DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

NewsPicks Breach Hits 362,000 Card Records, 323,000 Emails

'May have leaked' is a placeholder, not a report. Uzabase's second-day numbers show what NewsPicks' day-one 'some users' hid: 362,000 card records and 323,000 email addresses. The emails are the weapon. I run AliasFleet, an email alias service: one address per site, so leaks name their source.

I wrote the day-one piece when the count was still a blank. This follow-up covers only what changed in the last 24 hours: the numbers, the correction, the sharper vector, and the updated advice.

From 'some users' to hard numbers

At 18:25 JST on 9 October, Asahi carried the escalation: Uzabase had announced that up to 362,000 user records may have leaked externally, and the data types ran broader than day one suggested. The full per-field list comes from Uzabase's second official notice, reported in detail by ITmedia at 18:05 JST the same evening. The notice itself is Japanese-only. The figures below are per ITmedia's reporting of it; Uzabase's first official notice is the linkable original.

Field Records (maximum)
Partial card info (cardholder name + last 3 or 4 digits) ~362,000
Email addresses ~323,000
Workplace position (7 categories) 273,000
Workplace / affiliation 65,000
Names 59,000
Delivery addresses / recipient names 31,000
Workplace phone numbers 29,000
Dates of birth 28,000
NewsPicks Enterprise / Education operator contacts 122

Two rows need a closer read. The card row is the cardholder name plus the last three or four digits only. Full card numbers are held by the payment processor and were never stored on Uzabase's systems, and security codes were not stored either. The email row, 323,000, is confirmed by a second outlet, TV Asahi.


Uzabase has not published a unique-user count, and the rows overlap. One paying subscriber can sit in the card row, the email row, the name row and the workplace rows at once. These are per-field maximums, not a body count. Anyone quoting a user total from this table is inventing one.

How 1.17 million became a correction

On 8 October the first wire carried the hedged wording. On 9 October the second notice brought numbers, and for two hours ITmedia's headline added them into 1.17 million. At 20:12 the same evening the headline changed: the figure had not accounted for duplication across the per-field rows, and the correction says so plainly. Credit where it is due. The fix took two hours, not two weeks, and it is on the record.

Read it as a rule, not an anecdote. The first number out of a breach story is almost never the final number, and the failure mode is always the same: overlapping rows added into a body count. Until a company publishes a unique-user count, every headline total is an estimate sitting on top of overlapping rows. This one got corrected in public, which is rarer than it should be.

Translated from Uzabase's second notice (9 October), via ITmedia's reporting:

Up to approximately 362,000 records, including cardholder names and the last three or four digits of card numbers, email addresses, names and workplace information, may have been leaked externally through a vulnerability in an operational management tool. Full card numbers are managed by the payment processor and were never stored on our systems. As of 9 October, no misuse and no public release of the data have been confirmed. We will contact potentially affected customers individually.

The vector got sharper too. The notice says a vulnerability in a management tool NewsPicks uses for business operations was exploited. Uzabase adds that there was no intrusion into the NewsPicks service itself or into its other systems, no password leaks were confirmed, and no secondary damage had been confirmed as of 9 October. The fix is already done: the tool's access was blocked, its accounts were deleted, its access keys were reissued, and the full countermeasures will be published once the cause is pinned down.

The email row is the attack list

The card data gets the headlines. The email row does the damage. Last-three-or-four digits cannot buy anything, but they are excellent props for sounding legitimate. Picture the call: it opens with your real name, your workplace, the last four digits of your card. That is not a stranger's guess. That is your data, read back to you.

And the thing that delivers the pitch is the email address. 323,000 named ones, in a file, belonging to people who click links as a habit. NewsPicks subscribers are professional link-clickers. That is the audience, and that is what makes the list a weapon.

Every row sharpens the next forgery: the name gets the greeting right. The workplace makes a 'corporate security notice' plausible. The date of birth fills the identity-verification box, and stacked together they make a spear-phishing kit with the victim's own details printed on the box.

The company's own warning stands unchanged: NewsPicks never asks for card numbers or passwords by email, SMS, phone or mail. Expect the forgery to ask for exactly those, quoting exactly your data.

One alias per site fences the list

A dedicated email alias for NewsPicks forwards to your real inbox, and every message on that alias is either from NewsPicks or from the attacker. A forged 'security update' landing on an address nobody but NewsPicks ever held has identified itself as the forgery. That is the leak-tracing mechanism: the leaked address names its source.

Kill the alias and the impersonation channel dies with it; your real inbox never appears in the attacker's file. Setting one up takes about two minutes.

The limit stands, same as yesterday: the address you already gave NewsPicks is already in the at-risk file, and no alias fixes that retroactively. Aliases fence the next subscription. The next breach is always coming, so the fence is worth building.

If you used NewsPicks, do this

The advice is mostly unchanged from yesterday. Two updates: the numbers are real now, and per TV Asahi, individual notifications were due to start on 9 October.

  1. Watch for the individual notice from Uzabase, but do not wait for it. It comes through official channels. Anything arriving sooner and asking you to click is suspect.
  2. Check your card statements and call your card issuer. Partial card data plus your name is social-engineering material aimed at the issuer, so ask whether a replacement card makes sense.
  3. Click no link in any email about this breach. Open the NewsPicks app yourself, or type the address into the browser. Verify through the company's own notice.
  4. Give your NewsPicks password a unique home. Passwords were not among the leaked fields, but credential stuffing pairs your leaked email with passwords stolen in other breaches anyway.
  5. Switch on two-factor authentication on your email. Leaked names, addresses and dates of birth are the raw material of account-recovery flows, and 2FA is the part an attacker cannot talk their way past.
  6. Check Have I Been Pwned once the incident is listed, and walk the breach-response order of operations.


If your address is in the file, the phishing risk applies to you, whatever tier you are on.

The blanks that are left

The official notice records a preliminary report to Japan's Personal Information Protection Commission at 21:44 on 8 October, with a police consultation the same night. Sankei confirms the timeline. That is fast, and it is the one part of this story the industry should copy.

What remains unknown: when the intrusion started (detection was 8 October at 12:48; the start is not reported), the exact vulnerability in the management tool, a unique-user count, and whether 'may have leaked' becomes 'did'. As of 9 October there is no confirmed misuse and no confirmed public release. If the dataset surfaces, the card advice above gets urgent and the email row becomes an active attack list. Until then, assume the file the second notice printed: your name, your email, your workplace, and part of your card. Act accordingly.

Top comments (0)