On October 6, Mr. Max Holdings disclosed that intruders hit the servers behind its MrMax app and online store, and up to 1,735,154 members' personal data may have leaked. You signed up for discount coupons. I run AliasFleet: one unique email address per site, so when the store app gets breached, the address in the stolen file belongs to that store alone.
There is a particular sting to this one. The MrMax app exists so shoppers can clip digital coupons at a discount store chain in Fukuoka and beyond. The registration form asks for the usual details and you give them without thinking, because a discount store feels harmless. Now the names, email addresses and phone numbers of up to 1.7 million people may be in play, and there is no "change password and move on" fix. No passwords were stolen. Nothing was stolen that you can reset.
What is in the file, and what is not
| May have leaked | Confirmed not leaked |
|---|---|
| Member ID | Home address |
| Name | Date of birth |
| Email address | Credit card information |
| Phone number | Password |
| Purchase history |
The company's phrasing is "possibility of leakage" for the first column and explicit confirmation for the second. Treat the maximum as the working number: the attacker reached the member servers and the investigation confirmed the intrusion, so the four fields above are the set to assume exposed. Fields vary by how each person registered, so not every row holds all four.
Two details in that table matter. First, the member ID. The file also ties each row to an account, not just a contact. That makes targeted social engineering cheaper: a message that greets you by member ID is not obviously fake.
Second, the confirmed-absent column. Mr. Max deserves credit for saying exactly what was not taken instead of hiding behind "we are still investigating". Address, date of birth, cards, passwords, purchase history: all confirmed out of the file. That is an unusually clean statement three days after detection, and it narrows the damage to one thing: the contact set. Which happens to be the exact set a phishing operation runs on.
Three days from detection to disclosure
The timeline is the best part of this story. The company found suspicious access on the evening of October 3, suspended the app and store immediately, and blocked external access the same day. It then brought in an external specialist, reported to Japan's Personal Information Protection Commission, and went public on October 6.
That is about as fast as retail breach disclosure gets. Compare it with the industry habit of "we became aware several weeks ago" buried in paragraph four. Mr. Max also did the two things that matter in the first 72 hours: it told the regulator and it started emailing affected members individually.
One awkward note in the middle of all that: the company is notifying victims by email. Email, the very channel the attacker will now use to impersonate the company. Mr. Max knows this; the announcement says it will never ask for passwords or credit card information by email or phone, so any message asking for them is not from them. Read that sentence again before you click anything that claims to be a breach notification. It is also the honest case for never giving a store your real address: when the genuine notification and the phishing arrive in the same week, the only safe way to tell them apart is the address in the To field.
The coupon-app bargain
I have now covered four Japanese consumer-app breaches in a week: Monogatari's 10.79 million Yakiniku King records, Daiki Suisan's 174,933 sushi app users, GMO infoQ's 948,498 survey members, and now this. The pattern is no longer subtle.
Loyalty apps collect identity data as a side effect of handing out discounts. You cannot get the member price without the member account, and the member account needs an email, a name and a phone number. The bargain looks fair at the register. It looks different when the server is breached and the contact set walks out the door.
Here is the part that bothers me. The company did nothing obviously wrong here that I can see: it detected the intrusion the same evening, shut the service down, and disclosed in three days. The problem is structural, not careless. Any database of 1.7 million contact rows is a target worth hitting, and every retail app in the country holds one. You can do everything right as a customer, pick a careful company, and still end up in a stolen file. That is the uncomfortable truth of this week's cluster, and it is why "trust the company" is not a plan.
If you are a Mr. Max member
If you have used that email address for years, of course this feels bad. None of this is your fault. Here is what to do.
- Expect the phishing first, because the company says no misuse has been confirmed yet, but a file of names, emails and phone numbers is built for spoofed messages, and Mr. Max is warning about spoofing and phishing specifically. Anything that asks for a password or card details "because of the breach" is a scam; the company says it will never ask for those by email or phone.
- Verify the notification, do not click it. If an email arrives claiming to be Mr. Max, go to the company's own site or reopen the app yourself. Do not follow links in the message.
- Watch the phone too. The file has phone numbers, so expect suspicious calls and texts, not just email. Hang up on unsolicited calls about your data and call the company's official number back yourself.
- Lock down your inbox anyway. Your email address is in this file, and your inbox is the recovery route into everything else you own. Turn on multifactor authentication if you have not.
- Check Have I Been Pwned once the breach is listed. It is the canonical place to see which of your addresses have leaked and where.
The breach-response guide has it all in order.
The address that names its source
Here is the practical version of the whole argument. If you had signed up for the MrMax app with an address used only for MrMax, the email address in the stolen file is a fingerprint: every phishing message that lands on it in the coming weeks is, by definition, either from MrMax or from whoever stole that file. Pause or delete that alias and the entire attack channel dies, while your real inbox stays clean.
That is the leak-tracing mechanism working as designed: the address itself tells you which company leaked it. No forensics needed. If you have never used one: this is what an email alias is, and the set-up guide takes about two minutes.
Three questions that decide how bad this gets
First, the intrusion route. Mr. Max says an external specialist is investigating, and the cause matters because the same server pattern may sit behind other retail apps. Second, whether the "up to" number narrows or grows as the forensic picture completes; the company was honest about the confirmed-absent fields, so I expect the same honesty on the scope. Third, whether the file surfaces anywhere public, which would move this from a contained intrusion to a circulating dataset. If any of those break, this piece gets updated.
One thing I keep coming back to: 1.7 million people gave a discount store their contact details for cheaper groceries, and three days after detection the company had done everything right. The file may still be out there. Speed and honesty from the company help, but they do not delete the copy. Only giving out an address you can kill does that.
Top comments (0)