← Campfire Inc Japan

2026 CAMPFIRE (Japan) — GitHub account compromise → internal DB access; ~225k users (Apr)

2026 225.8K records affected Share on X

Data compromised

User PII, addresses, phones; subset bank account fields per disclosure summaries

Technical writeup

In April 2026, Tokyo-based crowdfunding operator CAMPFIRE publicly disclosed unauthorized access stemming from compromise of a GitHub account used for system management, with unauthorized database access detected April 21, 2026, and customer notification shortly thereafter (e.g., ITmedia coverage April 24). Company statements and English-language summaries described potential exposure of roughly 225,846 users, including possible bank account records for a subset (~82k narratives in some roundups), while stressing payment card numbers were not stored in the affected flows per company messaging.

Root cause

GitHub credential compromise leading to internal system and database access

References