Daiki Suisan warned on October 5, 2026 that its official sushi-chain app suffered unauthorized access confirmed on September 15, 2026, creating a possible leak for 174,933 customers who registered between November 1, 2024 and September 15, 2026. Fields at risk include name, phone, email, gender, postal code, address, and date of birth where provided; passwords live on a separate server and were not in the possibly exposed set. Source PDF: 00000164_file.pdf. Canonical: https://breachhistory.com/daiki-suisan/daiki-suisan-app2026 (/daiki-suisan/daiki-suisan-app2026).
This is a verified Daiki Suisan data breach notification under Japan’s APPI framing — the company cannot rule out leakage even though it has not confirmed external publication or fraud yet. What this is not: a confirmed paste on a leak site with downloadable rows; Daiki Suisan explicitly says actual external leak and misuse are unconfirmed at notice time.
What happened by September 15
Daiki Suisan discovered unauthorized access to the app system on September 15, 2026. It blocked external paths, strengthened monitoring, and engaged an outside forensic firm. Because investigators could not eliminate the possibility that personal data left the environment, the chain issued a broad customer warning rather than waiting for proof of resale on criminal forums.
That cautious posture matters for readers: “possible leak” notices often precede definitive exfiltration metrics by weeks. Assume defensive action now; update if Daiki Suisan later confirms copies were not taken.
Who is in scope
The affected cohort is anyone who registered for the Daiki Suisan official app during the window 2024-11-01 through 2026-09-15, including people who later deleted accounts — 174,933 people total per the PDF.
Optional profile fields mean not every row contains every column. Address and date of birth appear only when customers voluntarily added them; gender and postal code likewise depend on registration choices.
Timeline
- November 1, 2024 — Start of registration window included in the incident.
- September 15, 2026 — Unauthorized access confirmed; containment and monitoring upgrades begin.
- September 15 – October 5, 2026 — Forensics with external specialists; Daiki Suisan consults Personal Information Protection Commission.
- October 5, 2026 — Public PDF apology and guidance published.
- Ongoing — Email notices to registered addresses; app remains available for normal use.
What remains publicly unsettled
- First day of attacker access before September 15 discovery.
- Technical root cause — vulnerability class, stolen credentials, or supplier issue — not named in the PDF excerpt.
- Confirmed exfiltration volume — “cannot deny possibility” language stops short of attested row counts leaving the network.
What data may have been exposed
- Name
- Phone number
- Email address
- Gender
- Postal code
- Address (optional registration)
- Date of birth (optional registration)
Together, optional address and DOB fields push this incident toward identity-fraud territory for subscribers who filled out complete profiles — worse than email-only restaurant leaks, even if passwords stayed on another server.
What Daiki Suisan says was not exposed
Passwords — stored on separate infrastructure from the possibly accessed database.
The PDF also states that, as of its writing, Daiki Suisan has not confirmed that information was published broadly or misused in fraud. That is reassurance about observed abuse, not a guarantee of containment.
How separate password servers help — and where they do not
Splitting credential stores from profile tables is good architecture: attackers who read member demographics may still lack password hashes. Users remain vulnerable if they reuse the same password elsewhere or if password-reset emails are intercepted using leaked phone numbers.
Daiki Suisan promises it will never ask customers to submit passwords or one-time codes in connection with this incident — a useful baseline for spotting impersonators.
Who is at risk
App registrants in the 174,933 cohort — especially those who added home addresses and birthdates for coupons or delivery experiments.
Household members at shared addresses when the primary account holder enrolled.
People expecting sushi-chain marketing SMS — legitimate campaigns will compete with scam texts using accurate names.
Phishing patterns to expect
- Fake reservation or points-expiry links in Japanese.
- “Confirm your Daiki Suisan app password” forms — the company says it will not solicit passwords for this event.
- Refund lures citing the October 5 notice without linking to daiki-suisan.co.jp.
