Rohto Pharmaceutical Co., Ltd., the Osaka-headquartered OTC medicine and skincare maker listed on the Tokyo Stock Exchange Prime market (4527), confirmed on September 11, 2026 that it had detected an event the previous day indicating its mail-order and online shopping system "may have been accessed by a third party." Three days later, a threat actor using the handle sta6 publicly claimed responsibility and alleged the theft of roughly 4 TB of data, including approximately 3.95 million Salesforce customer records and about 850,000 recorded customer service calls. Rohto has confirmed neither the intrusion's success nor any data loss. The volume figure varies by source: TechNadu reports the actor's claim as 4.1 TB, while Japan's Security Measures Lab, which reviewed the forum post and the actor's sample files directly, describes it as approximately 4 TB with the call recordings alone accounting for about 3.5 TB.
Note on sourcing: no regulator filing or national CERT advisory has been issued in this case. The closest thing to a primary source is Rohto's own September 11 corporate notice, republished in English via MarketScreener. Everything about the actor and the alleged data volume comes from criminal claims and third-party reporting, and is treated as unverified throughout this brief.
What Happened
Rohto's own account is deliberately narrow. Per the company notice, on September 10, 2026 it "confirmed an incident in its mail-order system that may have been accessed by a third party," implemented containment measures "including restricting access to the system in question," and began reviewing related systems and investigating the scope of impact. As of that statement, it had "not confirmed any impact on our main business operations."
Security Measures Lab makes a point worth repeating: Rohto's phrasing is "confirmed an event with the possibility of unauthorized access," not "confirmed unauthorized access." As of September 14 the company had still not published a follow-up notice, and by September 15 it had not disclosed any data leakage. What remains unstated in Rohto's disclosures is extensive: intrusion date, entry vector, whether a vulnerability or stolen credentials were involved, whether customer data was accessed, how many customers are affected, whether payment card data is in scope, whether ransomware or malware was used, and which specific systems and services fall inside the affected perimeter.
Separately, Rohto has warned customers to be alert for suspicious phone calls, emails, and SMS messages impersonating the company or its mail-order operation. That advisory is the strongest signal in the official record that the company considers customer contact data to be at some risk.
The actor's claim surfaced on September 14, 2026 on a foreign cybercrime forum, amplified on X by HackManac. The same day, the Dark Web Intelligence account DailyDarkWeb posted a short alert naming Rohto in connection with a potential breach. UNDERCODE NEWS notes that the DailyDarkWeb post carried almost no technical substance: no actor attribution, no data volume, no ransom demand, and no indication of whether the material originated from corporate systems or a customer platform. Its value was timing, not content.
Rohto's official online shop remained reachable as of September 14, with login and product pages functioning. Security Measures Lab cautions that a working website does not establish that the storefront is outside the affected system boundary.
What Was Taken
Nothing has been confirmed as taken. What follows is the actor's claim and what one outlet was able to corroborate from published samples.
sta6 claims approximately 3.95 million Salesforce customer records and approximately 850,000 recorded customer calls. The claimed inventory also spans SharePoint corporate documents, departmental files, internal database content, OneDrive files, Outlook messages, joint research records, sales history, customer systems, internal collaboration tools, and proprietary research holdings.
Security Measures Lab reviewed the proof samples the actor published and reported three findings. First, a sample file of 1,000 records whose data structure is consistent with Salesforce REST API sObject records. Second, video that appears to be interior facility footage captured by an omnidirectional camera. Third, a screen image that appears to show internal materials being shared in an online meeting. The outlet explicitly declined to publish the leaked samples, actor contact details, or links to the stolen data.
Crucially, the same outlet flags what the samples do not prove. A structurally valid 1,000-record sample does not validate a 3.95 million record set. The camera footage does not establish that cameras were directly compromised; it could have been obtained from stored or shared media. Nothing confirms that Salesforce itself was breached as a platform, and nothing confirms that the forum poster is the party that actually carried out the intrusion rather than a reseller or opportunist.
If the claim holds even partially, the sensitivity profile is awkward for Rohto. The company sells OTC medicines, health foods, and cosmetics direct to consumers, so a mail-order CRM would plausibly carry purchase histories tied to health-adjacent products. Call recordings are worse than records on a per-item basis: they are unstructured, typically contain verbal identity verification, and are rarely covered by the redaction controls applied to structured CRM fields. The claimed joint research and proprietary research material, if genuine, moves this out of a pure consumer privacy event and into IP loss for a firm whose group includes Rohto Nitten and Amato Pharmaceutical on the prescription side and Mentholatum internationally.
Why It Matters
The single most important detail in this incident is the word "Salesforce."
Between mid-2025 and August 2026, the cybercriminal collective operating under the ShinyHunters brand, tracked across clusters including UNC6040, UNC6240, UNC6395, UNC6661, and UNC6671, ran a sustained data theft and extortion campaign specifically against Salesforce customer data at hundreds of organizations. ThreatPaper's case study documents the mechanics: OAuth token supply chain compromise, vishing of Salesforce administrators, and abuse of overly permissive Experience Cloud guest user permissions to pull CRM records without tripping login anomaly detection. The Salesloft Drift token theft alone, harvested from source code repositories via automated secret scanning, reached roughly 760 tenant organizations. Gainsight and Klue integrations were abused similarly, and attackers deployed customized variants of Mandiant's open-source AuraInspector to enumerate exposed Experience Cloud endpoints.
