Key takeaways
- Moonstar (ムーンスター), a long-established Japanese shoemaker, said on October 2, 2026 that customer data from its online store may have leaked after attackers logged in to one of its servers.
- It is the follow-up to a notice in March 2026, when Moonstar said it suspected unauthorized access but had found no sign that customer data was taken.
- The data at risk: names, addresses, phone numbers, email addresses and past orders. Card numbers and passwords were not stored on the server.
- Phishing emails impersonating Moonstar have already reached some customers, the company says.
What happened#
| Date (2026) | Event |
|---|---|
| Mar 26 | Moonstar announces suspected unauthorized access to some of its servers. It says it has not confirmed that any customer data was taken, and that the investigation continues |
| Oct 2 | Moonstar says its investigation found that attackers may have logged in to a system server and obtained data. Online store customers' data may have leaked. Phishing emails impersonating the company have reached some customers |
Moonstar says it has cut the server's external connections, forced password changes, and is working with outside specialists on a detailed technical investigation. It also plans vulnerability fixes, layered defenses, a review of internal rules on personal data and staff training.
What may have been exposed#
| Data | Status |
|---|---|
| Name, address, phone number, email address | May have leaked |
| Past order history | May have leaked |
| Credit card numbers, passwords | Not stored on the affected server |
Who is affected: customers who have used Moonstar's online store. Moonstar has not given a number.
Moonstar says it has not found the data published anywhere. But it has confirmed that phishing emails pretending to come from Moonstar have been sent to some customers.
What we don't know yet#
Moonstar has not said:
- How many customers are affected
- When the phishing emails started, and whether they are what led it to revise its March assessment
- Why it took six months to conclude that data may have been taken
- How the attackers logged in, and whether the access continued after March
- Whether it has reported the incident to the Personal Information Protection Commission or the police
Our analysis#
"Not confirmed" was not "did not happen"#
In March, Moonstar said it had not confirmed that customer data was taken. That was technically true. Six months later, the company says data may have been taken after all, and scammers are already using it.
This is the same lesson as ABAHOUSE, where customers' reports of scam emails exposed a breach the company had not noticed. A phrase like "no leak has been confirmed" in an early notice describes the state of the investigation, not the state of the data. Readers, and the customers named in the data, should treat it that way, especially when the investigation is still running.
Six months without a warning#
The cost of the March wording falls on customers. For six months, the official position was that no customer data had been found to be taken. Customers had no reason to be suspicious of emails that appeared to come from Moonstar. By the time the company told them to be careful, phishing emails were already in their inboxes.
A company does not need to be certain of a leak to warn customers to be careful. Moonstar could have said in March what it says now: that its name may be used in phishing emails, and that it will never ask for passwords or card details. Advice like that costs little and protects people while the investigation runs.
Order history again#
As with ABAHOUSE and Yamato's pay-later service, the data includes past orders, the detail that makes a fake "order problem" or "refund" email convincing. Three Japanese consumer businesses in one week have now reported possible leaks of order data, alongside contact details.
What this means for readers#
- If you have bought from Moonstar's online store, assume your name, address, contact details and order history may be in the hands of scammers.
- Be suspicious of emails, texts and calls that claim to be from Moonstar, especially ones about orders, refunds or account problems. Moonstar says it will never ask for passwords or card details. Contact the company through its customer center instead: 0800-800-1792 (weekdays 10:00–17:00) or cs@moonstar.co.jp.
- If you reused your Moonstar password elsewhere, change it there. Moonstar says passwords were not on the affected server and has forced password changes, but the change is a good habit after any breach.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| ムーンスター | Mūnsutā | Moonstar Co., Ltd., shoemaker |
| 不正アクセスの疑い | fusei akusesu no utagai | Suspected unauthorized access |
| 確認されておりません | kakunin sarete orimasen | "Has not been confirmed" |
| なりすましメール | narisumashi mēru | Impersonation email |
| パスワードの強制変更 | pasuwādo no kyōsei henkō | Forced password change |
We will update this article if Moonstar publishes the number of people affected or more about the cause.