Restaurant app context in Japan
Sushi and casual-dining chains rely on apps for waitlists, coupons, and repeat visits. Those databases hold marketing-grade PII even when they exclude payment cards. October 2026 saw multiple hospitality brands disclose member-system intrusions; Daiki Suisan’s “possible leak” wording sits on the cautious end of that spectrum.
What the company asked customers to do
- Ignore suspicious email, SMS, and calls; do not open unknown links or share personal data.
- Use the dedicated hotline 0120-811-266 (9:00–18:00, including weekends/holidays) rather than general store phones for incident questions.
- Watch registered email for official guidance — not forwarded screenshots on social media.
- Continue normal app use unless future notices say otherwise; service was not discontinued.
Was I affected?
If you created the official app account between November 2024 and mid-September 2026, you are in the published population. Email notification is the primary channel; if you unsubscribed from mail but kept the app, verify status through the hotline.
APPI reporting posture
Daiki Suisan says it reported and consulted with the Personal Information Protection Commission. That does not automatically publish a public docket with your name — but it signals regulators are aware if scope widens.
Forensic investigation continuing
External specialists remain on the case per the PDF. Future updates might confirm whether data actually exited, which subnets were touched, or whether additional fields were involved. Bookmark the canonical BreachHistory URL instead of trusting forum reposts.
Optional fields and risk scoring
Security teams helping family members should ask: did you enter your home address for a delivery trial or birthday perk? If yes, treat this like a partial identity bundle leak even without passwords. If you minimized profile data, exposure may be only name plus contact channels — still enough for SMS fraud.
Long-term monitoring
When companies cannot deny leakage, assume criminals eventually obtain samples even if official misuse reports stay at zero. Rotate passwords on email accounts tied to the app, enable MFA, and watch for address-change attempts at other services that use SMS recovery.
Daiki Suisan’s app role in the chain
Daiki Suisan operates conveyor-belt sushi and related brands across Japan, using its official app for promotions, wait management, and repeat-visit incentives. The app’s member database sits apart from in-store cash registers for payment — consistent with the PDF’s focus on profile fields rather than card swipes.
Why “possibility of leak” language appears
Japanese operators sometimes notify when forensics cannot prove data stayed inside the network even if they also lack evidence of public posting. That legal-prudent phrasing frustrates readers who want a yes/no exfiltration answer. Practically: behave as if copies may exist; update your plan if Daiki Suisan later confirms zero egress.
November 2024 registration start date
The window beginning 2024-11-01 likely tracks a app relaunch or material backend migration rather than the chain’s entire historical CRM. Long-time customers who never migrated to the new app may fall outside the 174,933 — but assume inclusion if you created any account after that date.
Gender and postal code fields
Demographics enable segmented scams — fake surveys referencing your prefecture or gendered marketing templates. They are not high-sensitivity on their own, but they increase click-through when combined with your name and mobile number.
Address and DOB optional registration
Many users skip optional fields for speed. If you added address or birthdate for a birthday coupon, your row is more valuable on identity markets. Check the app profile settings now and remove fields you no longer need after the incident response period ends.
Password segregation architecture
Daiki Suisan emphasizes passwords on a separate server. Ask support whether password-reset SMS uses the phone number confirmed in the leak — if yes, prioritize carrier SIM protections and consider Google/Apple Authenticator on email instead of SMS where available.
Hotline-only support strategy
The PDF routes incident questions to 0120-811-266 and explicitly says stores and general contact forms cannot handle case-by-case breach guidance. That reduces misinformation from well-meaning floor staff but requires patience on hold times after major news coverage.
App continues operating — user experience
Unlike GMO infoQ’s hard shutdown, Daiki Suisan kept the app live with strengthened controls. You do not need to uninstall the app; you should update it when the publisher pushes security releases and avoid sideloaded “security fix” APKs from chat apps.
September 15 detection vs October 5 disclosure
Three weeks elapsed between confirmation and public PDF — time likely spent on forensics, regulator consultation, and preparing member email batches. Delay does not imply cover-up; it reflects APPI process. Still, attackers had a head start if data actually exited early in September.
