[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ff64hd6ne5lvm":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":36,"seoTitle":37,"seoTitleEn":38,"seoDescription":37,"seoDescriptionEn":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"68e3266eda11adda48825188","disk-union","Disk Union Data Breach","diskunion.net","2022-06-24T00:00:00.000Z","2025-06-07T07:08:28.000Z","2026-07-09T21:14:21.376Z","2026-07-18T23:49:42.483Z","Website hack","https:\u002F\u002Fdiskunion.net\u002Fportal\u002Fct\u002Fnews\u002Farticle\u002F1\u002F107705",[15,17,18,19],"https:\u002F\u002Finternet.watch.impress.co.jp\u002Fdocs\u002Fnews\u002F1421036.html","https:\u002F\u002Fwww.phileweb.com\u002Fnews\u002Faudio\u002F202208\u002F10\u002F23566.html","https:\u002F\u002Fwww.security-next.com\u002F137693",690667,"known",null,"unknown","High",[26,27,28,29,30,31,32,33,34,35],"Email addresses","Names","Phone numbers","Physical addresses","Postal codes","Geographic locations","Plain text passwords","Passwords","Membership details","Usernames","\u003Cp>The Disk Union data breach is a large-scale customer data incident observed in the online store memberships of the Japan-based music and record retailer. After an external notification on June 24, 2022, the company's online stores were suspended, and subsequent forensic investigation confirmed that approximately 701,000 customer records registered on diskunion.net and audiounion.jp may have been affected. Independent breach indexes list about 690,667 unique email addresses for this incident; this number does not mean that each customer record corresponds to one individual. The Disk Union data breach is particularly significant for account security because it included email addresses, full names, addresses or postal codes, phone information, membership identifiers, and plaintext password information.\u003C\u002Fp>\n\u003Cp>This record addresses the Disk Union incident only with verifiable fields. The focus of the incident is more on online membership systems than on physical store purchases. It has been stated that payment transactions are conducted through external service providers and that credit card information is not retained by the company; therefore, the credit card number is not listed among the types of data leaked in this record. Since there is no verified external export information for purchase history, the explanation excludes this field. The most critical risk is the reuse of email and plain text password combinations on other sites, or the preparation of more convincing fraud messages using membership numbers or contact information.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Among the verified data types are email addresses, full name information, location data such as physical addresses or postal codes, phone and fax information, membership numbers or user identifiers, and login passwords. In the independent breach index, data classes are listed as email addresses, geographic locations, names, passwords, phone numbers, and usernames. The company announcement also mentioned member numbers and address information of online store members. For this reason, the Disk Union data breach is not just an email list, but a more risky customer account incident that includes contact, identity, and login information together.\u003C\u002Fp>\n\u003Cp>Plain text password information is the most severe part of this incident. The exposure of the directly readable password instead of the password hash makes it easier to try the same email and password pair on other services. Fields such as name, address, and phone number also increase the context that attackers can use; fake shipping, order, membership verification, refund, or customer service messages can become more realistic. Identifiers such as membership numbers are not financial information on their own, but they can be misused to appear to reliably represent an account.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope of the incident is limited to diskunion.net and audiounion.jp online stores operated by Disk Union. In the initial stage, a potential leak was noticed on June 24, 2022, following a third-party notification; the online stores were suspended on the same day, notifications were made to the Japanese personal information authority on June 27, 2022, and to law enforcement on June 28, 2022. The incident, publicly announced on June 29, 2022, became clearer on August 10, 2022, with the confirmation of the leak following an external investigation. This timeline indicates that the June 2022 breach date recorded is related to the discovery and response period.\u003C\u002Fp>\n\u003Cp>It is important not to expand the scope. Approximately 701,000 customer records is the upper impact area announced by the company; approximately 690,667 unique emails is the number of indexed unique emails. These two numbers do not measure the same thing. Credit card data was not included in this record because it was reported that it is not held by the company. There is also no verified outbound information for purchase history or payment history. The cause of the incident was explained as a security vulnerability found on a server associated with online store systems, the relevant access was cut off, and stores were kept closed until security measures were completed.