July 14, 2026: Tokyo-listed Fabrica Holdings disclosed that subsidiary Media 4u detected unauthorized access to its SMS transmission system on June 24, 2026. Attackers stole an account-management file with 95,412 records and abused the platform to send 280 unauthorized text messages before the company went public three weeks later.
What happened
Media 4u runs an enterprise SMS gateway — the plumbing behind bulk and transactional texts for Japanese businesses. Intruders reached the system's management console, pulled a configuration export, and briefly used the live sending path for their own messages.
Fabrica said it cut off access, preserved logs, hired outside forensics, and forced password resets across all customer accounts. Multi-factor authentication and tighter monitoring are planned, though the company has not published a full technical timeline.
What data was exposed
The leaked file held account-management rows, not necessarily one row per person. Fabrica flagged 22,928 entries that may qualify as personal information because they include contact names or identifiable email addresses. Fields in scope include:
- Account IDs and usernames
- Contact names
- Prefecture and postal code data
- Notification email addresses
Importantly, Fabrica stated that passwords, password hashes, API keys, authentication tokens, and billing or payment data were not in the compromised file. That limits immediate credential-stuffing risk but does not eliminate phishing — an attacker who knows your company name, region, and notification email can craft convincing fake invoices or “account suspension” texts.
The rogue SMS angle
Two hundred eighty texts sent without authorization is small in telecom scale but large in trust damage. Recipients may assume a message from a known sender ID is genuine. Fabrica is still investigating message content and which accounts were abused to send them.
Action items for Media 4u customers
- Complete any forced password reset Fabrica issued and enable MFA when available.
- Treat unexpected SMS referencing Media 4u or Fabrica as suspicious until verified through official channels.
- Rotate API keys on integrations that pointed at Media 4u, even though keys were not in the leaked file — standard post-incident hygiene.
- Watch for follow-on phishing using prefecture or postal details from the dump.
Canonical record: Media 4u 2026 breach on BreachHistory.