{
  "id": 13073580,
  "title": "Data leaks at travel companies could impact millions of customer records",
  "url": "https://urgent.news/2026/10/09/data-leaks-at-travel-companies-could-impact-millions-of-customer",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T08:51:00.000Z",
  "source": {
    "name": "Japan Times",
    "slug": "japan-times",
    "url": "https://www.japantimes.co.jp/business/2026/10/09/tech/travel-companies-data-breach/"
  },
  "original_language": "en",
  "account": "Recent reports indicate potential data breaches at multiple travel companies in Japan, prompting fears that customer personal data may have been exposed. The impacted firms include Adventure, H.I.S., and Temairazu. According to Adventure's operator, up to 14.64 million customer records could be compromised, with approximately 4.13 million potentially containing login passwords. The breach, which occurred between October 2 and 4, affected both internal servers and cloud storage, with victims' names, birthdates, addresses, phone numbers, and email addresses at risk. However, passport numbers and credit card details remained unaltered. Adventure swiftly blocked unauthorized access, initiated an investigation, and suspended credit card payments while warning customers about potential phishing attempts. The company expressed regret and committed to enhancing security protocols.\n\nH.I.S., a major travel agency, disclosed that its Thailand-based subsidiary, H.I.S. Tours, experienced unauthorized access in December, potentially exposing passport information of up to 627 customers. This included dates of birth and passport numbers, information that H.I.S. attributed to inadequate safety measures despite implementing countermeasures. The company delayed the announcement due to the complexity arising from unrelated data muddling personal information during an internal investigation. Temairazu, a travel technology firm, also reported unauthorized access to its systems on September 28, potentially leading to fraudulent text messages soliciting banking details. The company promptly blocked the intrusion and restored its services.",
  "summary": "The affected companies include Adventure, which operates the travel booking website Skyticket, travel agency H.I.S. and travel company Temairazu.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}