Ransomware at 157 Japanese retail stores: all reopened, points still down
REXT Corporation, which runs WonderGOO, Shinseido and WonderREX, was hit by ransomware on August 9. Registers, points and buybacks are still down on day five.
Table of contents
REXT Corporation, which runs WonderGOO, Shinseido and WonderREX, was hit by ransomware on August 9. Registers, points and buybacks are still down on day five.
WonderGOO, Shinseido, WonderREX, HAPiNS, JEANS MATE. REXT Corporation, which runs all 157 stores across these five brands, has disclosed that it suffered a ransomware intrusion on August 9, 2026. Ransomware is an attack that encrypts a company's data without permission, making it unusable, and then demands money in exchange for restoring it.
As of the official update at 09:30 on August 17, 2026, all 118 directly run stores are open. None are closed. But not a single store is back to normal operation. All 118 are listed as "open with some services restricted," and point accrual and redemption, self-checkout, and new hold and reservation requests are still down chain-wide.
Credit cards, on the other hand, are back at 117 of the 118 stores. What works and what does not varies store by store, and the company publishes a per-store list. That is where this article starts.
The outage fell right on the overlap of the Obon holiday travel season and summer vacation, one of the busiest stretches of the year for bookstores and hobby shops. Even so, for the first three days only one major outlet had covered the incident: INTERNET Watch.
What you will find if you go to a store
The information that matters most if you are planning to visit a store. Everything below comes from the store operating status page the company updated at 09:30 on August 17, 2026. It covers 118 directly run stores: 36 WonderGOO, 35 WonderREX, 18 Shinseido, 17 JEANS MATE, and 12 HAPiNS / PASSPORT.
| Service | As of August 17 (118 stores) |
|---|---|
| Points | Down chain-wide. Neither the card nor the app earns or redeems anything |
| Self-checkout | Down chain-wide. Staffed registers only |
| Holds and reservations | New requests suspended chain-wide |
| Credit cards | Accepted at 117 stores. The remaining one is cash only |
| QR-code and e-money | Back at 22 stores. The other 96 cannot take it |
| Normal register checkout | 115 stores. Three are on handwritten slips, so expect a wait |
| Buyback intake | 71 stores. Only WonderGOO and WonderREX offer it, and some are suspended or on handwritten slips |
In other words: you can shop, but you will earn no points and redeem none, and nine out of ten stores still cannot take QR-code payment. The company advises customers to "bring cash" and to "keep your receipt." Asking people to keep receipts reads like preparation for crediting points retroactively, but nothing about that has been announced.
You can check your own store on the official store status page by searching a store or place name. Seven items — shopping, buyback, cards, QR-code payment, points, reservations, and arcade corners — are shown per store on a four-level scale: normal, handwritten slips (slower), unavailable, or not offered. It is updated as things change, and the company tells customers in a hurry to call the store directly.
Note that REXT's own corporate profile puts its store count at 157. The company has not explained which stores account for the gap with the 118 covered on the status page.
Separately, five stores — Shinseido Quartet 5 Kashiwa, Shinseido Leafwalk Inazawa, JEANS MATE Tachikawa, and the JEANS MATE and HAPiNS stores at Sunlive Create Munakata — closed for good on August 16 and have dropped off the list. Shinseido's Akishima and Canal City Hakata stores are set to close on August 23. The company does not tie any of these closures to the incident.
One thing that is easy to overlook is buyback at WonderREX. For a reuse retailer, buyback is procurement itself, and halting intake and appraisal is the same as closing the front door for anyone trying to sell. More than a week of disruption flows straight through to store inventory later on.
What the official announcement admitted
The release published by parent company REXT Holdings on August 10, 2026 states the following.
"On Sunday, August 9, 2026, we confirmed that unauthorized access by ransomware had occurred within part of the internal network systems of our subsidiary REXT Corporation."
The impacts listed are temporary store closures and partial operations, changes to opening hours, restrictions on cashless payments and similar services, suspension of buyback intake and appraisal, suspension of the points program, and delays in online order shipping. That matches what is actually happening in the stores.
The key point to grasp here is that all five brands are operated by a single company, REXT Corporation. A June 2022 reorganization consolidated the separate per-brand operating companies into one, and the store systems run on a shared platform. That is why a single attack simultaneously stopped the bookstores, the reuse shops, the CD stores, the variety goods stores and the apparel stores. Had there been as many companies as brands, the damage might have been far more contained.
