MrMax Holdings announced on October 6th that the servers for the MrMax app and online store had suffered unauthorized access by a third party, resulting in the leak of members' personal information. The company operates the general discount store "MrMax" primarily in Fukuoka Prefecture, with stores also in the Kyushu, Kanto, and Chugoku regions.

The leak affects up to 1,735,154 individuals registered as of October 3rd. The compromised data includes member IDs, names, email addresses, and phone numbers. The company states that addresses, dates of birth, credit card information, passwords, and purchase history were not leaked.

The company detected suspicious access to its servers on the evening of October 3rd and temporarily suspended services. External access was blocked later that same day. Subsequent investigation revealed that a third party had illicitly exploited a software function used to configure the service to infiltrate the servers.

As of October 6th, no misuse of the leaked information has been confirmed, but users should be wary of phishing emails impersonating MrMax or similar entities.