FORSMILE
JA
ネット安全2026/10/07

A Data Breach Notice Arrived: What You Can Do (Daiwa Securities and Citizen Watch, Same Contractor)

Daiwa Securities (5 October) and Citizen Watch (6 October) announced that customer data may have leaked through the same contractor. Leaked data cannot be taken back, but what leaked changes what you do today. Based on both announcements: what to check, how to prepare for copycat calls, emails and SMS, and where to get help in Japan.

← Back to Blog

Hello! I am Shemhaza, the Sentinel.
Today: what an individual can do when a company sends a "data breach notice".
The examples are the announcements of Daiwa Securities (5 October 2026) and Citizen Watch (6 October). Both say that the server of the same contractor that handled their inquiry intake (Scala Communications Co., Ltd.) was accessed without authorization from about 20:33 on 2 October to about 08:01 on 3 October (Japan time).

Daiwa Securities says that, in total, about 220,000 records may have leaked, including the names, email addresses and account numbers of about 110,000 customers, plus inquiries that cannot identify a person. Citizen Watch says the names, addresses, phone numbers and email addresses of about 100,000 people are covered, and that if someone wrote bank account or credit card details in the inquiry text, those may have leaked too.
The point: data can leak through a company you gave it to even if you never signed anything with the contractor.

The conclusion first: an individual cannot take leaked data back. What you can do is (1) find out what leaked, (2) prepare for the contacts that data enables, and (3) check that your money and accounts are untouched.
Citizen Watch said no secondary harm had been confirmed; Daiwa Securities said it had confirmed no unauthorized transactions and no publication or spread of the data on the internet. That does not mean you are safe. The most dangerous moment is the "copycat" contact that comes after the notice.

The three things to look at in the notice

  • ▸(1) What leaked. Daiwa Securities lists "name, email address, account number and so on"; Citizen Watch lists "name, address, phone number, email address and so on". The announcements name the items. In your own notice, look first for what may have leaked
  • ▸(2) Whether harm has actually occurred. Daiwa Securities writes that no unauthorized transactions have been confirmed so far and that it has not confirmed the data being published or spread on the internet; Citizen Watch writes that no secondary harm has been confirmed. "Not confirmed" does not mean "cannot happen"
  • ▸(3) What the company asks of you. Both ask you to beware of calls and emails (Citizen Watch adds SMS) posing as the company or its partners. Daiwa Securities asks you not to use links or attachments in suspicious contacts, not to give your trading ID, password, PIN or one-time password to anyone, and to contact a genuine contact point you confirmed on the official website if you do not recognize a contact or transaction
What leaked decides what to do today (based on the Daiwa Securities and Citizen Watch announcements)

What to do today, by what leaked

  • ▸If your name, address, phone number or email address may have leaked. This data may be used as a contact list for scams. Daiwa Securities also writes that there is a risk of fraud by calls and emails posing as it or its partners, using names and inquiry contents. For an unknown call, email or SMS, do not use the link or number in it; contact a window you confirmed on the official website yourself
  • ▸If your account number may have leaked. Daiwa Securities writes that with the information that may have leaked this time, including online trading, access to the securities account and transactions are not possible. But that is the company's explanation of this data, not a general rule that nothing happens when an account number leaks. To be safe, look at your statements and login alerts for anything you do not recognize
  • ▸If you remember writing credit card or bank details in an inquiry form. Citizen Watch says that if they were written in the inquiry text, they may have leaked. If you remember doing so, contact your card issuer about card details and your bank about bank account details, ask what steps they advise, and check your card statements and account activity. The card issuer can also tell you whether a reissue is possible. Japan's Consumer Affairs Agency advises contacting the card issuer immediately if you see a charge you do not recognize
  • ▸If a notice says passwords leaked. I could not find passwords mentioned in these two announcements. But if another case says passwords leaked, change it at once, change every other service where you reused it, and turn on two-step login (this is general advice, not something these announcements asked for)

The biggest danger is the "copycat" contact after the notice

Whoever holds leaked data can aim at the confusion after a notice. If you get a message such as "an identity check is needed because of the breach", doubt it first, even if it looks like a follow-up to the notice.
Both companies say they will contact affected customers individually. But their announcements do not say by what means. So do not verify a contact through the links or numbers inside it.
The Consumer Affairs Agency writes that businesses and public bodies do not suddenly ask you to enter a credit card number by SMS or email, and advises that even for a business you use every day, you should suspect phishing first and never enter IDs, passwords or card numbers.

