Local Chorus
Local news from local sources, read in your language.
Developing

Citizen Watch says data of about 100,000 people may have leaked in contractor breach

🇯🇵 Japan, Tokyo 06:44 IT & software Business3 Tech updated 9 h ago first reported by 東京新聞

In short

Citizen Watch said on Oct 6 that personal information on about 100,000 people may have leaked after unauthorized access to a server run by an outside contractor. The access was to a server of Tokyo-based Scala Communications between the night of Oct 2 and the morning of Oct 3, and the data may include names, addresses, phone numbers and, if customers entered them, bank account or credit card numbers. Scala said up to 713,126 records across up to five companies may have leaked from the same server; Daiwa Securities reported a separate leak of about 220,000 records from the same service on Oct 5.

Read the full story 2 min read

Citizen Watch said on Oct 6 that personal information on about 100,000 people may have leaked after unauthorized access to a server run by an outside contractor. The information had been entered in inquiry forms on the company's brand websites. The company said no unauthorized access to its own systems had been confirmed. [ 1 , 2 , 3 , 4 ]

The affected server belongs to Scala Communications, a Tokyo-based system operator that provides the i-ask FAQ and inquiry system, according to the company and Scala's parent company Scala. Scala said a third party logged into the i-ask management site and placed a malicious program on the server between around 20:30 on Oct 2 and around 08:00 on Oct 3. It said it blocked the access on the morning of Oct 3 and reported the matter to its customers the same day. [ 2 , 3 ]

The data that may have leaked includes names, addresses, phone numbers and email addresses. Bank account and credit card numbers are also included in the disclosure if customers had written them into the inquiry text. Nishi-Nippon Shimbun said the forms covered inquiries submitted from January 2015 to September 2026, while ITmedia described the data as that stored in the inquiry system as of Oct 3. ITmedia named the brand sites as Citizen, Bulova and Frederique Constant. [ 2 , 3 ]

Citizen said the impact is limited to data stored in the contractor's system, and that the information could not be used to access its official online store, the MY CITIZEN and Citizen Owners Club membership services, its production systems or its internal network. It said no secondary damage connected to the breach had been confirmed as of Oct 6. [ 3 ]

The company said it is contacting affected individuals individually and has set up a dedicated inquiry form. It urged people to be careful of suspicious emails pretending to come from the company or related parties, and to avoid providing personal information, opening attachments or clicking links. It said it had already reported to the Personal Information Protection Commission and consulted a police station. The affected system is no longer used for new inquiries and is scheduled to be retired in mid-October, after which stored personal data will be deleted. [ 2 , 3 ]

Scala said data for up to five companies, up to 713,126 records in total, may have leaked from the same server, counting repeat inquiries by the same user, and that the actual number of people affected is under investigation. Daiwa Securities said on Oct 5 that information on about 220,000 accounts, including account numbers, may have leaked through the same contact-management service. [ 3 ]

Why it matters

The documents show the same contractor's server held inquiry data for up to five companies, and Daiwa Securities reported a possible leak of about 220,000 records through the same service, so the incident extends beyond one company. Citizen says it found no access to its own systems and no secondary damage as of Oct 6, but it is warning affected customers about suspicious emails. The case centres on the risks of outsourcing customer inquiry handling to a shared outside system.

Key facts

  • Citizen Watch announced on Oct 6 that personal information on about 100,000 people may have leaked after unauthorized access to a contractor's server. [ 1 , 2 , 3 , 4 ]
  • The server belonged to outsourced system operator Scala Communications of Tokyo's Shibuya Ward, which provides the i-ask FAQ system. [ 2 , 3 ]
  • The unauthorized access took place between the night of Oct 2 and the morning of Oct 3. [ 2 , 3 , 4 ]
  • Potentially leaked items include names, addresses, phone numbers and email addresses, plus bank account or credit card numbers if customers entered them in the inquiry form. [ 2 , 3 ]
  • The data came from inquiry forms on Citizen's brand websites, which ITmedia named as Citizen, Bulova and Frederique Constant. [ 2 , 3 ]
  • Citizen said it is contacting affected individuals individually, has set up a dedicated inquiry form, and has reported to the Personal Information Protection Commission and consulted police. [ 2 , 3 ]
  • Scala said that up to five companies' inquiry data, up to 713,126 records in total, may have leaked from the same server, counting repeat inquiries, so the actual number of people affected is under investigation. [ 3 ]
  • Daiwa Securities said on Oct 5 that about 220,000 records including account numbers may have leaked through the same contact-management service. [ 3 ]