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of customers who registered on the Disk Union or Audio Union online stores before 2022 or during the incident period. The risk significantly increases for people who use the same email and password on different shopping sites, email accounts, social networks, or payment-linked services. When a plaintext password is available, an attacker does not need to crack the password; it may be enough to try the same information on other login forms. Therefore, not only the Disk Union account but all accounts where the same password is used should be reviewed.\u003C\u002Fp>\n\u003Cp>Collectors placing orders from outside Japan, record and music archive customers, people who have been using the same membership for a long time, and customers who keep their account information with old email addresses are also at risk. Since addresses, phone numbers, and membership identifiers have been leaked, targeted messages may not come only in the form of general phishing; they can be crafted under the theme of order status, stock notification, membership update, or account recovery. Such messages may appear to be based on a real brand history, the existence of a membership relationship, and the person's contact information.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used in the online store of Disk Union or Audio Union should be changed immediately. If the same password was used on other accounts, those accounts should also be assigned different and strong passwords. Using a password manager makes it easier to generate unique passwords for each service and prevent the reuse of old passwords. Email accounts, shopping sites, and payment-linked services should be checked as a priority, because the combination of email address and password is the first area attackers will try. Two-factor authentication should be enabled wherever possible.\u003C\u002Fp>\n\u003Cp>Suspicious login alerts, password reset messages, unexpected order notifications, and fake customer service requests should be carefully examined. Messages associated with the name Disk Union should not be acted on hastily, and account operations should be initiated by typing the address directly into the browser. Since personal address and phone information are also included, verification requests made by phone, or information requested under the pretext of delivery fees or return forms, should be questioned separately. Although credit card information was reported as out of scope in this incident, suspicious payment activities should still be monitored as part of overall security oversight.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Disk Union data breach shows that passwords used in old memberships can continue to pose a risk for a long time. Users should regularly check where they have used the same password, close accounts that are no longer in use, and use strong authentication methods on important accounts. Email accounts should be particularly protected because password reset links often come via email. If an attacker gains access to the email account, a wider chain of account takeover can occur, not limited to Disk Union.\u003C\u002Fp>\n\u003Cp>On the corporate side, this incident serves as a reminder of how big a risk it is to store passwords in plain text in online store systems. Passwords should be protected with strong, one-way, and up-to-date methods; unnecessary personal data retention periods should be shortened; and access to fields such as membership numbers, addresses, and phone numbers should be limited with layered authorization. Regular vulnerability assessments, monitoring of log records, early detection of unusual export activities, and testing of incident response plans reduce the impact of similar customer data leaks.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The match seen in this record indicates that your email address may be associated with the unique email fields in the Disk Union data breach dataset. A match does not necessarily mean that all your customer information has been compromised; however, it should be taken seriously since the incident involves plaintext passwords, contact information, and membership identifiers. The priority is to change accounts using the same password and to better protect your email account. Even if the old password remains active in a single location, it could pose a risk in automated login attempts years later.\u003C\u002Fp>\n\u003Cp>If you have a Disk Union or Audio Union account, check your account history and contact address, and look for signs of sessions or transactions you do not recognize. Do not reuse the same password on any service after changing it. Be skeptical of messages that appear personal due to phone, address, and membership information; initiate real customer service transactions directly through the official site. The purpose of this record is to make the incident visible without exaggerating it, to keep verified data fields limited, and to provide the user with actionable account security steps.\u003C\u002Fp>","","Disk Union Data Breach (690.7 Thousand Reported Records)","Disk Union Data Breach. 690.7 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdiskunion_net.webp",false,{"name":43,"sector":44,"country":45,"website":9,"websiteArchiveUrl":37,"websiteStatus":37,"websiteCheckedAt":22},"Disk Union","Retail","Japan"]