MrMax — the Kyushu discount retailer — confirmed on October 6, 2026 that attackers abused its MrMax app and online store servers on October 3, exposing member data for up to 1,735,154 people. The company says leaked fields were limited to member ID, name, email address, and phone number, and that addresses, dates of birth, credit cards, passwords, and purchase history did not leave according to its investigation. Primary source: incident_20261006. Canonical record: https://breachhistory.com/mrmax/mrmax-app2026 (/mrmax/mrmax-app2026).
This is a verified MrMax data breach disclosure — dates, ceiling count, and negative findings come from MrMax’s own notice — not a ransomware leak-site listing. What this is not: a payment-terminal compromise at checkout lanes; MrMax explicitly separated card data and purchase histories from the accessed member database.
What happened on October 3
MrMax says it spotted suspicious server access on the evening of October 3, 2026 (Saturday). The company paused the affected services, blocked external access the same day, and started forensics. Investigators concluded that someone misused functionality built into the app/online-store software stack to get inside the server and copy a slice of member personal information.
The wording “misused software functionality” usually points to an application-layer bug, misconfigured endpoint, or abused legitimate feature — not a vague “we were hacked” line. MrMax has not, in the indexed notice, published a CVE number or third-party vendor name; treat the entry vector as under investigation unless a later update names a patch.
At publication MrMax reported no confirmed misuse of the leaked data — standard early language that means fraud teams have not tied scams to the incident yet, not a guarantee copies were not sold.
Timeline
- October 3, 2026 (evening) — Suspicious access detected; services temporarily stopped; external access blocked.
- October 3–6, 2026 — Forensics confirm member PII exposure path; scope set at up to 1,735,154 registrants as of October 3.
- October 6, 2026 — Public apology and FAQ published at mrmax.co.jp; PDF notice linked.
- October 6 onward — Affected users notified by email from [email protected]; incident desk accepts inquiries.
- Ongoing — Report filed with Japan’s Personal Information Protection Commission; police consulted per notice.
What remains unknown publicly
- Exact vulnerability — function name, patch status, and whether a vendor supplied the flawed module.
- Dwell time before October 3 — notice centers on detection day, not first intrusion timestamp.
- Whether all 1.73M rows were exfiltrated or the figure is the maximum registrant table size touched.
- Online-store-only vs app-only members — both populations are in scope but field completeness differs by registration choices.
What data was exposed
MrMax lists four positive fields:
- Member ID — internal loyalty identifier useful for account takeover when paired with weak reset flows.
- Name — personal or household account holder name as stored for the app/online store.
- Email address — channel for phishing and credential-stuffing against reused passwords.
- Phone number — SMS scams and vishing pretending to be MrMax support.
The notice warns that which fields apply depends on registration choices — not every member supplied every element. Still, the maximum affected population equals everyone registered as of October 3.
What MrMax says was not exposed
MrMax states clearly that the following were not involved:
- Home addresses
- Dates of birth
- Credit card information
- Passwords
- Purchase history
That negative list narrows scam realism: attackers should not know your last basket contents or card last-four from this incident alone. They can still impersonate MrMax because they may have your name, email, and phone — enough for convincing “account verification” scripts.
How the intrusion may have worked
Without a CVE, defenders can only map patterns. Retail app stacks often expose:
- Authenticated APIs that return member profiles when sequential IDs are guessed
- Admin or batch-export features hidden behind weak session controls
- Legacy integration endpoints shared between app and online store
MrMax’s “misused software functionality” phrase suggests the attacker did not need stolen passwords for every victim — they found a server-side path that returned member rows. Security teams at other retailers should review similar APIs for authorization gaps while waiting for MrMax technical detail.
Who is at risk
MrMax app and online-store members registered on or before October 3, 2026 — up to 1.735 million accounts.
People reusing passwords between MrMax and email or banking — even though passwords were not in the leaked set, many users recycle credentials attackers can guess from older breaches.
Family plan holders where one email manages multiple member IDs — one phishing success may unlock several loyalty numbers.
Kyushu communities where MrMax is a default grocery run — local SMS lures in Japanese will sound plausible with accurate names.
