DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Bookoff Confirms Data Breach Affecting Up to 6.43M Members

Bookoff Group Holdings confirmed on Friday that a subsidiary's member-management system was hit, and up to 6.43 million member records may have been taken. I run AliasFleet, an email-alias service: one forwarding address per site, so a leak names its source. A bookstore loyalty card is the inbox nobody protects. The email address you handed Bookoff for points on a used book is the one field in that file you could have made expendable.

What Bookoff confirmed

The disclosure came on 9 October, reported by NHK and the Kyodo wire via Saga Shimbun. Bookoff Group Holdings (TSE Prime 9278, Japan's largest second-hand book chain) says an unauthorised third party accessed a subsidiary's member-management system and obtained member data from it. Detection was 6 October. The notice gives no intrusion window: how long the access ran before anyone noticed is unstated.

Confirmed Still unconfirmed
The disclosure: Bookoff announced it itself on 9 October; detection was 6 October The attack vector into the subsidiary's member system
Up to ~6.43 million member-number records at risk. The notice's own footnote says this counts member numbers, not unique people How many unique individuals those member numbers belong to
Exposed fields: names, birthdates, gender, email addresses, phone numbers, postal addresses, hashed passwords, point-card numbers, member numbers (Bookoff's official notice, 9 October) The final affected count; the notice says the population is still being narrowed down
Passwords were hashed, not plaintext; the notice says they cannot be read as-is Which subsidiary was hit; the notice says only "a subsidiary"
No credit card or payment data: the system never held it Whether the dataset has surfaced publicly or been traded
No confirmed public posting of the data and no confirmed misuse as of disclosure How the system was reached and whether other systems are affected

Bookoff says it cut the attacker's communications, fixed the vulnerability, and blocked external access to the affected system. A full emergency inspection of all systems is underway, and the company is reporting to Japan's Personal Information Protection Commission. The services named in the notice: the Bookoff official site and app, the online store, Bookoff Online, the Hugall member service, and Bookoff U.S.A. member services.

The notice closes the way these notices always close:

「お客様には多大なるご心配とご迷惑をおかけしておりますことを、深くおわび申し上げます。」

"We deeply apologise for the great worry and trouble caused to our customers," Bookoff Group Holdings' official notice, 9 October 2026.

Keep that apology in mind. The forgeries will quote it too.

Four loyalty breaches in three days

This is the fourth consumer loyalty breach in Japan this week. Lawson confirmed 2.15 million member records on 8 October, Daiichi Kosho disclosed up to 8.72 million karaoke member records the same day, and NewsPicks followed hours later. Bookoff's 6.43 million makes four disclosures in three days. Every one of them hit the same kind of data.

The signup is always the same. You hand over your real email for a discount, the account sits for years, and one day it turns out that file held your name, your birthdate, your phone number, your address. Nobody interrogates a loyalty programme's security before signing up. The attackers do.

The fields repeat because the playbook repeats. Names, birthdates, emails, phones, addresses: the standard kit for voice and SMS fraud. The passwords are hashed this time. Better than plaintext, not a reason to relax. Attackers pair leaked emails with passwords from other breaches, so if your Bookoff password matches anything else you use, that other account is the weak one now.

The one field in this file you could have made expendable

You cannot change your name, your birthdate, or your phone number. They are fixed. The email address you gave Bookoff was a choice, and it is the only field in the leaked record you could have rendered useless to the attacker.

A dedicated email alias for the Bookoff signup changes the shape of this breach completely. Every message on that alias is either from Bookoff or from whoever stole the file. No third option. A "breach notification" arriving on an address nobody but Bookoff ever had, quoting the real apology and asking for your password or card details, identifies itself as the forgery on arrival. The real Bookoff would never email you for data it already holds. Kill the alias and the impersonation channel dies with it. That is the leak-tracing mechanism aimed at exactly this attack. The set-up guide takes about two minutes.

Loyalty signups are the addresses you were always going to lose. Bookoff, Lawson, Big Echo. Same casual signup. Same email.

The phishing wave reads the notice too

Bookoff's notice tells victims exactly what is coming: messages impersonating the Bookoff group or related companies. The company says it never asks for passwords, verification codes, or card and bank details by mail, SMS or phone. So the forgeries will ask for exactly those things. Same apology, same wording, different URL.

If you have used the same email for Bookoff for years, this feels personal, not technical. Of course it does. That is what makes the impersonation work: the email that knows your member number sounds like it knows you. It does not know you. It has the file.


Bookoff will contact victims individually once the investigation concludes, which means that until then, any mail, SMS or call claiming to be Bookoff about this breach is suspect. And a message asking for passwords, verification codes, or card and bank details has identified itself as the attack. Bookoff says it never asks for any of those by mail, SMS or phone. Verify through the inquiry desk at 0570-01-2902 or the official inquiry form. Never click a link in a breach message.

What Bookoff members should do now

  1. Do not click links in any message about this breach. Verify through Bookoff's own site or the inquiry desk, typed by you. This applies to the genuine notification too: a habit that works against the forgeries has to work against the real ones.
  2. Do not reuse your Bookoff password anywhere else. The leaked copies are hashed, but if that password matches one you use on another site, change it there now. Credential stuffing is automated and patient.
  3. Expect SMS and calls that "confirm your identity" with your own details. Names, birthdates, phones and addresses leaked. Anyone reading them back to you is proving they have the file, not that they are Bookoff.
  4. Remember what Bookoff will never ask for. No passwords, no verification codes, no card or bank details, by mail, SMS or phone. Anything asking for those is the phishing wave wearing the incident's language.
  5. Check Have I Been Pwned once the incident is listed. Then walk the breach-response order of operations.

What to watch in the Bookoff investigation

Three things. First, the subsidiary: which Bookoff company ran the member system, and whether its customers face different exposure. Second, whether "may have been obtained" becomes confirmed exfiltration, and the final unique-person count. Third, whether the dataset surfaces publicly. That is the step that turns a contained intrusion into a circulating one. The investigation continues. So does the week's pattern.

Top comments (0)