JR East Reports Potential Data Leak Affecting 2.06 Million Members, While View Card Exposure May Reach 4.03 Million

October 9, 2026

Summary

JR East says personal information linked to about 2.06 million Eki-net and Otona no Kyujitsu Club members may have been exposed. The incident is connected to unauthorized access at IDC Frontier, a SoftBank subsidiary. Potentially affected information includes email addresses, membership numbers, credit-card expiration dates and dates of birth, depending on the service. JR East says names, addresses and full credit-card numbers are not believed to have been leaked. View Card separately reported that about 4.03 million email addresses may have been exposed. Customers should be alert for phishing emails, fake account warnings and suspicious payment requests. The investigation is continuing, so check the full article for the latest details and practical precautions.

JR East Reports Potential Data Leak Affecting 2.06 Million Members, While View Card Exposure May Reach 4.03 Million

JR East investigates possible personal information leak

East Japan Railway Company, commonly known as JR East, announced on the 9th that personal information belonging to approximately 2.06 million members of two group-related services may have been exposed following unauthorized access to a data-center operator.

The potentially affected accounts include around 1.67 million members of Ekihai—the JR East online railway and travel reservation service known in Japan as Eki-net—and approximately 390,000 members of the Otona no Kyujitsu Club, a membership program popular with older travelers. JR East said the incident was connected to unauthorized access at IDC Frontier, a SoftBank subsidiary that provides data-center and information-technology services.

Information that may have been exposed

For Eki-net members, the potentially leaked information is reported to be email addresses. For Otona no Kyujitsu Club members, the information may include email addresses, membership numbers, credit-card expiration dates and dates of birth.

JR East said there is no indication that customers’ names, addresses or full credit-card numbers were exposed in the incident. This distinction is important because the information reportedly involved could still be used in targeted phishing attempts, even though it does not include complete payment-card details.

View Card also reports possible exposure

JR East also disclosed a separate potential impact involving View Card, the group’s credit-card company. Approximately 4.03 million email addresses may have been exposed, according to the company. JR East said that names, addresses and full credit-card numbers are not believed to have been leaked in that case either.

The company is investigating the circumstances surrounding the unauthorized access in cooperation with the relevant service providers. Customers may receive further information as the investigation determines which records were accessed and whether the data was actually taken or misused.

What customers should watch for

People who use Eki-net, Otona no Kyujitsu Club or View Card should be cautious about unexpected emails, text messages or telephone calls claiming to come from JR East or a related company. Suspicious messages may ask recipients to click a link, confirm account information, provide a password or make an urgent payment.

Customers should avoid using links in unsolicited messages and instead access official services by entering the known website address directly or using an official application. They should also avoid sharing one-time passwords or payment information with callers or senders whose identity cannot be independently verified. Because email addresses may have been exposed, users should be particularly alert to convincing messages that refer to train reservations, membership renewals, loyalty benefits or credit-card security.

Why the incident matters to travelers in Japan

Eki-net is widely used by residents and international visitors to reserve tickets for JR East services, including popular routes to destinations such as Tokyo, Sendai, Nagano and Hokkaido connections. The Otona no Kyujitsu Club is closely associated with rail travel among older members, while View Card is used by many JR East customers for railway-related purchases and everyday spending.

The incident highlights the security risks that can arise when companies rely on external cloud, hosting and data-center providers. It also shows why travelers and residents in Japan should keep contact details updated, use unique passwords and monitor account activity. At this stage, JR East’s announcement concerns a potential leak, and the full scope and consequences remain under investigation.