Phishing scenarios after the MrMax breach 2026
- Fake coupon SMS citing MrMax app points — the notice says purchase history was not taken, so “we saw you bought X” messages are red flags unless from another leak.
- “Online store password reset required” emails linking to credential harvesters.
- Support calls asking for credit card numbers — MrMax says it will never ask for card or password details by cold contact.
Japan retail app context — October 2026
MrMax lands in a crowded week of Japanese chain-app disclosures. Restaurant and panel sites reported their own unauthorized access stories the same month. The harm profile here is contact-data theft without payment instruments — similar to other loyalty incidents where criminals optimize for SMS fraud volume rather than card-not-present fraud.
Readers comparing BreachHistory entries should note scale: MrMax’s 1.735 million ceiling sits between mid-size regional leaks and multi-million national app incidents. Field mix matters more than headline count — absence of addresses reduces physical mail fraud but not digital impersonation.
What MrMax and regulators said
MrMax — via incident_20261006 — apologizes, lists fields, denies card/password/history loss, promises email notification, and opens [email protected] for questions. It reports the Personal Information Protection Commission and police consultation.
English trade press may lag the Japanese PDF; treat the company page as authoritative for field lists and counts.
What you should do
- Read email from [email protected] carefully; ignore look-alike domains.
- Do not open attachments in unexpected “MrMax incident compensation” messages.
- Rotate passwords if you reused your MrMax or online-store password elsewhere — even though passwords were not leaked here.
- Enable MFA on email and financial apps tied to your registered phone number.
- Call official channels if unsure — use contacts from mrmax.co.jp, not SMS links.
- Monitor accounts for unrelated fraud; absence of card data in this leak does not immunize you from other scams using the same phone number.
- Bookmark /mrmax/mrmax-app2026 for updates if MrMax revises scope.
Was I affected?
If you registered for the MrMax app or online store by October 3, 2026, assume you are in the maximum population until MrMax says otherwise. Individual email notices are the primary confirmation channel. Lack of mail yet does not prove safety — batches take days, and spam filters swallow retail senders.
Online store vs app membership
MrMax combined both programs in one incident because they share backend infrastructure. You might shop in physical stores rarely yet still hold an online account — check whether you created credentials during COVID-era delivery pushes or app coupon campaigns.
Technical notes for defenders
- Map every API that returns member ID + PII; require per-user authorization, not just session presence.
- Alert on bulk profile exports or abnormal query rates from app server subnets.
- Pre-draft customer comms that explain missing purchase-history exposure — reduces helpdesk load when scammers claim otherwise.
Business continuity
MrMax restored service after the October 3 pause — the notice focuses on data confidentiality, not prolonged outage. Shoppers should expect normal app and online-store function while forensic work continues; watch for patch-app prompts or forced logouts if engineers rotate secrets.
Incident desk and documentation
Save PDF and web copies of the October 6 notice if your employer or insurance asks for proof of third-party exposure. MrMax’s incident desk email is the supported path for individualized questions; store staff may not have breach details at registers.
Long-term monitoring
Contact-only leaks age into slow-burn SMS campaigns. If MrMax publishes additional fields or confirms exfiltration volume, update your plan. Until then, the attested facts already justify skepticism toward any message quoting member IDs or asking for payment details.
Kyushu discount retail and digital loyalty
MrMax built its brand on large-format discount stores across Kyushu and neighboring regions, with app coupons and an online store accelerating during pandemic-era shopping shifts. The October 3 intrusion hits that digital spine — not point-of-sale terminals in every aisle. Shoppers can still pay cash or card in stores; the stolen rows are membership identifiers tied to digital engagement.
That distinction helps families prioritize responses: there is no need to cancel credit cards solely because of MrMax’s notice unless you see unrelated fraud. There is a need to treat SMS about “MrMax app refunds” as hostile until verified.
October 3 service pause in plain terms
Pausing app and online-store services on detection day prevented attackers from continuing scripted extraction while engineers rotated secrets and reviewed logs. Short outages frustrate coupon hunters but reduce ongoing data loss. If you attempted orders that Saturday evening, retry through official channels after confirming the site is live — and ignore third-party “backup checkout” links sent by email.
