Security NEXT•August 31, 2026•🇯🇵Translated from Japanese

Yellow Hat Reports Breach in Web Work Reservation System, Possible Leak of 1.8 Million Member Records

Yellow Hat, a major Japanese retailer of car parts and accessories, has confirmed a security breach affecting its online Web Work Reservation System.

The system, used by customers to book maintenance services such as oil changes, battery replacements, and vehicle inspections, was found compromised on August 18, 2026. Subsequent investigation revealed that personal information stored on the company's member server may have been accessed and leaked externally.

Up to 1,801,499 members could be impacted. The exposed data includes names, telephone numbers, email addresses, and member numbers.

Yellow Hat has reported the incident to police and the Personal Information Protection Commission. Affected members are being notified via email, SMS, telephone, or postal mail, with warnings to watch for any suspicious unsolicited contacts.

Related articles

BoletimSec•Data Breaches & Leaks

EY Confirms Data Breach Exposing Goldman Sachs and Man Group Client Details via Checkmarx Vulnerability

EY has confirmed a data breach involving client documents accessed through a third-party technology services management platform used to support its tax operations. The unauthorized access occurred via a vulnerability in Checkmarx software and lasted from March 28 to April 12, with detection only on April 23. Exposed information included names, addresses, tax identification numbers, email addresses, and financial details belonging to clients in Goldman Sachs wealth management and the Man Group investment fund. Neither Goldman Sachs nor Man Group systems were compromised, confirming the exposure originated solely from EY's environment. The leaked materials consisted of attachments from support tickets rather than core system data. EY has engaged independent security firms, notified regulators in California, Texas, Massachusetts, and Vermont, and offered credit monitoring to affected individuals.

BoletimSec•Data Breaches & Leaks

ThreatMon Exposes SQL Server xp_cmdshell Abuse Stealing Credentials from Viva Aerobus

Researchers at ThreatMon discovered an exposed attacker infrastructure containing 17 attack tools and data stolen from airline Viva Aerobus. Attackers gained operating system access through the xp_cmdshell feature in SQL Server, which allows execution of system commands when enabled. They issued Windows and encoded PowerShell commands directly through database sessions. Data exfiltration occurred by reading files, splitting content into smaller chunks, converting to Base64, and returning results via normal SQL query responses to avoid network detection. Recovered materials included browser, Windows, and SQL credentials, source code, configuration files, database connection strings, OAuth, email, SFTP, and payment system references, plus connection history from SQL Server Management Studio. Activity took place between September 25 and 29, with no identified initial access vector or link to known malware families.

Security NEXT•Data Breaches & Leaks

Times Car Breach Exposes Identity Documents of 1.6 Million Users

Times Mobility, operator of the Times Car car-sharing service under the Park24 group, confirmed a data breach affecting approximately 6.6 million accounts. The intrusion was detected on September 25, 2026, after unauthorized access to the company's systems. Leaked information includes names, addresses, phone numbers, dates of birth, email addresses, driver's license details, and hashed passwords. Most notably, images of identity verification documents were exposed for around 1.6 million accounts, covering driver's licenses, address proofs, student IDs, and family confirmation documents. The company is notifying affected members individually by email and plans further updates based on ongoing investigation results.

AntiMalware•Data Breaches & Leaks

German Intelligence Deputy Chief's Personal Data Exposed for Years After LiveAuctioneers Breach

The personal phone number, email address, and home address of Dag Baer, deputy head of Germany's Federal Intelligence Service (BND), remained publicly accessible for several years following a 2020 breach of the American online auction platform LiveAuctioneers. The incident exposed data belonging to 3.4 million users and was uncovered through a joint investigation by Süddeutsche Zeitung and WDR. Baer continued using the compromised phone number until journalists contacted him on September 9, after which he acknowledged the error and stopped using the old number. Similar exposures affected a Bundeswehr general-major based in Bavaria as well as Peter Resink, head of the Dutch military intelligence service MIVD. All cases originated from third-party commercial services rather than direct compromises of intelligence agency systems. The reporting highlights how even senior intelligence officials remain vulnerable to ordinary consumer data breaches when they reuse contact details across personal accounts.