In terms of ownership, REXT Corporation sits under REXT Holdings, which in turn sits under the RIZAP Group. RIZAP Group is listed on the Sapporo Securities Exchange Ambitious market, but no timely disclosure has been filed with the exchange over this incident; it has been announced only as a corporate press release.
RIZAP Group reported first-quarter results on August 14. That period covers April to June, so none of the August damage is in the numbers. Revenue came to 36.91 billion yen (down 7.5 percent year on year) with operating profit of 790 million yen (up 93.4 percent), and net income turned positive for the first time in five years. REXT is named as one of the subsidiaries that drove that profit growth. What this outage costs will not show up until the second quarter or later.
What has happened so far
Here is the sequence of events, based on the official announcements and individual store notices.
← Swipe to navigate
The information was coming from store accounts
Another striking aspect of this incident is the route the information traveled.
On the morning of August 9, when the registers went down, the first to report the situation was neither headquarters nor a brand's official account, but the social media accounts run by individual stores. A short post saying: chain-wide server trouble, registers unusable.
WonderGOO's official account did not mention the incident until 1:11 p.m. on August 12. That was three days after the outage began and two days after the company's own public announcement. In the meantime, only store accounts kept posting individual updates on the situation.
Customers voiced their frustration with that silence in multiple posts, along the lines of "the whole chain is down and only individual store accounts are saying anything; nothing from the official account or the website" and "if the official account says nothing about a system outage, what is it official for?" There are also reports of people traveling to a store only to leave empty-handed, or being turned away when asking for an item to be held.
Communications during an outage are not a matter of corporate appearances. They are practical information customers need to decide whether to go to that store today. When they lag, everyone who shows up has wasted the trip, and complaints and front-line workload rise accordingly. In fact, the fastest and most accurate source for the specific terms of the partial reopening (cash only, bring your reservation slip, no points) was, again, the store accounts. Designing the first response to an outage, deciding what to isolate and how to communicate it, matters just as much as the technical preparations.
Was customer data leaked?
The first report, on August 10, said the following.
"Based on our investigation to date, we cannot completely rule out the possibility that customers' personal information, business partner information and similar data held by REXT Corporation has leaked externally."
In the second report, on August 14, that became:
"Based on our investigation to date, we estimate the possibility that customers' personal information, business partner information and similar data held by REXT Corporation has leaked externally to be extremely low, but we cannot completely rule it out."
"Extremely low" was added. The frame has not changed: a leak has not been confirmed, but it has not been ruled out either. Neither the number of records nor the data fields have been disclosed. The second report does state that reports to the police and the Personal Information Protection Commission are complete, and that an outside specialist firm began a detailed investigation on August 12. In incidents of this kind, the scope typically becomes more concrete as the investigation advances.
As for the attackers, almost nothing is known at this point. Here is the state of play.
✓ Confirmed facts
- ✓Unauthorized access by ransomware was confirmed on August 9 (source)
- ✓The company states the possibility of an external leak is extremely low but cannot be completely ruled out (August 14, second report)
- ✓Reports to the police and the Personal Information Protection Commission are complete, and an outside specialist firm began a detailed investigation on August 12
- ✓Neither REXT nor any of the five brands appears on attacker-run leak sites (as of August 17)
- ✓All stores reopened on August 16, but zero are back to normal operation, and no full-recovery date has been announced
? Not yet known
- ?The name of the group behind the attack — no claim of responsibility has been confirmed
- ?The intrusion route — the company has disclosed nothing at all
- ?Whether a ransom was demanded, and how much — no information
- ?The number of records and data fields exposed — undisclosed
- ?The exact number of closed stores — no store-by-store list has been published
The absence of a leak-site listing does not by itself mean "nothing was stolen." Attackers typically go public only after ransom negotiations break down, and a gap of two to four weeks between encryption and publication is not unusual. We have covered the names and methods of the major ransomware groups in a separate article, but in this case no group's name has surfaced yet.
If you bought from APORITO since May, your card details are in scope
Separately from the stores, one more incident has been disclosed inside the RIZAP Group — and this one does put credit card details in scope. It is being treated as a distinct incident from the store outage, and the two are easy to confuse, so here it is on its own.
