Key takeaways

  • Adventure, Inc., which runs the Japanese travel booking site skyticket, said on October 9, 2026 that attackers took customer data in three separate intrusions, each by a different route.
  • The largest, on October 2–4, exposed about 14.64 million customer records: names including passport spellings, birth dates, emails, phone numbers and addresses, plus hashed passwords for about 4.13 million members. Passport numbers were not taken.
  • A second attack, on September 20, exploited a vulnerability in a business system and exposed refund bank account details for 17,780 records.
  • A third problem left bus booking confirmation pages viewable without logging in for two months. About 12,000 bookings were scraped.
  • Card numbers and passport images were not stored, so none leaked. skyticket has suspended payment with saved cards and is asking members to change their passwords.

Three intrusions#

According to skyticket's notice:

Server intrusion Business system Bus booking pages
When October 2–4, found October 5 September 20, found September 28 August 3 to October 1, found October 1
How Some admin functions of skyticket were manipulated, giving access to other servers and data stored in the cloud A vulnerability in the business management system was exploited Booking completion pages could be opened without logging in, and were viewed mechanically
Records About 14.64 million, of which about 4.13 million include hashed passwords 17,780, including duplicates. Some records are still being counted About 12,000 bookings, plus companions
Data Name (including passport spelling), date of birth, email, phone number, postal code and address, bank transfer name, hashed password Name, phone number, refund bank account details (bank, branch, account type, number, holder). For a few, email, birth date or address Name, age, sex, birth date, email, phone, member ID, payment method and amount, bus route and booking number, and companions' names, ages and sexes

Passport numbers were confirmed not taken in the server intrusion. For the business system, skyticket says no passport number leak has been found so far but it is still checking. The bus page flaw was fixed on October 1. skyticket also found that one member's account had been taken over on September 9.

skyticket says it has blocked the access routes, addressed the vulnerabilities and reported to the Personal Information Protection Commission. On the evening of October 7, it stopped payments with saved credit cards and the option to save cards, so that hijacked accounts cannot be used to buy tickets. It began emailing affected customers on October 8, from info@skyticket.com, with subjects in both Japanese and English.

Who is affected#

skyticket compares and books flights, hotels, tours, buses, rental cars and more, mainly for travel in and from Japan. It also runs an English-language site, skyticket.com. The notice does not say whether users of the English site are included, but its notification emails are bilingual. If you have booked through skyticket in any language, assume you may be affected until you hear otherwise.

The flood of inquiries has also caused problems of its own. skyticket says its mail server is failing under the load, so booking confirmation emails are delayed or not being sent, and it warns that scammers may exploit the delay.

What we don't know yet#

skyticket has not said:

  • How attackers reached the admin functions, and why that gave access to other servers and cloud storage
  • What the vulnerability in the business system was, and whether it was in a product or its own code
  • How the passwords were hashed
  • Whether users of the English site are among the 14.64 million
  • Whether it has reported the attacks to the police

Our analysis#

Three ways in#

What stands out is not only the size but the number of routes. In a little over a month, skyticket had a scraped page that needed no login, an exploited vulnerability in a business system, a single account takeover and a large intrusion through admin functions. Each is a different kind of failure. skyticket has not said whether they are connected. In our view, taken together they point to weaknesses across the service rather than a single bug.

The largest intrusion began with admin functions being manipulated and then spread to other servers and cloud storage. That is close to what JPCERT/CC described this week: attackers abusing administrative functions and APIs that are not meant to be reachable, and then moving further in. That is our reading; skyticket has not described the method in detail.

The bus pages#

Booking confirmation pages that open without a login are one of the most basic access control flaws. Anyone who can guess or iterate the page address can read other people's bookings, and here someone did so mechanically for two months. The data, including bus routes, booking numbers and companions, is exactly what a scammer needs to make a fake "change to your booking" call convincing.

Bank details and passwords#

Two parts of this breach carry risks beyond phishing. Refund bank account details cannot be used to withdraw money on their own, as skyticket notes, but they make scams asking for PINs or banking logins far more credible. And as with Bookoff this week, skyticket says its passwords were hashed but not how. It openly warns that they could be cracked and reused, which is more candid than most notices, and is why every member should change any password they reused.

The largest disclosure of the week#

skyticket's 14.64 million records made it the largest disclosure in a week that also included Yakiniku King, Bookoff and Lawson. Our week in review covers the rest.

What this means for readers#

  • If you have a skyticket account, change your password through the official site or app, not through a link in an email. Change it anywhere else you used the same one.
  • Check your booking history and card statements for anything you did not book.
  • If you received a refund to a bank account through skyticket, be wary of anyone asking for PINs, online banking logins or "fees" for a refund or compensation. skyticket says it will never ask for these.
  • If you booked a bus through skyticket, be suspicious of calls or messages about changes to your booking. Check with the bus operator or skyticket directly.
  • Only trust emails from info@skyticket.com, and even then, do not enter passwords through links.

Japanese terms at a glance#

Japanese Reading Meaning
管理機能 kanri kinō Admin functions
業務管理システム gyōmu kanri shisutemu Business management system
返金先の口座情報 henkinsaki no kōza jōhō Bank account details for refunds
ハッシュ化 hasshuka Hashing (of passwords)
予約完了ページ yoyaku kanryō pēji Booking confirmation page
流出したおそれ ryūshutsu shita osore May have leaked