Cyber & AI intelligence
Wasteland.
Briefs indexed3104
Issues31
Published Mondays07:30 CT
▣ Breach ADVENTURE-JAPAN-DA 2026-10-09

Adventure (skyticket): Three Intrusions Expose 14.6 Million Customer Records

"On October 9, 2026, Adventure Inc. (TSE: 6030) said that about 14.64 million customer records from its skyticket travel-booking platform were leaked or may have been leaked. Adventure is a listed Japanese company that…"

On October 9, 2026, Adventure Inc. (TSE: 6030) said that about 14.64 million customer records from its skyticket travel-booking platform were leaked or may have been leaked. Adventure is a listed Japanese company that runs skyticket, a site for comparing and booking flights. About 4.13 million of the affected records include hashed member login passwords. The announcement covered three separate incidents, each reached by a different route. The other two affected 17,780 refund records containing bank account details and about 12,000 bus bookings. Every source we reviewed gives the same headline figures. Adventure's own notice in Japanese, its investor-relations filing, MLex, The Japan Times and vpnlab.io all cite about 14.64 million records and about 4.13 million with passwords. Adventure has reported the incidents to Japan's Personal Information Protection Commission (PPC). No threat actor has been named, and no group has claimed responsibility in the material available.

What Happened

Adventure's statement describes three unrelated incidents that it disclosed together:

  1. Server and cloud intrusion (the largest). Between October 2 and October 4, 2026, an attacker misused part of skyticket's admin functions. From there they reached other Adventure servers and data stored in the cloud. Adventure found the intrusion on October 5. This incident accounts for about 14.64 million records.
  2. Business management system breach. On September 20, an attacker exploited a vulnerability in skyticket's back-office business management system. Adventure detected it on September 28. It affected 17,780 records, a count that includes duplicates. Adventure says some further counts are still being investigated. Separately, it confirmed an unauthorized login to one member's account on September 9. vpnlab.io links that login to this incident.
  3. Exposed bus booking pages. From August 3 to October 1, bus booking confirmation pages could be opened without logging in, and a third party viewed them automatically. Adventure fixed the flaw on October 1. About 12,000 bookings were exposed, and more people than that are affected because the bookings include fellow passengers. vpnlab.io calls this a design flaw rather than a hack. Adventure lists it under the heading of unauthorized access.

Adventure says it blocked the attackers' access routes, put vulnerability fixes in place, suspended payments with stored credit cards as a precaution, and stopped storing payment information. Its IR filing says the impact on financial results is still being assessed.

What Was Taken

Incident 1 (about 14.64M records): - Names, including the spelling used in passports - Dates of birth - Email addresses and phone numbers - Postcodes and home addresses - Names of people who paid by bank transfer - Member login passwords stored as hashes (about 4.13M records)

Adventure says it has confirmed that passport numbers were not taken.

Incident 2 (17,780 records): - Names and phone numbers - Full bank account details for refunds: bank, branch, account type, account number and account holder name - Email addresses and dates of birth for 68 people, and addresses for 18

For this incident, Adventure says it has found no evidence that passport numbers were taken but is still checking.

Incident 3 (about 12,000 bookings): - Booker's name (in katakana), age, gender and date of birth - Email address, phone number and member ID - Device type, payment method and amount, and booking date and time - Full trip details: operator, route, boarding and drop-off points, departure time, and the operator's booking number - Fellow passengers' names, ages and genders

Adventure says it never stored credit card numbers or passport images, because a payment processor holds the card data. It says none of either was leaked in any of the three incidents. Apart from the one hijacked account, the company has found no misuse of the stolen data so far.

Why It Matters

At 14.64 million records, this is one of the largest consumer data exposures in the current wave of Japanese breaches. It is also a heavily travel-focused dataset. The Japan Times reports that H.I.S. and travel-technology company Temairazu disclosed incidents around the same time. Japan Cyber Watch says Times Car, Sagawa Express, Seicomart and others were hit in earlier weeks. It also cites Macnica, a Japanese technology distributor, which counts 119 similar web breaches disclosed in Japan this year, 81 of them since July.