A third party had planted a malicious script on "APORITO Online Store," the sports and outdoor goods site run by RIZAP Corporation. A suspicious external-transmission program was found in the system on August 5, and the site was taken down at 15:30 that day. There is no reopening date.
Who is affected, and what may have been exposed
- ▸Window: anyone who ordered from, or entered details into, the store between May 1 and August 5, 2026
- ▸Personal data: name, address, phone number, email address
- ▸Card data: card number, expiry date, security code
- ▸Customers whose card details are in scope were notified individually by email dated August 8
In attacks of this type, a script planted on the input form typically ships whatever the customer types straight out to the attacker as they type it. That is what explains security codes being in scope even though a merchant should never store them. The specifics of this particular attack have not been disclosed.
The company says that as of August 10 it had confirmed no fraudulent use and no secondary damage. That said, a card number, expiry date and security code together are enough to make an online purchase. If you used this store during that window, check your card statement even if no individual email reached you. If a charge you do not recognize shows up, contact your card issuer first. Fraudulent charges are normally covered by the issuer, and the process starts with you reporting it.
Why the registers stopped while online stores kept running
This part is about the technology. The damage in this incident shows a clear pattern.
What stopped: in-store registers, electronic payments, points, buyback appraisal, and online order processing. Meanwhile, the official online shops of JEANS MATE and HAPiNS kept running normally. Same group, same attack, and yet one side was wiped out while the other was untouched.
The difference comes down to where the systems run. The online shops run on external services, in a different place from the internal network. Store registers, points and buyback appraisal, by contrast, only work once they are connected to the internal core systems. What was attacked was "part of the internal network systems," and only the things hanging off it were dragged down with it.
Registers are in a particularly tough spot. A terminal can scan a product barcode on its own, but looking up the price, allocating inventory, calculating points and authorizing a credit card all require querying a central system and waiting for an answer. The moment the other end goes silent, the register cannot produce a total. JEANS MATE and HAPiNS were able to switch to handwritten slips and cash and keep their doors open presumably because they sell clothing and variety goods, with little dependence on points or buyback. Handling trading card lottery sales or appraising used goods by hand is simply not realistic.
This pattern, where an IT failure directly halts a physical business, has appeared again and again in recent domestic incidents. The same thing happened in the case where a cyberattack stopped warehouses and the frozen food supply chain and in the case where an intrusion through a single VPN appliance held up a company's financial closing. According to National Police Agency statistics, more than 60 percent of ransomware intrusions came through VPN equipment, and although over 95 percent of victim companies had antivirus software installed, in more than 70 percent of those cases it failed to detect the attack.
The same group was hit two months ago
What cannot be overlooked is that this is not a first for the REXT group.
On June 1, 2026, D&M, a consolidated subsidiary of REXT Holdings, was infected with ransomware via a VPN appliance, and disclosed it on June 12. Data on 633 orders received by fax was said to have possibly been exposed. That was just two months before the current incident.
On top of that, the APORITO Online Store case covered above was disclosed on the parent side around the same time. That means two security incidents of different natures came out of the same group in the same week — three, if you count D&M two months earlier.
No causal link between the individual incidents has been disclosed, so they cannot be tied together with any certainty. Still, it is a fact that, viewed across the group as a whole, incidents are recurring at short intervals. In corporate groups where each subsidiary has its own systems and its own management structure, lessons learned at one company can fail to reach the others, and the same weakness ends up being exploited somewhere else. The same pattern kept surfacing when we examined the seven Japanese manufacturers that disclosed breaches in March alone.
How long will recovery take?
No recovery estimate has been announced. For reference, here is how long recent domestic incidents actually took.
| Incident | Occurred | Partial sales resumed | Full normalization | Financial impact |
|---|---|---|---|---|
| Tokiwa Industry | March 2025 | Next day (all stores) | Card payments down for over 2 months | Parent fell into negative net worth |
| Askul | October 2025 | 10 days | 117 days | 22.1 billion yen net loss |
| Asahi Group | September 2025 | 10 days | 190 days | Roughly 40 billion yen |
| KADOKAWA / DWANGO | June 2024 | Book shipments about 70 days | About 4 months | Revenue down about 8.3 billion yen |
| Nichirei | July 2026 | — | 11 days | Spread to business partners |
| REXT (this case) | August 2026 | 2 days (reserved items only) | Undetermined (all stores open after 7 days) | Undisclosed |
In National Police Agency statistics, about 47 percent of ransomware victims needed more than a month to recover. Only about 21 percent were done in under a week. REXT managed to resume handing over reserved items on day two and had every store open again by day seven, which puts its initial response on the fast side. But with points, self-checkout and holds still down chain-wide, this is "reopened," not "recovered." The realistic yardstick for full normalization is weeks or months, not days. In earlier cases, too, getting the doors open took days while card payments and points took months to come all the way back.
