PeakManager Allegedly Breached as 32 Million Database Rows Go Up for Sale

A threat actor claims to have stolen 32 million database rows from PeakManager while offering customer data, source code, and internal access for sale.
Forum post claiming PeakManager was breached and that 32 million customer database rows are being sold.
A forum post claims PeakManager was breached and offers 32 million database rows for sale along with alleged source code and internal access.

A threat actor claims to have breached Japanese reservation and customer management platform PeakManager and extracted a database containing more than 32 million rows of customer information.

The data was advertised for sale on July 25 alongside alleged access to PeakManager’s internal network and database systems. The actor also claims to possess the platform’s source code and continuing remote access to its infrastructure.

The claims remain unconfirmed. PeakManager and its operator EPARK Relax & Este had not issued any public statement addressing the alleged intrusion at time of publication.

32 million rows may represent fewer customers

The threat actor claims the original database contains exactly 32,510,060 rows. However, that figure should not be interpreted as 32 million unique individuals.

According to the sale post, duplicate records were removed using phone numbers and entries without phone numbers or addresses were excluded. The actor claims this process produced 2 datasets containing a combined 6,118,016 rows.

The processed collection was described as approximately 1.11 GB when uncompressed, while the original 32 million-row database was allegedly compressed to 3.14 GB.

BreachNews has not independently verified those totals or determined how many unique customers may be represented. A single customer could appear multiple times across shops, bookings, visits, memberships, or historical records.

Sample points to extensive customer profiles

The sample accompanying the claim appears to contain detailed customer and reservation-system records. BreachNews is not publishing the sample or identifying any individuals whose information appeared in it.

The exposed fields allegedly include:

  • Customer names and phonetic name readings
  • Telephone numbers and email addresses
  • Dates of birth and gender markers
  • Postal codes and residential addresses
  • Shop and customer identifiers
  • Membership types and pricing information
  • Account creation and modification dates
  • Visit frequency and sales-related values
  • Customer notes and internal account fields
  • Stored password-related database fields

Some sample entries appear to contain recent modification dates extending into July 2026. That may indicate the dataset includes current information, although the dates and authenticity of the records have not been independently established.

The presence of detailed identity, contact, membership, and transaction-related information could expose affected customers to phishing, impersonation, account takeover attempts, and targeted fraud. Information about visits to wellness or treatment businesses could also carry additional privacy concerns depending on the services received.

Source code and internal access also offered

The actor is seeking $70,000 for the databases and claims the sale can be completed through an escrow service. The post also advertises PeakManager’s purported source code and access to the company’s internal network and database environment.

Those additional claims raise the potential impact beyond a static database theft. Continuing internal or remote database access could allow further data extraction or system manipulation if the access is genuine and has not been revoked.

BreachNews has not tested the alleged access or downloaded the offered database. No technical evidence identifying the initial access method was included in the public post.

PeakManager serves more than 2,000 locations

PeakManager describes itself as a reservation and customer management platform developed for relaxation salons, chiropractic practices, aesthetic salons, osteopathic clinics, and acupuncture businesses.

The platform supports appointment scheduling, sales management, customer records, email distribution, membership applications, payment features, and visit histories. Its website says the service has been adopted by more than 2,000 locations.

PeakManager is operated by EPARK Relax & Este, a Tokyo-based company established in 2016. The service’s website states that its customer management functions can retain names, telephone numbers, visit histories, and treatment preferences.

The alleged incident follows other significant data security events affecting organizations in Japan. In a separate case, KDDI said a third-party software breach may have exposed 14.2 million email accounts.

Operator has not confirmed the claim

PeakManager had not published a breach notice or service advisory addressing the alleged database theft at time of publication.

The company has not confirmed whether customer information, source code, internal systems, or database credentials were accessed. The number of unique individuals represented by the purported files also remains unknown.

Organizations using PeakManager should monitor communications from EPARK Relax & Este and review administrative accounts for unfamiliar activity. Customers should be cautious of messages referencing real appointment, membership, or contact information and should avoid sharing passwords or verification codes through unsolicited communications.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site