Member ID plus contact — fraud mechanics
Without passwords or purchase history, criminals still automate vishing lists sorted by member ID. A caller who opens with your ID and name sounds like internal support. MrMax says it will not ask for card numbers or passwords via unsolicited contact — use that as your litmus test.
Member IDs also appear on printed materials and barcode scans in stores. Physical exposure in stores is normal; digital bulk exposure is not. Assume bulk availability changes the economics for spam campaigns.
Online store accounts overlapping app logins
MrMax merged app and online-store membership in one incident because backends overlap. You might have registered online for ship-to-home promotions without installing the app — you are still within the 1,735,154 ceiling if the account existed on October 3.
Personal Information Protection Commission reporting
MrMax says it reported to the PPC and consulted police. Japanese regulators may publish guidance or statistics later; English readers should monitor the canonical BreachHistory row rather than machine-translated rumor threads.
Comparison with other October 2026 Japanese app leaks
October brought multiple hospitality and retail member-system disclosures. MrMax’s field mix is narrower than full-profile restaurant apps that include addresses and birthdates, but the headcount is larger than many regional chains. Scale times contact data equals sustained SMS fraud potential across Kyushu phone prefixes.
Children and family accounts
Households sometimes register loyalty accounts in a parent’s name with children’s contact info for school-age coupon programs. If your family shared one email across members, a single compromised row still enables targeted messages referencing MrMax branding.
Reusing email for password recovery elsewhere
Even when password fields stay secure, email compromise via phishing can reset banking or social accounts. Harden the inbox tied to MrMax registration first — MFA, recovery codes stored offline, and removal of SMS-only recovery where safer options exist.
Incident desk workflow
Save the October 6 PDF notice from mrmax.co.jp if your employer or cyber-insurance asks for documentation. Email [email protected] from an address you control; avoid posting member IDs on public social threads where scammers harvest replies.
Developer accountability questions
MrMax has not named the abused software feature in English materials. When updates arrive naming patches or vendors, reassess whether similar modules exist in other retailers you operate. Until then, generic API authorization reviews are the prudent corporate response.
Physical store safety vs digital exposure
Store shopping remains safe from a payment-terminal perspective per MrMax’s negative list. Digital impersonation is the open risk surface. Clerks at registers cannot verify breach status — use corporate channels only.
PDF notice parity with the web page
MrMax linked a PDF mirroring the October 6 web notice — useful for employees who need employer-facing proof. Download from mrmax.co.jp rather than unofficial mirrors that may inject phishing links.
Coupon fraud without purchase history
Attackers lacking basket history may still blast generic “double point weekend” lures. Legitimate MrMax campaigns exist; verify through the app’s official news tab, not SMS alone.
October 6 publication timing
Three days from detection to public notice is fast for a 1.7M ceiling investigation — suggests MrMax prioritized APPI-aligned warning over waiting for exhaustive forensics. Counts may shrink later if investigators find the accessed table was smaller than the registered member universe.
Regional media and Japanese primary sources
English readers should expect Kyushu newspapers and TV to summarize the incident in Japanese before global wire services pick it up. Machine translation of local reporting can supplement but not replace mrmax.co.jp wording on fields.
After the notice — staying safe in stores and online
MrMax’s physical stores remain the core business; the breach does not change in-aisle payment safety according to the company’s negative list on cards and passwords. What changes is your inbox and SMS feed — treat every unexpected “MrMax security” message as untrusted until you open the official app yourself or call numbers listed on mrmax.co.jp, not numbers embedded in the text of a cold message.
Canonical record and sources
BreachHistory indexes MrMax as company-confirmed unauthorized access with up to 1,735,154 members and four positive data types. Update at https://breachhistory.com/mrmax/mrmax-app2026 if counts or fields change.
MrMax shoppers should treat October 3 as the detection anchor, assume contact details for up to 1.73 million members are in criminal hands unless future notices narrow the set, and ignore scammers who claim access to cards or receipts the company says stayed offline.