2026 Lawson — Lawson ID app API abuse; 2,155,345 accounts + 26 partial cards
Data compromised
Lawson ID 2,155,345: email, name; optional gender/phone/address/newsletter settings. App Reservation 26 users: name, phone, partial credit-card numbers.
Technical writeup
Verified Lawson disclosure Oct 8, 2026 — Attackers accessed Lawson ID data for 2,155,345 accounts (Sep 12–14) and Lawson App Reservation for 26 users (Sep 17); discovered Oct 7. Lawson attributes the breach to unauthorized access to a security/display mechanism in the Lawson app used to show users their own information. Lawson ID fields: email and name, plus optional gender, phone, address, newsletter settings. App Reservation: name, phone, and part of credit-card numbers. App Reservation suspended; PPC notified; no misuse confirmed at disclosure.
Root cause
Unauthorized use of an app mechanism intended to show users their own information (Sep 12–14 Lawson ID; Sep 17 App Reservation); found Oct 7