MENU

CLOSE

NEWS



2023.08.21(Mon) OTHER

Apology and report regarding possible leakage of personal information due to unauthorized access

We found out on there was a possible leakage of personal information on Sunday, August 6, 2023, due to unauthorized access to our customer management system “The HUGE CLUB (hereinafter referred to as THC)”, managed and operated by our company. This personal information include name, phone number, email address, date of birth, gender, reservation history, acquired point history. This personal information does not include credit card information. In order to prevent secondary and further spread of damage, we have quickly considered the opinions of the local police station and experts and we have decided to announce the report today. We deeply apologize for causing great inconvenience and concern to our customers and many other related parties.

1. Overview of the matter
① Occurrence
Early morning of August 6th, it was reported that a system errored occurred on the THC server managed and operated by our company. When we investigated the cause, we discovered traces of unauthorized access by a third party. Due to this, THC has experienced problems such as inability to make reservations. In order to prevent further spread, we immediately disabled the access key and set up an emergency headquarter on August 7th. We are currently investigating the scope, status, cause of the illegal access of the server and examining recovery.

② Background of the investigation
During the initial investigation, we confirmed that the THC server had been compromised and some internal data had been deleted. In addition, it was found out that the compromised server contained a file that stored some customer information which had been deleted.
Regarding the possible leak and misuse of this personal information that was hacked, we have not yet confirmed any unauthorized use of personal information related to this matter. However, it is difficult to completely deny the possibility of an outflow, and we will continue to investigate.

2. Possible Items of personal data that was hacked
① Subject
96,938 customers who registered “The HUGE CLUB” between June 15th, 2021 and September 19th, 2022
② Information
Name, phone number, email address, date of birth, gender, reservation history, acquired point history
※Credit card information is not included.

3. cause
As a result of comprehensive verification including the opinions of external experts, we believe the intrusion rout may be through EC website, which in currently under development connecting with THC, using the stolen access information from THC.

4. Secondary damage and/or possibility of such damage and its detail
We are currently investigating and consulting with external experts.
Please be cautious of fraud emails that pretend to be THC or HUGE and make sure to follow below if you do receive anything suspicious:
1. Confirm that the domain of the e-mail address is “huge.co.jp”
2. No clicking of links on e-mail
3. No opening of attachments

5. Customer Support
We have sent a report to our customers subjected to the matter by email on August 10th. Regarding future reports, we will contact them individually as soon as we can.

◆ Customer Support Center
Phone: 0120-142-044
Hours: Weekdays 10:00-17:00
Email: thcinfo@huge.co.jp / ※Please contact via email for English inquiries

We take this fact very seriously and will make every effort to resolve the concerns of our customers. We will also work to further strengthen our personal information management system so that similar situation will never occur.

AWSOM Powered