What hurts most is the timing: a stretch that combines the Obon shopping season, summer vacation and new trading card set releases went by without a single point being earned. As noted when we tracked how the damage at Asahi Group eventually showed up in its financial results, losses of this kind take shape not right after the incident but in earnings reports months later.
157 stores go down, and it still isn't news
Finally, the thing about this incident that bothered me most.
Stores across five brands have not functioned properly for over a week, and for the first three days the only coverage was a single INTERNET Watch article. A few security trade outlets followed later, but national newspapers and television have not moved at all. On X, customers are asking why this isn't making the news.
If I had to guess at the reasons: the stores are concentrated in a region centered on northern Kanto; the parent is not a nationally recognized listed company; and the damage is a "service outage" rather than a confirmed "large-scale data breach." Put those three together and it does not make the national papers.
But for the people who use those stores every day, scale is beside the point. You cannot pick up the new release you reserved, you cannot spend the points you saved, and the items you brought in to sell cannot be appraised. One post described re-reserving through another online retailer a CD that could not be reserved at Shinseido. During the days a business is down, customers drift elsewhere, and that share does not come back once systems are restored.
Reported ransomware cases in Japan hit a record 226 in 2025, and most involved small and midsize companies whose names nobody knows. Cases like this one, where "it never becomes national news but daily life in that area has definitively stopped," pile up behind those statistics every month. This article is kept up to date against the company's releases and its store status page; the latest check is the official update at 09:30 on August 17, 2026. We will add follow-ups here when points come back, when the leak investigation concludes, and when APORITO reopens.
The same thing, at other companies
"A system goes down and physical goods stop moving" has happened repeatedly in Japan this year. If you want to know what the road back looks like, the companies that have already walked it are the best guide.
A breach at Nichirei emptied the shelves at KFC Japan
One company was attacked; the people inconvenienced were another company's customers. Damages and response costs were eventually published.
How many days it took Asahi Group to get back to normal
Ten days to partial resumption. One hundred and ninety to full normalization. A preview of where this case may go.
A directory of the major ransomware groups and their methods
No group has been named in this case yet. Here is who is out there and how they operate.
References
- ▸ REXT Holdings - Notice regarding unauthorized access by ransomware (August 10, 2026, PDF)
- ▸ REXT Holdings - System failure from unauthorized network access and changes to store operations (second report) (August 14, 2026, PDF)
- ▸ REXT - Store operating status (per-store list) (as updated 09:30, August 17, 2026)
- ▸ RIZAP - Apology and report regarding unauthorized access to APORITO Online Store
- ▸ ITmedia NEWS - Unauthorized access to RIZAP-run EC site; personal and card data possibly exposed (August 12, 2026)
- ▸ REXT Corporation - Company profile (store counts)
- ▸ WonderGOO - Notice regarding the system outage (August 12, 2026)
- ▸ Shinseido - Notice regarding the system outage (August 12, 2026)
- ▸ WonderREX - Notice regarding the system outage (August 12, 2026)
- ▸ JEANS MATE - Notice regarding store operations following the system outage (August 11, 2026)
- ▸ HAPiNS - News
- ▸ INTERNET Watch - Security incidents at two RIZAP Group companies (August 12, 2026)
- ▸ ScanNetSecurity - D&M ransomware incident (via VPN) (June 25, 2026)
- ▸ National Police Agency - Threat landscape in cyberspace in 2025 (PDF)
- ▸ Askul - 18th report on the system outage (February 13, 2026)
- ▸ Asahi Group Holdings - On measures to prevent recurrence (February 18, 2026)
- ▸ KADOKAWA - Notice regarding the system outage

Backend Engineer / AWS / Django