← Fast Retailing

2019 Fast Retailing — credential-stuffing wave against UNIQLO Japan / GU Japan online store accounts

2019 461.1K records affected Share on X

Data compromised

Names, addresses, phone numbers, email addresses, gender, birth dates, purchase history, sizing or measurement fields, and partial card digits per company disclosure summaries

Technical writeup

Fast Retailing publicly reported unauthorized logins affecting roughly 461k customer accounts on UNIQLO Japan and GU Japan online stores between late April and early May 2019, attributing the pattern to list-based credential reuse against reused passwords. The company invalidated impacted passwords, summarized accessed profile and partial payment metadata fields, and described coordination with law enforcement in its group news release.

Root cause

Credential stuffing / list-type account takeover against e-commerce accounts

References