TOKYO (TR) – The operator of the Japanese accommodation reservation management system Temairazu on Monday revealed that its network was breached by hackers, triggering a targeted phishing scam aimed at stealing credit card information from hotel guests.
Starting late night on September 21, multiple lodging facilities reported that individuals who had booked rooms were receiving fraudulent messages via WhatsApp, WeChat, email and SMS.
Armed with the guests’ actual reservation details obtained from the breach, the scammers posed as hotel representatives. The messages instructed victims to click malicious links to “confirm” their bookings, demanding they re-enter credit card information or make urgent payments.
Highly coordinated phishing campaign
During an internal investigation, the company confirmed that its system had suffered unauthorized access, admitting that a third party likely viewed or extracted personal guest data to launch the highly coordinated phishing campaign.
The company stated that it does not directly handle or store credit card data on its servers, but urged any guests who entered their payment details into the fraudulent websites to contact their credit card providers immediately.
Following the discovery of the cyberattack, the operator temporarily suspended parts of the Temairazu system to sever the unauthorized access, patch the vulnerabilities, and reinforce security monitoring. The system has since been restored to normal operations.
External cybersecurity experts
The operator has reported the breach to the police and the Personal Information Protection Commission, and has enlisted the help of external cybersecurity experts to assist in the ongoing criminal investigation.
In a public warning, the company is urging guests to ignore suspicious messages, refrain from opening unknown links, and avoid transferring money. Partner hotels and online travel agencies (OTAs) have also been instructed to change their login passwords and monitor their accounts for any unauthorized changes to bank transfer destinations or administrative privileges.




