Hackers breach Japanese hotel booking system, target guests in credit card phishing scam黑客入侵日本酒店预订系统,以信用卡钓鱼诈骗为目标,诈骗目标直指酒店客人
The operator of the Japanese accommodation reservation management system Temairazu on Monday revealed that its network was breached by hackers

TOKYO (TR) – The operator of the Japanese accommodation reservation management system Temairazu on Monday revealed that its network was breached by hackers , triggering a targeted phishing scam aimed at stealing credit card information from hotel guests.
Starting late night on September 21, multiple lodging facilities reported that individuals who had booked rooms were receiving fraudulent messages via WhatsApp, WeChat, email and SMS.
Armed with the guests’ actual reservation details obtained from the breach, the scammers posed as hotel representatives. The messages instructed victims to click malicious links to “confirm” their bookings, demanding they re-enter credit card information or make urgent payments.
Highly coordinated phishing campaign
During an internal investigation, the company confirmed that its system had suffered unauthorized access, admitting that a third party likely viewed or extracted personal guest data to launch the highly coordinated phishing campaign.
The company stated that it does not directly handle or store credit card data on its servers, but urged any guests who entered their payment details into the fraudulent websites to contact their credit card providers immediately.
Following the discovery of the cyberattack, the operator temporarily suspended parts of the Temairazu system to sever the unauthorized access, patch the vulnerabilities, and reinforce security monitoring. The system has since been restored to normal operations.
External cybersecurity experts
The operator has reported the breach to the police and the Personal Information Protection Commission, and has enlisted the help of external cybersecurity experts to assist in the ongoing criminal investigation.
In a public warning, the company is urging guests to ignore suspicious messages, refrain from opening unknown links, and avoid transferring money. Partner hotels and online travel agencies (OTAs) have also been instructed to change their login passwords and monitor their accounts for any unauthorized changes to bank transfer destinations or administrative privileges.
Published in Business , Crime and News
The editorial team at The Tokyo Reporter brings the site's readership the latest news from the under side of Japan.
Female JR East employee sues over restroom peeping tom cover-up: ‘It’s tough being cute’ Female JR East employee sues over restroom peeping tom cover-up: ‘It’s tough being cute’
Ex-Prudential sales rep loses personal data of 1,570 clients after quitting Ex-Prudential sales rep loses personal data of 1,570 clients after quitting
Tokyo MK taxi boss accused of hurling F-bombs and chairs in explosive ‘English test’ rampage Tokyo MK taxi boss accused of hurling F-bombs and chairs in explosive ‘English test’ rampage
Three Sony Life employees accused of swindling customers out of ¥55 million Three Sony Life employees accused of swindling customers out of ¥55 million
东京(TR)——日本住宿预订管理系统Temairazu的运营商周一透露,其网络遭到黑客入侵,引发了一场有针对性的网络钓鱼诈骗,旨在窃取酒店客人的信用卡信息。
从 9 月 21 日深夜开始,多家住宿场所报告称,已预订房间的客人通过 WhatsApp、微信、电子邮件和短信收到欺诈信息。
诈骗分子利用从数据泄露事件中获取的客人真实预订信息,冒充酒店工作人员。他们发送的信息指示受害者点击恶意链接“确认”预订,并要求他们重新输入信用卡信息或紧急付款。
高度协调的网络钓鱼活动
在内部调查期间,该公司证实其系统遭受了未经授权的访问,并承认第三方可能查看或提取了客人的个人数据,从而发起了一场精心策划的网络钓鱼活动。
该公司声明,其服务器上不直接处理或存储信用卡数据,但敦促任何在欺诈网站上输入支付详情的顾客立即联系其信用卡发卡机构。
网络攻击被发现后,运营商暂时关闭了Temairazu系统的部分功能,以切断未经授权的访问、修复漏洞并加强安全监控。目前,系统已恢复正常运行。
外部网络安全专家
该运营商已向警方和个人信息保护委员会报告了此次泄露事件,并已聘请外部网络安全专家协助进行正在进行的刑事调查。
该公司发布公开警告,敦促宾客忽略可疑信息,不要打开未知链接,并避免转账。合作酒店和在线旅行社(OTA)也被要求更改登录密码,并监控账户,防止银行转账地址或管理权限被未经授权更改。
发布于商业、犯罪和新闻版块
《东京记者报》的编辑团队为网站读者带来来自日本阴暗面的最新消息。
JR东日本女员工起诉公司掩盖厕所偷窥事件:“长得可爱真不容易”
一名前保诚保险销售代表离职后丢失了1570名客户的个人数据。
东京MK出租车老板被控在“英语测试”中大开杀戒,投掷脏话和椅子
三名索尼人寿员工被控诈骗客户5500万日元