Lawson Confirms Data Breach Exposing 2.15 Million Customer Records

Japanese retailer Lawson confirmed that attackers accessed more than 2.15 million customer records through its app infrastructure, exposing names, emails and other personal information.
Japanese convenience store and smartphone illustrating the Lawson data breach affecting more than 2.15 million customer records.

Japanese convenience store giant Lawson has confirmed a data breach affecting 2,155,345 customer records after attackers exploited a security mechanism within its mobile app infrastructure to access personal information.

The company disclosed the incident on October 8, revealing that unauthorized access to its Lawson ID account service exposed customer names and email addresses, along with additional personal details for some users.

A separate compromise involving the Lawson App Reservation service exposed 26 records containing names, phone numbers and partial credit card numbers.

According to Lawson’s official breach disclosure, investigators determined that attackers had abused functionality originally designed to display personal information to authenticated app users.

The company confirmed that information was leaked but said it had not identified any resulting fraud or secondary harm at the time of its announcement.

More than 2.15 million Lawson ID records exposed

The largest portion of the breach involved Lawson ID, the account system customers use to access the retailer’s mobile application and online services.

Lawson confirmed that 2,155,345 records were affected.

The exposed information included customer names and email addresses. Depending on what users had previously submitted through the service, additional information may have included:

  • Gender
  • Phone numbers
  • Residential addresses
  • Email newsletter subscription information

Some of these additional details were collected when customers participated in promotional campaigns or prize applications using their Lawson ID accounts.

The company did not indicate that every affected record contained all the listed information.

Separately, attackers accessed 26 records associated with Lawson App Reservation, a service that allows customers to reserve and pay for seasonal products through the company’s official application.

Those records contained names, phone numbers and portions of credit card numbers.

Lawson described the payment information as partial card numbers rather than complete card details. It did not disclose which portions were exposed or whether additional payment-related information was involved.

The company has not reported that passwords or complete payment card numbers were compromised.

Attackers exploited an app security mechanism

The most significant technical finding involves how the attackers accessed the customer information.

Lawson said the breach occurred after an unauthorized party abused a system associated with its mobile application.

Investigators determined that a security mechanism intended to display information to the appropriate account holder had been accessed improperly, allowing personal information to leak.

The company has not disclosed the precise vulnerability or explained whether the attack involved an authentication bypass, authorization weakness or another application security failure.

However, the findings suggest that the incident involved misuse of application functionality rather than a conventional ransomware attack or malware infection.

Lawson specifically stated that its investigation had not identified malware infections or unauthorized access beyond the incidents it disclosed.

That distinction matters because application-level security weaknesses can expose large amounts of customer information without attackers necessarily compromising the underlying servers or deploying malicious software.

The company has not publicly attributed the breach to a specific threat actor.

Unauthorized access occurred in September

Although Lawson announced the breach on October 8, the unauthorized activity occurred several weeks earlier.

The company’s investigation established the following timeline:

  • September 12-14: Attackers accessed the Lawson ID service without authorization.
  • September 17: Unauthorized access affected the Lawson App Reservation service.
  • October 7: Lawson’s investigation identified the earlier intrusions and associated data exposure.
  • October 8: The company publicly confirmed the breach and disclosed the number of affected records.

The timeline indicates that approximately 3 weeks passed between the first unauthorized access and the investigation that established the breach.

Lawson has not explained what initially prompted the October 7 investigation or whether the attackers maintained access throughout that period.

It also has not disclosed how much information was accessed during individual sessions or whether the stolen records were subsequently distributed.

Reservation service suspended after breach

Following the discovery, Lawson blocked suspicious access sources and suspended the Lawson App Reservation function to prevent further exposure.

The company also began displaying notifications about the incident within its mobile application.

Affected customers are being contacted individually by email, while Lawson has reported the breach to relevant authorities, including Japan’s Personal Information Protection Commission.

Lawson said it plans to strengthen security controls across the affected systems, improve monitoring capabilities and reinforce its incident response procedures.

The company expects to resume the reservation service in mid-October, subject to further announcements.

It has not disclosed whether the Lawson ID service experienced broader operational disruption or whether customers need to reset their passwords.

Exposed information increases phishing risks

Although Lawson has not identified confirmed misuse of the stolen information, the exposed records could support targeted phishing and impersonation attempts.

Customer names and email addresses can help attackers construct messages that appear to originate from Lawson or its associated services.

Where phone numbers and residential addresses were also exposed, attackers could incorporate additional personal details to make fraudulent communications appear more credible.

The breach could also create opportunities for scams involving loyalty accounts, promotional campaigns, account verification requests or fraudulent delivery notifications.

Lawson has warned affected customers to remain cautious about suspicious emails, text messages and telephone calls directed at contact information registered with Lawson ID.

Customers should verify unexpected communications through the retailer’s official application or website rather than following links in unsolicited messages.

For the 26 reservation records involving partial credit card information, the company has not reported evidence of fraudulent transactions connected to the incident.

Lawson investigates the security failure

The breach highlights the risks associated with customer-facing applications that process large volumes of personal information.

Even security mechanisms designed to restrict access to individual account data can become exposure points if attackers discover ways to misuse the underlying application functionality.

In this case, Lawson has confirmed that the mechanism responsible for displaying user information was involved in the unauthorized disclosure.

However, the company has not released enough technical detail to determine whether the underlying problem resulted from flawed authorization checks, improper session handling or another weakness.

Lawson has apologized to affected customers and said it will work to prevent similar incidents through additional security measures.

The company has not identified any secondary damage resulting from the breach, but the exposure of more than 2.15 million customer records leaves a substantial population potentially vulnerable to follow-on phishing and impersonation attempts.

Further findings may clarify how attackers exploited the application and whether additional information was accessed.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →