← Fabrica Holdings

2026 Fabrica Media 4u — SMS gateway breach; 95,412 account records (detected Jun 24; disclosed Jul 14)

2026 95.4K records affected Share on X

Data compromised

Account-management file with 95,412 records (account IDs, usernames, contact names, prefecture/postal data, notification emails); Fabrica says 22,928 may qualify as personal information; passwords, API keys, and billing data were not in the file; 280 unauthorized SMS sent

Technical writeup

Fabrica Holdings Co., Ltd. (TYO: 4193) disclosed on July 14, 2026 that consolidated subsidiary Media 4u detected unauthorized access to its SMS transmission system management console on June 24, 2026. Attackers exfiltrated an account-management file containing 95,412 records; Fabrica stated 22,928 entries may include personal information such as contact names or identifiable email addresses, while noting record counts reflect account-management rows rather than confirmed unique individuals. Leaked fields included account IDs, usernames, contact names, prefecture and postal code data, and notification email addresses. The company said passwords, password hashes, API keys, authentication tokens, and payment or billing information were not part of the compromised file. Intruders also used the system to send 280 unauthorized SMS messages; Fabrica forced credential resets, engaged forensic specialists, and said it would notify regulators as required.

Root cause

Unauthorized access to Media 4u SMS transmission system management console (per Fabrica Holdings disclosure)

References