DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

174,933 Daiki Suisan App Users' Emails Possibly Exposed in Breach

You signed up for the coupons. On October 5, Daiki Suisan announced its sushi-chain app was hit by unauthorized access, and 174,933 users may have lost names, phone numbers and email addresses. I run AliasFleet, an email-alias service where every site gets its own address, so one leak stays there.

Daiki Suisan runs about 80 conveyor-belt sushi shops and fresh fish stores across the Kansai region. Its official app handles reservations, coupons and points, the kind of app you install once for a discount and forget about. Everyone who registered between November 2024 and September 2026 is in the file, including people who already quit. Quitting did not delete you.

The server that held the coupon list

May have leaked Not included
Name Password (kept on a separate server)
Email address
Phone number
Gender
Postal code and address (optional registration, not everyone)
Date of birth (optional registration, not everyone)

The split that matters: no passwords, so there is no credential-stuffing wave coming from this file. But names, emails, phone numbers and addresses are the complete kit for phishing, smishing and impersonation calls. The company is already warning customers about suspicious mail, texts and calls, which tells you what it expects next.

Found September 15, announced October 5

The unauthorized access was confirmed on September 15. The public announcement came on October 5, twenty days later. The company says it tightened security measures and monitoring, and brought in an outside specialist to investigate.

I cannot tell from the reporting whether those twenty days were investigation or deliberation. Both happen. I would rather see the first, but twenty days is a long time for 174,933 email addresses to sit in someone else's hands while their owners hear nothing.

As of the announcement, the company has confirmed no actual external leak and no misuse of the data. That is a point-in-time statement, not a clean bill of health. It means the file may exist and its future is unknown.

Japan is having a terrible week for customer databases

Daiki Suisan is not an isolated story. It is one of several Japanese customer-data incidents to surface within days. Monogatari lost 10.79 million Yakiniku King app member records to an intruder in its member system. Daiwa Securities says a vendor's server may have exposed data on 110,000 brokerage clients. Seicomart confirmed 572,022 convenience-store app members had their data viewed by a third party, and Osaka Metropolitan University disclosed a ransomware attack that may have exposed 130,000 people's records. Same week, same target shape.

Notice what the attackers are not hitting: not the trading engine or the payment vault, but the reservation app, the inquiry-management server, the member database. The systems that hold everyone's contact details on a fraction of the security budget.

The harmless signup is the dangerous one

Here is the part that should bother you. Nobody hands their real email to a sushi app after careful thought. You hand it over because the coupon is right there and the form is one screen. That thoughtless handover is the entire business model of the breach file. Attackers do not need your bank. They need the hundred casual signups where you typed your real address without thinking, and now every one of those is a phishing list with your name on it.

Daiki Suisan kept the data of people who already quit the app. Deleting the app did not delete you. The only handover you control is the address you give out. Everything after that is their security, not yours.

If you registered on the Daiki Suisan app

  1. Expect phishing. Any message about this breach that asks you to click a link or hand over a code is suspect, and the company says it will never ask you for passwords or authentication codes. Anyone who does is not the company.
  2. Do not trust the sender name. The file has real names and real phone numbers, so the fakes will look personal. Open the app or the company's site yourself instead of clicking through.
  3. Turn on multifactor authentication on your email account. Your email is the recovery address for everything else you own, and it is in this file.
  4. Check Have I Been Pwned once the breach is listed. It is the canonical place to see which of your addresses have leaked and where.
  5. You do not need to change your password because of this one; passwords were on a separate server and were not in the file. But change it if you reused it elsewhere. That is a different problem.

The breach-response guide has the full checklist in order.

Hand the next coupon app a different address

You cannot un-leak this file. What you can do is make the next one useless: give every app, shop and forum its own email alias. When the next coupon app gets opened up, the address in the file belongs to that app alone. Pause it and the phishing dies. Your real address never appears, because you never handed it out. The address itself names the source, which is the leak-tracing mechanism working exactly as designed.

If you have never used one: this is what an email alias is. The set-up guide takes about two minutes.

One open question

Twenty days passed between discovery and disclosure, and the company has not said why. I will not guess. But 174,933 people spent three weeks reachable at email addresses that may have been in someone else's hands. If an incident response plan needs three weeks to write a notice, the plan is the vulnerability.

Watch for phishing posing as Daiki Suisan. I will update this piece if the investigation publishes more.

Top comments (0)