2019 Fast Retailing — credential-stuffing wave against UNIQLO Japan / GU Japan online store accounts
Data compromised
Names, addresses, phone numbers, email addresses, gender, birth dates, purchase history, sizing or measurement fields, and partial card digits per company disclosure summaries
Technical writeup
Fast Retailing publicly reported unauthorized logins affecting roughly 461k customer accounts on UNIQLO Japan and GU Japan online stores between late April and early May 2019, attributing the pattern to list-based credential reuse against reused passwords. The company invalidated impacted passwords, summarized accessed profile and partial payment metadata fields, and described coordination with law enforcement in its group news release.
Root cause
Credential stuffing / list-type account takeover against e-commerce accounts