says the sender display was disguised and cannot be used to tell whether an email is related. For most recipients, the only safe rule is the one Lawson gives: do not reply to unexpected messages offering money, whoever they appear to come from.

Two days, over a weekend#

The sending started on a Friday afternoon and stopped on Sunday evening, about 50 hours later. At an average of roughly 14,000 emails an hour, that is far beyond the normal output of a company's mail server. Lawson has not said how it found out. But a sudden jump in outgoing mail is one of the easiest things to monitor, and weekends are when fewer people are watching.

The cost falls on others first#

No customer data is reported lost. The harm falls mostly on the people who received the emails, most of them overseas, and on Lawson's reputation. A mail server that sends spam can also end up on blocklists used by email providers, which can affect delivery of a company's legitimate messages. Lawson has not said whether that has happened.

A clear notice, with the key question open#

Lawson's notice is clear and practical: exact times, an estimated volume, the subject lines, and an honest warning that the sender display cannot be trusted. Publishing it at all helps recipients in Japan, even though most of the emails went abroad.

The gap is the cause. "No intrusion into the data center" does not explain how someone came to be sending mail through Lawson's server for two days. Until Lawson says how that happened, it is hard to judge whether the "permanent measures" it promises will close it.

What this means for readers#

  • If you received an English email with the subject "Mutual Benefit" or "RE" between September 25 and 27, 2026, especially one offering money, delete it. Do not reply or send personal details, whoever the sender appears to be.
  • Do not judge an email by its sender name. In this case it was disguised. Judge by what the email asks you to do.
  • If you run mail systems, alert on unusual outbound volume as well as inbound threats, and make sure someone sees those alerts outside office hours.

Japanese terms at a glance#

Japanese Reading Meaning
ローソン Rōson Lawson, Inc., convenience store chain
メールサーバーの不正利用 mēru sābā no fusei riyō Unauthorized use of a mail server
不審メール fushin mēru Suspicious email
送信元アドレスの偽装 sōshinmoto adoresu no gisō Disguised (spoofed) sender address
通信制限 tsūshin seigen Restriction of communications
恒久的な対策 kōkyūteki na taisaku Permanent measures

We will update this article if Lawson publishes the cause.