🚨Cyberattack - Credential Stuffing 🚨
🇯🇵Japan - Yonex (ヨネックス株式会社)
The official Yonex online shop experienced unauthorized login attempts from November 7 to November 8, 2024, affecting 223 accounts through a credential stuffing attack. Out of these, personal information for 53 accounts may have been accessed, including names, addresses, phone numbers, gender, birth dates, purchase history, and partial credit card details.
The attack was detected after a customer reported a suspicious order confirmation. Yonex has since blocked IP addresses involved in the attack, invalidated all member passwords, and implemented password change requirements for future logins.
Source:
https://yonexshop.jp/news/207