← Blog

Skyticket Breach: 14.64M Customer Records at Risk

Share on X

Adventure Inc. (TSE Growth: 6030), operator of the skyticket comparison and booking site, published an October 9, 2026 IR apology stating that unauthorized access led to customer personal information leaving — or risking leaving — its systems at massive scale. About 14,640,000 personal-information pieces are in scope for the primary server intrusion, of which about 4,130,000 include member login password hashes. Separate tracks cover 17,780 operations-management access cases (including duplicates) and about 12,000 bus-reservation page views. Adventure says it does not store passport images or credit-card numbers on its side (cards live with payment processors); stored-card checkout was stopped around October 7. IR summary: JapanIR disclosure page. Canonical: https://breachhistory.com/adventure-skyticket/skyticket-adventure2026 (/adventure-skyticket/skyticket-adventure2026).

This is a verified Skyticket data breach — listed-company IR, PPC report, concrete counts, and containment steps. What this is not: a claim that passport images or raw card PANs were sitting in Adventure’s database and walked out. The company is explicit that those artifacts were not stored for the scenarios it describes.

What happened — three unauthorized-access tracks

Adventure’s notice frames the matter as three distinct unauthorized-access paths, not one monoculture incident. That structure matters for customers: your risk profile depends on which systems touched your data.

(1) Company servers — ~14.64 million

Attackers improperly operated part of skyticket’s management functionality, then reached other company servers and cloud-stored data. Access window: October 2–4, 2026. Discovery: October 5. Population: customers who registered or entered data on skyticket — about 14,640,000 pieces — including about 4,130,000 with hashed member login passwords.

Fields Adventure lists for this track include names (including passport-notation spellings), dates of birth, emails, phones, postal codes and addresses, remittance sender names used for bank transfers, and hashed login passwords. Passport numbers were not leaked on this track, the company says.

(2) Operations / business-management system — 17,780 cases

Date of occurrence: September 20, 2026. Discovery: September 28. Cause described as exploitation of a vulnerability in the business-management system. Count: 17,780 (duplicates included; additional volume still under investigation).

Data that leaked or may have leaked: names, phones, and refund destination bank details (institution, branch, account type, account number, account holder). For some customers, email and DOB (68) or address (18) also appear. Passport numbers are not confirmed leaked here; Adventure says it continues verifying that negative. Separately, Adventure notes unauthorized login to one member account on September 9.

(3) Bus reservation completion pages — ~12,000 reservations

Window: August 3–October 1, 2026. Discovery: October 1. Cause: bus reservation completion pages were viewable without login and were mechanically browsed by a third party; fixed October 1. About 12,000 reservations (companion travelers mean headcount can exceed that).

Viewed or potentially viewed: reserving party’s name (kana), age, gender, DOB if registered, email, phone, member ID, device type, payment method and amount, reservation timestamps, boarding service details (times, stops, operator, flight/bus names as applicable, operator reservation numbers), and companion name/age/gender. Passport numbers not leaked on this track, Adventure states.

Timeline

  1. August 3 – October 1, 2026 — Unauthenticated bus completion pages exposed to automated viewing (~12,000 reservations); fixed October 1.
  2. September 9, 2026 — One member account unauthorized login noted in the IR.
  3. September 20 / found September 28 — Business-management system vulnerability abused (17,780 cases).
  4. October 2–4 / found October 5 — Server/cloud path via abused management functions (~14.64M / ~4.13M with password hashes).
  5. October 7 ~18:00 — Stored-card payments and card-storage features stopped to limit fraudulent purchases with saved cards after account takeover.
  6. October 9, 2026 — IR apology and notice; PPC reported; customer emails rolling out.

What was not stored / not leaked (per Adventure)

  • Credit-card numbers — not stored at Adventure; held by payment agents. Not leaked in these cases per the notice.
  • Passport images — not stored; not leaked.
  • Passport numbers — confirmed not leaked on tracks (1) and (3); track (2) still under negative confirmation work.

To be clear: stopping stored-card checkout is a containment move against account takeover using hashed-password cracking or session abuse — not evidence that PANs sat in the 14.64 million export.

Password hashes and the 4.13 million

Adventure says member passwords were stored hashed in a form difficult to reverse, yet still warns that analysis could recover passwords for skyticket and any reused sites. That is the correct customer message regardless of algorithm pride.

If you are in the hashed-password subset, rotate skyticket credentials immediately and everywhere you reused them. If you are unsure which subset you fall into, rotate anyway — the cost is low relative to account takeover on a travel wallet.

