← Kaga Solnet

2026 Kaga Solnet — Academico Navi EC unauthorized access; max ~170,000 user records (names/addresses/emails/password hashes)

2026 170.0K records affected Share on X

Data compromised

Per Kaga Solnet: user-registration data from Oct 2021–Apr 2026 — names, addresses, contact details, email addresses, and encrypted mypage passwords; maximum about 170,000 records. Payment-card data not stored on the site (third-party payment processor) — company says no card leak. No confirmed public misuse as of the notice.

Technical writeup

Verified company notice — 1 July 2026. Kaga Solnet (加賀ソルネット株式会社, EM company) said its Academico Navi university/student PC sales site suffered unauthorized access confirmed 22 June 2026, with possible leakage of user-registration data. The company paused the site, restricted access, investigated with a contractor, and reported to Japan’s Personal Information Protection Commission. In-scope fields for purchases with user registration between October 2021 and April 2026: name, address, contact, email, encrypted mypage password; maximum about 170,000 records (約17万件). Credit-card and other payment data are held by a payment processor, not the site — company states no payment-info leak. As of the notice, no confirmed public disclosure or misuse; customers told to ignore suspicious mail/SMS/calls and change reused mypage passwords. Japanese universities (Teikyo and others) posted student notices the following day. recordsAffected 170000 as the company-stated maximum.

Root cause

Unauthorized third-party access to the Academico Navi (アカデミコナビ) sales site, confirmed 22 June 2026; site paused and access restricted (company 1 July notice)

References