A threat actor claims to have breached Japanese reservation and customer management platform PeakManager and extracted a database containing more than 32 million rows of customer information.
The data was advertised for sale on July 25 alongside alleged access to PeakManager’s internal network and database systems. The actor also claims to possess the platform’s source code and continuing remote access to its infrastructure.
The claims remain unconfirmed. PeakManager and its operator EPARK Relax & Este had not issued any public statement addressing the alleged intrusion at time of publication.
32 million rows may represent fewer customers
The threat actor claims the original database contains exactly 32,510,060 rows. However, that figure should not be interpreted as 32 million unique individuals.
According to the sale post, duplicate records were removed using phone numbers and entries without phone numbers or addresses were excluded. The actor claims this process produced 2 datasets containing a combined 6,118,016 rows.
The processed collection was described as approximately 1.11 GB when uncompressed, while the original 32 million-row database was allegedly compressed to 3.14 GB.
BreachNews has not independently verified those totals or determined how many unique customers may be represented. A single customer could appear multiple times across shops, bookings, visits, memberships, or historical records.
Sample points to extensive customer profiles
The sample accompanying the claim appears to contain detailed customer and reservation-system records. BreachNews is not publishing the sample or identifying any individuals whose information appeared in it.
The exposed fields allegedly include:
- Customer names and phonetic name readings
- Telephone numbers and email addresses
- Dates of birth and gender markers
- Postal codes and residential addresses
- Shop and customer identifiers
- Membership types and pricing information
- Account creation and modification dates
- Visit frequency and sales-related values
- Customer notes and internal account fields
- Stored password-related database fields
Some sample entries appear to contain recent modification dates extending into July 2026. That may indicate the dataset includes current information, although the dates and authenticity of the records have not been independently established.
The presence of detailed identity, contact, membership, and transaction-related information could expose affected customers to phishing, impersonation, account takeover attempts, and targeted fraud. Information about visits to wellness or treatment businesses could also carry additional privacy concerns depending on the services received.
Source code and internal access also offered
The actor is seeking $70,000 for the databases and claims the sale can be completed through an escrow service. The post also advertises PeakManager’s purported source code and access to the company’s internal network and database environment.
Those additional claims raise the potential impact beyond a static database theft. Continuing internal or remote database access could allow further data extraction or system manipulation if the access is genuine and has not been revoked.
BreachNews has not tested the alleged access or downloaded the offered database. No technical evidence identifying the initial access method was included in the public post.
PeakManager serves more than 2,000 locations
PeakManager describes itself as a reservation and customer management platform developed for relaxation salons, chiropractic practices, aesthetic salons, osteopathic clinics, and acupuncture businesses.
The platform supports appointment scheduling, sales management, customer records, email distribution, membership applications, payment features, and visit histories. Its website says the service has been adopted by more than 2,000 locations.
PeakManager is operated by EPARK Relax & Este, a Tokyo-based company established in 2016. The service’s website states that its customer management functions can retain names, telephone numbers, visit histories, and treatment preferences.
The alleged incident follows other significant data security events affecting organizations in Japan. In a separate case, KDDI said a third-party software breach may have exposed 14.2 million email accounts.
Operator has not confirmed the claim
PeakManager had not published a breach notice or service advisory addressing the alleged database theft at time of publication.
The company has not confirmed whether customer information, source code, internal systems, or database credentials were accessed. The number of unique individuals represented by the purported files also remains unknown.
Organizations using PeakManager should monitor communications from EPARK Relax & Este and review administrative accounts for unfamiliar activity. Customers should be cautious of messages referencing real appointment, membership, or contact information and should avoid sharing passwords or verification codes through unsolicited communications.