Bank refund details — the 17,780 track

Refund destination accounts are not ATM PINs. They are still powerful social-engineering props. Expect calls and emails that recite your bank name and branch while asking for “verification” of internet-banking passwords or cash-card PINs to “complete a skyticket refund.” Adventure says it will not ask customers to pay fees or install apps for this incident.

If you see unfamiliar deposits or withdrawals, contact your bank — not a number in a surprise SMS.

Bus bookings and itinerary abuse

Knowing your boarding time, operator reservation number, and companion names lets a scammer impersonate skyticket or the bus company with unsettling accuracy: “Your 14:30 departure was cancelled — pay a rebooking fee.” Adventure tells customers to contact official support if reservations change without their action.

The root cause — completion pages without authentication — is mundane and devastating. Travel OTAs and carriers should treat confirmation URLs as secrets equivalent to boarding passes.

Who is at risk

Nearly anyone who entered personal data on skyticket sits near the 14.64 million figure for the primary track — domestic travelers, inbound tourists who used passport-notation names, and dormant members.

~4.13 million members with password hashes face credential-recovery and stuffing risk.

Customers in the operations-system set (17,780 including duplicates) face bank-detail phishing; a smaller slice also lost email/DOB/address extras.

Bus reservation parties and companions in the ~12,000 reservation views face itinerary-based fraud.

Anyone who stored a card on skyticket should note that stored-card charging was disabled October 7; watch for phishing that claims you must “re-enter the card to keep your booking.”

Phishing and fraud patterns Adventure itself flags

  • Fraud email/SMS/phone/post impersonating Adventure, banks, airlines, or bus operators using stolen name/contact/address data.
  • Unauthorized login after password recovery from hashes.
  • Refund theater aimed at extracting bank PINs or net-banking credentials from people whose refund accounts leaked.
  • Reservation change/cancel scams quoting real trip details from the bus page views.

What Adventure and regulators did

Adventure says it cut intrusion paths, applied vulnerability countermeasures, stopped stored-card payments and card-save features on October 7, is emailing affected customers (this IR stands in when mail does not arrive), and reported to the Personal Information Protection Commission. Business-impact assessment was still under examination at disclosure.

Secondary damage: aside from the one September 9 unauthorized member login called out in the IR, Adventure reports no confirmed misuse of the leaked information at notice time — while enumerating exactly how misuse could still arrive.

English IR digest: JapanIR. Original Japanese PDF is linked from that page for full field and timeline language.

Industry context

Online travel agencies concentrate identity, itinerary, and payment-adjacent workflows. A management-function compromise that fans out into cloud data stores is a classic OTA nightmare: one admin-surface bug becomes a census of travelers.

August–October 2026 also saw a wider Japanese wave of unauthorized-access disclosures across retail and apps. Adventure’s IR is notable for publishing three parallel tracks with dates, counts, and field inventories in a single timely disclosure — more operational detail than many peers offered the same week.

For other large-scale data-exposure narratives on BreachHistory, see pieces such as France’s open multi-source database incident and Vercel’s internal security incident coverage — different mechanisms, same reader need for verified scope language.

What you should do

  1. Change your skyticket password and every reused password (email and banking first).
  2. Enable MFA on the email account tied to skyticket — recovery attacks will target that inbox.
  3. Review recent skyticket reservations for unexpected changes; contact Adventure’s official desk if something moved without you.
  4. Ignore refund/compensation messages that demand fees, transfers, or app installs — Adventure says it will not ask for money related to this incident.
  5. If you provided refund bank details, alert yourself to vishing; lock down net-banking MFA and never recite PINs to cold callers.
  6. Watch for airline/bus impersonation that quotes real itinerary fields from the bus-page exposure.
  7. Do not re-save cards on skyticket until Adventure clearly restores the feature through official UI — phishing will fake that restoration.
  8. Bookmark /adventure-skyticket/skyticket-adventure2026 for IR updates.

Was I affected?

If you registered or typed personal data into skyticket, treat the ~14.64 million track as the default answer until Adventure’s email or a later IR narrows your case. Membership with a login raises the odds you are also in the ~4.13 million hash set.

Bus-only customers in the August 3–October 1 window may be in the ~12,000 reservation view set even if they never created a long-lived member password. Operations-system exposure is a smaller, finance-sensitive cohort — Adventure’s individual mail should clarify bank-detail inclusion.

Tourists who used skyticket once during a Japan trip still count; passport-notation names in the large export make international phishing feasible in multiple languages.

Why Adventure halted stored cards

Even without storing PANs, a travel site that remembers a tokenized card for one-click checkout becomes a fraud terminal if attackers can log in as the member. Killing stored-card payments after a hash-inclusive breach is a direct way to break that chain while customers rotate credentials.