Confirmed by several sources

  • Citizen Watch announced on Oct 6 that personal information on about 100,000 people may have leaked after unauthorized access to a contractor's server. [ 1 , 2 , 3 , 4 ]
  • The unauthorized access was to a server operated by the outsourcing company Scala Communications, based in Tokyo, and occurred between the night of Oct 2 and the morning of Oct 3. [ 2 , 3 , 4 ]
  • Potentially leaked data includes names, addresses, phone numbers and email addresses, and also bank account or credit card numbers if customers entered them. [ 2 , 3 ]
  • Citizen said it is contacting the affected people individually and warning them to be careful of suspicious emails. [ 2 , 3 ]

Still unclear

  • The exact number of people affected. Scala said up to 713,126 records across up to five companies may have leaked from the same server, but the figure counts repeat inquiries by the same user, and Scala says the actual number of individuals is still under investigation (doc 3).
  • The period covered by the affected inquiry data. Nishi-Nippon Shimbun says the forms covered inquiries from January 2015 to September 2026 (doc 2), while ITmedia describes the data as that stored in the inquiry system as of Oct 3 (doc 3); the outlets describe the scope differently.
  • Whether any personal information actually leaked, rather than possibly leaked. Citizen and the covering outlets say only that a leak may have occurred (docs 1, 2, 3, 4).
  • Whether bank account or credit card data actually leaked. The documents say such data may be included only if customers had entered it in the inquiry form's free-text field (docs 2, 3).

What local media are saying

Business mediaTokyo Shimbun, Nishi-Nippon Shimbun and TBS NEWS DIG reported Citizen Watch's announcement in brief: the possible leak of about 100,000 people's data, the unauthorized access to a contractor's server, the types of data involved and the warning to affected customers. TBS and Tokyo Shimbun highlighted in their headlines that bank account and credit card information may also have leaked. [ 1 , 2 , 4 ]
Technology mediaITmedia gave the most technical account, naming the i-ask FAQ system and operator Scala Communications, the access window on the server, the connection to the separate Daiwa Securities case, Scala's estimate of up to five companies and 713,126 records, and Citizen's statements that its own systems were not accessed and that no secondary damage had been confirmed. [ 3 ]

Timeline, local time

  1. A third party begins unauthorized access to a Scala Communications server hosting the i-ask system, installing a malicious program on it, according to Scala's parent company Scala. [ 3 ]
  2. Scala Communications blocks the access in the morning and reports the incident to its customers the same day, according to Scala. [ 3 ]
  3. Daiwa Securities announces that information on about 220,000 accounts, including account numbers, may have leaked through the same contact-management service. [ 3 ]
  4. Citizen Watch announces that about 100,000 people's personal information may have leaked, and says it has reported to the Personal Information Protection Commission and consulted police. [ 2 , 3 , 4 ]
  5. Tokyo Shimbun reports the possible leak, focusing on unauthorized access at the contractor. [ 1 ]
  6. Nishi-Nippon Shimbun reports the announcement, including the October 2 night to October 3 morning access window. [ 2 ]
  7. ITmedia reports details including the i-ask system, the link to the Daiwa Securities case and Scala's figure of up to 713,126 records across up to five companies. [ 3 ]
  8. TBS NEWS DIG reports that bank account and credit card data may also have leaked. [ 4 ]