The government has treated the wave as urgent. According to Japan Cyber Watch, eight agencies issued warnings or requests between October 7 and 9, including the PPC, JPCERT/CC, the National Cybersecurity Office and the Financial Services Agency. At an inter-ministerial meeting on October 8, the minister in charge of cybersecurity called the situation "very urgent."

The secondary risks are concrete: - Credential stuffing. About 4.13 million hashed passwords are at risk. Adventure warns they could be cracked, and Adventure has not said which hashing algorithm or salting it used. - Highly convincing phishing. Attackers can pair identity data with real travel bookings and bank details to impersonate Adventure, an airline, a bus operator or a bank. - Refund scams. Adventure warns that people whose bank details were taken may be contacted by fraudsters posing as refund handlers who ask for PINs or online banking credentials.

The Attack Technique

Adventure's descriptions are brief: - Incident 1: an admin function was misused, then used to reach other servers and cloud storage - Incident 2: a vulnerability in the business management system, which Adventure has not named - Incident 3: pages missing an authentication check, then read automatically by a scraper

Adventure has not said whether the three incidents are connected. It has not named a CVE, a product or an actor.

For context only: on October 8, JPCERT/CC issued a warning about the wider breach wave, as reported by Japan Cyber Watch. It describes four patterns: - Scanning each target for many known vulnerabilities and poorly protected files - Abusing internal APIs, often found by analyzing public smartphone apps - Exploiting a SQL injection flaw in Metabase - Web shells hidden in WAR files on Java application servers behind public web servers (added October 9)

JPCERT/CC also published attacker IP addresses and User-Agent strings. The misused admin function and the exposed booking pages at skyticket fit the access-control and internal-API patterns. However, no source we reviewed links Adventure's incidents to JPCERT/CC's indicators or to any of the other breaches. Treat any connection as unconfirmed.

What Organizations Should Do

  1. Check admin and internal endpoints. Every admin function and internal API should require authentication and authorization checks on the server. Remove anything reachable from the internet that doesn't need to be. JPCERT/CC's guidance focuses on access control for every endpoint, rate limits on APIs and short-lived tokens.
  2. Look for missing authentication checks. Test booking, confirmation and receipt pages for direct access without a login and for IDs that can be guessed. Watch for automated, sequential requests to them.
  3. Limit movement from the application tier. Application servers and admin panels should not hold broad credentials to cloud storage or other servers. Use the narrowest IAM roles possible, segment the network, and alert on unusual cloud data access.
  4. Search for JPCERT/CC's indicators. Check web, WAF and cloud logs against the attacker IPs and User-Agent strings JPCERT/CC published. Look for unexpected WAR deployments or web shells on Java application servers. Patch Metabase and other BI tools, and take them off the public internet.
  5. Strengthen account protection. Use a modern, slow, salted password hash such as Argon2id or bcrypt. Offer MFA, and monitor for credential stuffing against customer logins, especially in the travel sector.
  6. Delete data you no longer need. Stop keeping refund bank details, passport-spelling names and old bookings beyond their purpose. Several Japanese agencies listed deleting unneeded data as a core request in this week's warnings.

Sources: Japan's Adventure reports data breach affecting 14.6m customer reco... | 不正アクセスによるお客様情報の流出に関するお詫びとお知らせ 株式会社アドベンチャー | Data leaks at travel companies could impact millions of customer re... | skyticket breach: 14.6 million records may have leaked | Japan's Adventure reports data breach affecting 14.6m customer records | JPCERT/CC Warning on Japan's Breach Wave: API Abuse, Web Shells and... | Japan's Government Responds to the Data Breach Wave: Eight Agency W... | Adventure, Inc. — Notice of Information Leakage and Recurrence Prev...