Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
▣ Breach LAWSON-DATA-BREACH 2026-10-09

Lawson: Abused App Function Exposes 2.15 Million Lawson ID Records

"Lawson, one of Japan's largest convenience-store chains, disclosed on October 8, 2026 that unauthorized access to its "Lawson ID" membership service and its "Lawson App Reservation" feature exposed personal information…"

Lawson, one of Japan's largest convenience-store chains, disclosed on October 8, 2026 that unauthorized access to its "Lawson ID" membership service and its "Lawson App Reservation" feature exposed personal information. Every source that gives an exact figure reports 2,155,345 records. Lawson ID access took place September 12 to 14, and app reservation access took place on September 17. The company says it found the activity during an investigation on October 7, so roughly three weeks passed before it noticed. Lawson has not named an attacker, and no threat group has claimed the incident. As of the announcement, the company had confirmed no misuse of the data and no secondary harm (ASCII.jp, Pirorin Tech, DX no Arukikata).

A note on sourcing: none of the eight sources is Lawson's own notice, a regulator filing or a CERT advisory. The company's statement reaches us through secondary coverage. Most of those reports agree with each other and quote the October 8 notice directly. Where they disagree, we say so below.

What Happened

Most reports give the same timeline:

Where the accounts differ: a BigGo Finance item, republished by Rankiteo, says the disclosure came on September 8 and detection on September 7 "during a routine system inspection." Those dates come before the access window the same article reports, so they cannot both be right. Every other source puts detection on October 7 and disclosure on October 8. The September dates look like a typo, and we use the October dates.

Lawson says affected users will get email from [email protected] and in-app notices. No self-service lookup page has been published. Users who are unsure whether they are affected are being directed to a dedicated inquiry form (Pirorin Tech, DX no Arukikata). As of October 8, the company had not announced compensation, points or other redress (DX no Arukikata).

Separate incidents: three nearby events should not be mixed up with this breach.

What Was Taken

The data that leaked depends on the service:

Service Records Data exposed
Lawson ID 2,155,345 Email address and name. Gender, phone number, home address and newsletter-subscription status are also exposed for users who entered them, for example in prize campaigns.
Lawson App Reservation 26 Name, phone number, partial credit card number

Sources: ASCII.jp, Security Incident Sokuhou, Pirorin Tech, DX no Arukikata, all citing Lawson's October 8 notice.

On scope:

In short, this is a large set of verified identity and contact data tied to a trusted retail brand. That makes it most useful for targeted phishing and smishing that pretends to be Lawson, especially fake "breach notification" or "compensation" messages.

Why It Matters

The Attack Technique

Lawson attributes the breach to improper use of "a system related to the Lawson app." It says a mechanism designed to show a user their own information was accessed by a third party (DX no Arukikata, Security Incident Sokuhou).

Lawson has not said which weakness was exploited, how any credentials or identifiers were obtained, or exactly what technique was used. DX no Arukikata warns against blaming a specific vulnerability yet.

Security Incident Sokuhou suggests a likely pattern without confirming it. If an endpoint returns member data for any identifier it is given, without checking that the requester owns that identifier, an attacker can step through identifiers and collect data in bulk. That is an insecure direct object reference (IDOR), or broken object-level authorization. It would fit the scale, the short access windows and the description of a "display" function being abused. Treat it as analysis, not a confirmed root cause.

No threat actor, ransomware group or extortion demand has been reported. Lawson responded by blocking the source of the access and suspending app reservation.

What Organizations Should Do

  1. Test object-level authorization before release. For every API that returns user data, confirm that asking for another user's ID, booking number or token fails. Add these checks to CI and to penetration testing scope, as recommended for broken object-level authorization in the OWASP API Top 10.
  2. Rate-limit and alert on enumeration. Watch customer-facing APIs for one session, token or IP pulling many distinct records, for sequential identifier patterns, and for unusual spikes in read volume. A few days of bulk harvesting should not go unnoticed for three weeks.
  3. Return less data. Display endpoints should send only the fields the screen shows, and should mask phone numbers, addresses and card fragments by default. A smaller response means a smaller leak if authorization fails.
  4. Lock down outbound mail. After the September mail-server abuse, check SMTP relay settings and authentication. Enforce SPF, DKIM and DMARC at p=reject so attackers cannot take advantage of real breach notices.
  5. Prepare for phishing after the breach. Publish the exact sender addresses you use and say that notices will never ask for passwords or card details. Tell support staff to expect scams that pose as breach follow-ups or compensation offers.
  6. Advise affected users clearly. Ask them to change reused passwords as a precaution. The 26 app reservation users should check their card statements. Everyone should verify messages through the official app instead of links in email or SMS (Pirorin Tech, citing IPA guidance).

Sources: Lawson Confirms Data Breach: Over 2.15 Million Records ... | 53 companies in Japan hit by Qilin ransomware group: police ... | ローソンIDに不正アクセス、215万5,345件が漏えい アプリ予約ではカード番号の一部も セキュリティ事故速報 | ローソンIDで約215万件の個人情報漏えい|対象の確認方法と利用者の対処 - ぴろりんテック | 【速報】ローソンIDで215万件超の個人情報漏えい|自分は対象?補償・原因と7pay事例から考えるDXセキュリティ DXの歩き方 | Cyberattacks Spread Across Japan | Daiichi Kosho and Lawson: Lawson Reports Data Breach Affecting Over... | Lawson's Own Mail Server Sent 700,000 Scam Emails Over a Weekend J...