To be explicit: nobody has linked sta6 to ShinyHunters, and no source in this set makes that claim. Rohto has not named Salesforce as an affected system. But the shape of the claimed haul, a large Salesforce customer record set, exfiltrated from a consumer-facing commerce environment, published on a forum with sample proof and no ransomware component, is the exact signature of that campaign family. For defenders in Japan and elsewhere, the correct response is to treat this as a prompt to audit SaaS integration trust, not to wait for attribution.
The second reason this matters is disclosure asymmetry. Rohto's public record consists of one short notice. The actor's record consists of a volume claim, a record count, a category list, and published samples. That gap is where customer-facing fraud grows, which is why Rohto's own impersonation warning is the most actionable line in its statement. A breached mail-order customer list plus 850,000 call recordings would be unusually good raw material for voice-enabled social engineering against the same customer base.
Context on the company: Rohto reported consolidated revenue of ¥308.6 billion and operating profit of ¥38.9 billion for the fiscal year ended March 2025, with roughly 9,144 consolidated employees (MarketScreener lists 9,292). It holds the leading share of the Japanese consumer eye drop market. This is also not its only regulatory headache of 2026; in August the company announced a precautionary voluntary recall of roughly 130,000 units of Vietnamese-manufactured eye drops from US retailers and distributors following FDA findings on manufacturing controls. The two events are unrelated, but they land on the same corporate risk and communications function within a month of each other.
The Attack Technique
Unknown, and no source claims otherwise.
Rohto has not disclosed an entry vector, a vulnerability, or whether credentials were stolen. Security Measures Lab lists intrusion path, intrusion start time, exploited vulnerability, credential theft, and attacker identity as all unpublished. The actor has not described methodology in the reporting available.
What can be said about the technique space, based on the ThreatPaper campaign analysis of the surrounding Salesforce-targeted ecosystem:
- Compromised third-party OAuth tokens. Access via an integration's token generates no anomalous login event on the tenant. The Salesloft Drift case is the template.
- Vishing of administrators. UNC6040 operations relied on phone-based social engineering to get admins to authorize malicious connected apps. Note the grim symmetry here: an organization holding 850,000 call recordings is an organization with a large phone-facing support operation.
- Experience Cloud guest user misconfiguration. Overly permissive guest profiles exposed object data to unauthenticated enumeration, queried at scale with modified versions of legitimate assessment tools.
Rohto's containment action, restricting access to the affected system, is consistent with any of these but distinguishes none of them. Treat vector speculation as speculation until Rohto's investigation reports.
What Organizations Should Do
- Inventory every connected app and OAuth grant in your Salesforce tenant. Enumerate non-human identities, the scopes each holds, and when each token was last rotated. Revoke anything unrecognized or unused. This is the control that failed across roughly 760 organizations in the Drift compromise.
- Enforce PKCE and refresh token rotation. Salesforce moved these toward mandatory in response to the 2025 to 2026 campaign. If your tenant is running on legacy grant flows or long-lived unrotated refresh tokens, you are still exposed to the original attack path.
- Audit Experience Cloud guest user permissions. Check object-level and field-level access for guest profiles, confirm sharing rules, and test your own endpoints for unauthenticated record enumeration before someone else does.
- Treat call recording archives as crown jewel data. Apply the same encryption, retention limits, and access logging you apply to structured PII. In this claim, recordings account for the overwhelming majority of the alleged volume at roughly 3.5 TB of about 4 TB. Most organizations have no egress alerting on these stores at all.
- Build vishing resistance into admin workflows. Require out-of-band verification for any request to authorize a connected app, reset MFA, or elevate privileges. Train support and IT staff specifically on pretexts that impersonate vendors and internal IT, and rehearse the refusal path.
- Monitor for bulk API read volume, not just failed logins. The defining feature of this campaign family is that it authenticates legitimately and then reads at abnormal scale. Alert on query volume and record export anomalies per integration identity.
- If you are a Rohto mail-order customer, expect impersonation attempts. The company has warned of fraudulent calls, emails, and SMS purporting to come from Rohto or its mail-order operation. Verify any contact independently through the official site, and do not act on inbound requests for payment or account details.
Sources: Rohto Pharmaceutical Discloses Cyber Incident, Cybercriminal Claims... | ロート製薬、ECサイトで不正アクセスの可能性 9月10日に確認、影響範囲を調査中セキュリティニュースのセキュリティ対策Lab | Rohto Pharmaceutical Faces a New Cybersecurity Shadow as Dark Web D... | ロート製薬 | ロート製薬 ECサイトへの不正アクセスでハッカーが約4TBのデータ取得を主張-公開サンプルを確認セキュリティニュースのセキュリティ対策Lab | ShinyHunters Salesforce Data Extortion and SaaS Supply-Chain Campai... | Rohto Pharmaceutical : Notice Regarding Voluntary Recall of Vietnam... | Rohto Pharmaceutical : Regarding the possibility of unauthorized a...