Expect confusion: legitimate bookings may need fresh card entry. That friction is preferable to silent fraudulent tickets charged to a remembered card.

Management functions as blast radius

Adventure’s primary track starts with improper operation of management functions, then lateral reach into other servers and cloud data. That sequence is a lesson for every OTA: admin tools need stricter network segmentation, step-up authentication, and egress monitoring than customer front doors.

Peer travel platforms should hunt for the same pattern — privileged UI that can enumerate customer objects, weak controls on export jobs, and cloud buckets mounted too widely for “ops convenience.”

Counting carefully

Adventure reports pieces of personal information (~14.64 million), not necessarily 14.64 million unique humans. Duplicates appear explicitly in the 17,780 operations count. Companions inflate people-vs-reservations on the bus track. When you see headlines that round to “14.64 million customers,” remember the IR’s more precise wording — and still assume you are included if you ever submitted data.

Password-bearing rows (~4.13 million) are the subset that changes password-hygiene urgency most sharply.

What remains open

  • Full unique-person reconciliation across the three tracks
  • Final passport-number negative confirmation on the operations track
  • Additional volume still under investigation beyond 17,780
  • Financial impact on Adventure’s results
  • Richer public detail on the exact vulnerabilities and management-function abuse chain

None of those gaps excuses delay on password rotation or phishing skepticism.

Travel-season stakes

Autumn travel and year-end holiday planning mean skyticket phishing will compete with real airline schedule-change mail. Build a habit: type the skyticket domain or use a bookmark; never trust a “reservation changed” link that arrives minutes after a breach headline.

Families booking group buses should brief companions — their names and ages may have been on viewed pages even if only one person held the member ID.

Passport notation names without passport numbers

Adventure lists names including passport-notation spellings among the large export while stating passport numbers and images were not stored or not leaked on the described tracks. That distinction is easy to miss in panic. Attackers may still greet you with the exact Romanization from your ticket history. That does not mean they hold your passport biodata page.

Tourists should still enroll passport-loss monitoring habits they already use when traveling, but the IR’s concrete claim is about names and contact fields — not a dump of scanned passports.

Remittance sender names

Bank-transfer payer names appearing in the primary track help scammers script “your wire to skyticket failed — resend to this account” messages. Real Adventure remittance instructions only come through official booking flows. Any urgency that requires sending money to a new personal account is fraud.

If you paid by transfer for a past booking, tell family members who share that bank app. Shared household accounts amplify remittance-scam success rates after travel breaches.

One confirmed unauthorized login

Adventure’s IR flags a single member-account unauthorized login on September 9 in addition to the bulk tracks. That datapoint proves account takeover is not theoretical for skyticket. It does not mean only one account will ever be tried. Hash cracking and stuffing campaigns scale after disclosure.

Review skyticket login history if the product surfaces it; revoke unfamiliar sessions; treat unexpected booking confirmations as emergencies until proven otherwise.

IR language for investors versus customers

As a TSE Growth issuer, Adventure must speak to markets about business impact under examination while simultaneously giving customers field lists and action items. Readers should use the customer sections — counts, fields, stored-card stop — as the operational truth, and treat unfinished earnings-impact language as unfinished, not as evidence the breach is minor.

Follow-up corrections on TDnet are common after first-day IR. Bookmark the JapanIR page and BreachHistory canonical path for revisions to the 17,780 investigation remainder or passport-number verification on the operations track.

Cloud data reach after admin abuse

Adventure’s description of the October 2–4 track — management functions misused, then other servers and cloud-held data accessed — should push every travel platform to map which customer corpora are reachable from admin sessions. If a single compromised ops workflow can read hashed passwords and address books in bulk, segmentation failed before the attacker arrived.

Customers will never see that architecture diagram. They will see the consequence: a 14.64-million-piece notice. The practical mirror is to assume any skyticket-submitted profile field could be in criminal hands and to stop reusing the skyticket password anywhere it still exists.

Canonical record and sources

BreachHistory indexes Adventure / skyticket as company-confirmed via October 9, 2026 IR: ~14,640,000 personal-info pieces (~4,130,000 with password hashes), 17,780 ops-management cases, ~12,000 reservation views, no stored passport images/card numbers, stored-card payments stopped, PPC reported. Live page: https://breachhistory.com/adventure-skyticket/skyticket-adventure2026.

If you used skyticket, assume a rich identity record may be out, treat password reuse as urgent if you ever logged in, watch bank and itinerary channels for tailored fraud, and take Adventure’s word on what it did not store — cards and passport images — without relaxing your guard on everything it did list.