2026 CAMPFIRE (Japan) — GitHub account compromise → internal DB access; ~225k users (Apr)
Data compromised
User PII, addresses, phones; subset bank account fields per disclosure summaries
Technical writeup
In April 2026, Tokyo-based crowdfunding operator CAMPFIRE publicly disclosed unauthorized access stemming from compromise of a GitHub account used for system management, with unauthorized database access detected April 21, 2026, and customer notification shortly thereafter (e.g., ITmedia coverage April 24). Company statements and English-language summaries described potential exposure of roughly 225,846 users, including possible bank account records for a subset (~82k narratives in some roundups), while stressing payment card numbers were not stored in the affected flows per company messaging.
Root cause
GitHub credential compromise leading to internal system and database access