2026 dip (Baitoru) — overseas access via site-function flaw; up to 3,885,771 emails
Data compromised
Per dip Oct 9 notice: up to 3,885,771 member email addresses only. Names, phones, passwords, and credit-card data not included in the leaked set. No confirmed internet dump or misuse at disclosure.
Technical writeup
Verified dip Inc. notice (9 Oct 2026). On 6 Oct, unauthorized overseas access via a specification flaw in a site function may have exposed up to 3,885,771 Baitoru / Baitoru NEXT member emails. Company blocked overseas access, patched the function, strengthened monitoring; notified members on-site 6 Oct; reported to PPC and MIC Kanto; consulting police. Services remain available. Emails only — no names/phones/passwords/cards. companyConfirmed true; recordsAffected 3885771.
Root cause
Overseas unauthorized access exploiting a specification flaw in a Baitoru / Baitoru NEXT website function (detected 6 Oct 2026)