< Back to all clusters
[TECHNOLOGY] · Japan · 2 sources

started · updated

Commune Inc. reports data breach affecting 307,000 users

Commune Inc., a provider of online community services, announced that its ‘Commune’ and ‘Commune for Work’ platforms suffered unauthorized access, potentially leaking information of approximately 307,000 members.

The breach occurred through attackers exploiting system vulnerabilities to obtain private community invitation links and impersonate administrators to view, extract, or overwrite member data. The leaked information includes display names and self-introductions for about 181,000 members, and email addresses for approximately 126,000 members. Notably, this email leak includes roughly 42,000 records belonging to Commune employees and demo accounts.

Multiple organizations using the service reported impacts. Yamaha confirmed potential leaks affecting 1,600 members of its network engineer community, while Suzuki reported approximately 3,000 members of ‘Suzuki Village’ may have had email addresses, gender, residence, and age information exposed. Other affected entities include Koikeya, Morinaga Milk Industry, Aomori Prefecture’s tourism community, and Bandai Namco Experience.

While credit card information, direct messages, and passwords were generally not compromised, 144 members had their passwords changed to temporary ones without authorization. Commune has since implemented security measures, blocked unauthorized access routes, and begun a phased resumption of services as of October 8. The company has advised members to remain vigilant against potential phishing attempts.

Entities

Aomori Prefecture · Commune Inc. · Koikeya · Suzuki · Yamaha