Yellow Hat Confirms 3.18 Million Records Leaked in 2rinkan Cyberattack
Yellow Hat (TYO:9882) confirmed that a cyberattack leaked personal data of about 3.18 million 2rinkan members, down from an earlier 3.46 million estimate following a forensic investigation.The attacker exploited API calls from the 2rinkan mobile app to access customer data from the web server. Name, address, phone number, date of birth, gender, email address, membership number, app user ID, app password, point balance and vehicle information was compromised. However, credit card data remained secure as it is managed on an external system.No traces of intrusion were found on other servers, and customers of Yellow Hat's other brands are unaffected.The company is reviewing security structures, enhancing API controls, and strengthening unauthorized access monitoring, with the 2rinkan app expected to resume around October.