White Essence, the Japanese teeth-whitening chain, says about 1.05 million accounts lost personal data: names, email addresses, home addresses, phone numbers, and logins with passwords in an encrypted state. The company announced the number on October 5. The intruders got in during August. I run AliasFleet, an email-alias service that hands every signup its own address so one company's breach cannot follow you home. This is the shape of breach that argument is built for, but the timeline is the real story.
Because there were two notices, and only one of them got anyone's attention.
The August notice said 'access'. The October one says 'gone'.
On August 12, White Essence suspended its reservation site and core systems and told the public it had detected unauthorized access. That was notice one. It sounded like a company handling something. Yesterday, nearly two months later, notice two arrived: the external investigation finished, and the data had actually been taken. About 1.05 million accounts' worth.
Read that again, slowly. The breach happened when the door opened. The confirmation is just the company finishing the count. Everyone who waited for October to take this seriously handed the attackers eight weeks of lead time. Nobody knows when the intrusion actually started, either: August 5 is when the company detected it, not when the attacker arrived.
This is the standard shape of a breach disclosure now. First notice: vague, hedged, sounds managed. Second notice: the number, weeks later, when the file is long gone. The lesson is boring and worth more than the number: act on the first notice. Change the password in August. Assume the file is out in August. October's confirmation changes nothing about what you should already have done.
The file, field by field
White Essence's accounting of what was taken is specific, and the specificity is the warning.
| Taken | Not taken |
|---|---|
| Name | Bank account info (never held) |
| Home address | Customer images (no leak confirmed) |
| Phone number | |
| Email address | |
| Date of birth | |
| Gender | |
| Employer | |
| Login ID and password (encrypted) | |
| Service usage and support records | |
| Company management number |
Not every account lost every field; the company says it varies by what was registered. The affected accounts belong to customers, franchise clinic staff, and head-office employees, roughly 1.05 million of them, registered as of August 5.
Look at the taken column as a scammer would. Name, home address, phone number, email, date of birth, plus a service relationship: this person used a teeth-whitening chain. That is the complete kit for a phishing email, a phone call, or a letter that references something real about you. Real details are what make fake messages believable. This file has the real details.
'Encrypted' is doing a lot of work in that table
The login credentials are the part of this story most people will read wrong. White Essence says the login IDs and passwords were stored in an encrypted state. Encrypted is not hashed. It is not described as salted, not described as using any particular algorithm, and an encrypted store can be opened by anyone who finds the key alongside it, which happens more often than security people like to admit.
But you do not need my speculation. The company told customers to change their passwords on any other service where they reused the same login. A company that believed its encrypted store was safe would not say that. The advice is the tell. Read "encrypted" as "we hope," and act as if the passwords are readable.
If you reused that login ID and password anywhere else, and most people do, the credential-stuffing risk is the sharpest edge of this breach. The email addresses in the same file tell the attacker exactly which inboxes to try them against.
The way in was the booking site
The company says a vulnerability in the reservation site's program was exploited, and the reservation site became the foothold into the core systems. The fix for that vulnerability is done, and services are being restored in phases after an outside firm verified them. The My Page function is still down.
Notice the shape. The attackers did not break the vault. They broke the appointment book, then walked into the building. The reservation site exists to take bookings; it happened to hold the keys to everything else. If you have been reading my recent breach coverage, you will recognise the silhouette: the side system with everyone's contact details is the target, because the side system is where the contact details live.
White Essence has reported the incident to Japan's Personal Information Protection Commission and consulted the police. As of the October 5 announcement, the company says no secondary damage has been confirmed. That is a snapshot, not a guarantee.
What to do if you used White Essence
- Change the password, and mean it. Change it on White Essence, then on every other service where you used the same login. Assume the encrypted store opens.
- Turn on multifactor authentication on your email account. Your inbox is in this file, and your inbox is the recovery address for everything else you own.
- Expect contact and distrust it. The company is warning about suspicious emails, calls and mail impersonating White Essence or other businesses. It is also notifying the people it can reach, so real and fake messages will arrive in the same window. Never click through from a message about this breach. Go to the company's site yourself.
- Watch for the phone and the postbox, not just the inbox. This file has home addresses and phone numbers, so the phishing will not stay in email.
- Check Have I Been Pwned once the breach is listed. One address, one search, and you know which of your accounts sit in the file.
The full ordered version of the standard response lives in our breach-response guide.
The part you can fix before the next one
You cannot un-leak this file. The copies exist, and 1.05 million people will spend the next few years deleting messages they can trace back to a teeth-whitening booking.
What you can fix is the next signup. Hand every service an address that exists only for that service. When the next booking site or shop gets opened up, the address in the file belongs to that site alone: you retire it, the phishing dies with it, and your real address was never in the dump because you never gave it out. And when the phishing starts arriving on that address, the address itself tells you which company lost it, which is the leak-tracing mechanism doing exactly what it is for. One address per signup. The breach ends at the address.
If you have never used one: this is what an email alias is. The set-up guide takes about two minutes.
Two honest gaps
First: the company's notice is in Japanese, and I do not read Japanese. The facts above come from ITmedia's reporting, cross-checked against the company's own notice page, which I verified exists and is dated October 5. If anything here differs from the Japanese original, the original wins.
Second: I do not know how the passwords were encrypted, so I cannot tell you how fast they fall. The company's own advice says to change reused passwords, and that is the safest thing to follow. I will update this piece if White Essence publishes more detail.
The breach was August. The number is October. Next time a company tells you it found someone inside its systems, do not wait for the count.

Top comments (0)