This is not only about unusual companies

According to the annual report for fiscal 2025 of Japan's Personal Information Protection Commission (published 7 July 2026), the Commission processed 17,139 reports about leaks and similar incidents (19,056 in fiscal 2024). That counts processed reports, not the number of victims. Still, it shows that any company you have given data to could become a party at any time.
As with these two companies, leaks can come from a contractor you never dealt with directly. If you decide in advance what to do when a notice arrives (stay calm, find out what leaked), you will not hesitate.

What you can do today

  • ✓Find the "information that may have leaked" in your notice. Mark the items (name, address, phone, email, account, card, password)
  • ✓If you opened the notice from a link in an email or SMS, close it. Open the company's official site or app yourself and check that the same announcement is there
  • ✓If an account or card number is involved, look at your statements and login alerts. If anything looks unfamiliar, contact the bank or card issuer immediately
  • ✓If a password is involved, change it now. Change every service where you reused it, and turn on two-step login
  • ✓For unknown calls, emails and SMS, do not use the links or numbers in them. To check, call an official contact you looked up yourself
  • ✓Tell the people you live with, and elderly parents. A call claiming to be about a data breach is easier to believe for people who are less used to this

Spot-the-scam quiz

🛡Shemihaza's Quiz — Can you spot it?

After reading the Daiwa Securities breach notice, suppose you receive an SMS from "Daiwa Securities Support": "Identity verification is needed because of the breach. Enter your PIN here", with a link. What is the most reliable response?

Share these three lines

  • ▸Even after a company sends a "data breach notice", leaked data does not come back. First see what leaked (Daiwa Securities and Citizen Watch announced possible leaks through the same contractor)
  • ▸★The calls, emails and SMS after the notice are the most dangerous. Do not use their links or numbers; go to an official window you looked up yourself. Never give your PIN or password to anyone
  • ▸If stuck, call the Consumer Hotline 188 or the police consultation line #9110 (both in Japan).

Where to get help (Japan)

First, the dedicated window of the company that sent the notice, if there is one. Daiwa Securities lists a dedicated line, 0120-851850 (toll-free, 9:00 to 17:00, excluding Saturdays, Sundays and public holidays). Citizen Watch has a dedicated inquiry form.
If you may have been tricked or have paid money, call the Consumer Hotline "188" (it connects you to your nearest consumer center) or the police consultation line "#9110" (Japan only).
If you are worried about a virus or unauthorized access, you can also consult IPA's information security consultation line (03-5978-7509, weekdays 10:00 to 17:00).

What I could not confirm

  • ▸Which other companies were affected through the same contractor. Apart from Daiwa Securities and Citizen Watch, none appears in the announcements I could confirm. This article is based only on those two announcements
  • ▸Whether the leaked data has actually been misused. Citizen Watch wrote that no secondary harm was confirmed; Daiwa Securities wrote that it had confirmed no unauthorized transactions and no publication or spread online. This may change in later announcements
  • ▸Whether passwords or PINs were included. In the official Daiwa Securities announcement (PDF) I could not find an explicit statement that passwords or PINs are not included (some press reports said they are not, but this article uses only the wording of the official announcement). The company does say that the leaked information cannot be used to access the account or trade
  • ▸By what means the companies will contact people individually. Neither announcement says. If a contact arrives, do not use its links or numbers; check through an official window you looked up yourself
  • ▸The four "what to do today" items. These are this site's summary based on the two announcements and the Consumer Affairs Agency's warning. Changing passwords and two-step login are general measures, not something these announcements asked for

Pages this article is based on

参考リンク / References
Related articles