Sushi-chain fraud seasonality
Autumn tourism and weekend family visits spike conveyor-belt traffic. Scammers timing SMS during dinner hours may see higher tap rates. Slow down on links when hungry — verify through the official app banner messages instead.
Corporate communication for minors
Parents who registered children for kid-meal perks should watch for grooming or phishing targeting minors’ phones linked to family accounts.
Cross-check with email notifications
Official mail should come from domains you already received marketing from — compare headers carefully. Forward suspicious samples to the hotline rather than replying with personal data.
Insurance and credit monitoring
Japan lacks U.S.-style universal breach credit freezes, but optional identity monitoring services may help if you supplied DOB and address. Document the PDF date for any future claims.
Restaurant competitor context
Other dining brands disclosed member leaks the same month with different field mixes. Do not assume protections from one chain apply to another — read each notice separately.
Technical indicators waiting game
When Daiki Suisan or its forensic vendor publishes IoCs — IP ranges, malware hashes, or vulnerability IDs — defenders at other hospitality companies should ingest them quickly. None were public in the October 5 PDF indexed here.
Reading the PDF as a legal document
Japanese breach PDFs often use precise statutory phrases — “cannot deny possibility of leak” — that sound weak to casual readers but carry deliberate regulatory meaning. Lawyers advising franchises should compare this text to APPI article 26 notification templates rather than to U.S. state breach forms.
174,933 including withdrawn accounts
Including users who already deleted the app widens the moral notification circle: you may get email at an address you forgot you used. Update spam filters to allow daiki-suisan.co.jp mail temporarily.
Gender field sensitivity
Gender data enables targeted fraud and harassment. If you supplied it for marketing segmentation, consider whether future optional fields are worth the risk after this incident.
Chain-wide reputation vs single app
Daiki Suisan’s brand spans many storefronts; the app breach does not imply POS malware at every location. Communicate that distinction to elderly relatives who may fear using credit cards in-store without cause.
Waiting for definitive exfiltration proof
If later notices confirm data never left, you can downgrade monitoring intensity — but GMO-style point fraud is absent here, so the main risk remains contact phishing rather than account balance drains.
Member email batches and language
Daiki Suisan promised sequential email to registered addresses. Messages may be Japanese-only; international residents who enrolled with English mail clients should still monitor spam folders and add daiki-suisan.co.jp to safe-sender lists temporarily. If you changed email since registering, the hotline is the path to update contact preferences — not unofficial social media DMs claiming to “refresh” your profile.
Volunteered address data and delivery experiments
Sushi chains occasionally trial delivery or preorder perks that ask for home addresses. If you joined such a test, your leaked row may be richer than a dine-in-only member. Review whether you still need that address on file after the incident; minimizing retained PII reduces future blast radius if another bug appears.
Coordination with family members
If a parent registered the app for a household, explain to everyone whose phone number appears in the profile that Daiki Suisan-themed SMS may arrive. Children and older relatives are common click-through targets when messages promise free sushi or urgent account verification.
Forensic updates to watch for
Daiki Suisan promised homepage and app announcements if new facts emerge. Those updates might confirm exfiltration, name a patched module, or shrink the 174,933 figure if investigators find backups were untouched. Subscribe to official news feeds rather than repost accounts that mix this incident with unrelated leak-site gossip.
Save a copy of the PDF now in case later web edits clarify scope; regulators sometimes reference the first public wording in enforcement discussions.
Until such an update lands, the October 5 PDF remains the authoritative field list for the Daiki Suisan data breach 2026 — names, phones, emails, optional address and date-of-birth fields, and segregated passwords — and the practical answer to “was I affected?” is yes if you registered in the stated window.
Canonical record and sources
BreachHistory indexes Daiki Suisan as company-confirmed unauthorized access with 174,933 possibly affected registrants and passwords segregated. Update at https://breachhistory.com/daiki-suisan/daiki-suisan-app2026 if exfiltration is confirmed or denied definitively.
Daiki Suisan app users in the November 2024–September 2026 window should operate as if contact and optional identity fields may have left the app environment, keep using official hotlines for questions, and refuse any “security check” that asks for passwords the company says it will never request.