Top/Articles/Ransomware halts registers at 157 Japanese retail stores, day five
wondergoo-rext-ransomware-cover-en

Ransomware halts registers at 157 Japanese retail stores, day five

REXT Corporation, which runs WonderGOO, Shinseido and WonderREX, was hit by ransomware on August 9. Registers, points and buybacks are still down on day five.

NewsPublished Aug. 13, 2026 Updated today
Table of contents
Key takeaways

REXT Corporation, which runs WonderGOO, Shinseido and WonderREX, was hit by ransomware on August 9. Registers, points and buybacks are still down on day five.

WonderGOO, Shinseido, WonderREX, HAPiNS, JEANS MATE. REXT Corporation, which runs all 157 stores across these five brands, has disclosed that it suffered a ransomware intrusion on August 9, 2026. Ransomware is an attack that encrypts a company's data without permission, making it unusable, and then demands money in exchange for restoring it.

The impact has landed squarely on the sales floor. Many stores have closed temporarily or are operating only partially, and even the ones that are open are cash-only as a rule, with no points earned or redeemed, and buyback intake and appraisal suspended. As of August 13, service still has not been restored. That is day five.

The outage falls right on the overlap of the Obon holiday travel season and summer vacation, one of the busiest stretches of the year for bookstores and hobby shops. Even so, as of this writing only one major outlet has covered the incident: INTERNET Watch. Here is what we know so far.

What you will find if you go to a store

First, the information that matters most if you are planning to visit a store. The situation differs considerably from brand to brand.

BrandStoresOperationsPaymentPointsOnline
WonderGOO43Closed except a few
→ reserved items only
Cash onlyNo earning
or redeeming
Shipping delayed
2-3 days
WonderREX36Mostly closedCash onlyCannot redeem
Shinseido25Changed hours
and limited service
Some e-payments
unavailable
Partly unavailableShipping delayed
HAPiNS24Normal hoursCash only as a rule
(some exceptions)
Normal
JEANS MATE24Normal hours
(manual checkout)
Cash only as a ruleNormal

From August 11, some WonderGOO stores began a partial reopening limited to handing over reserved items and lottery-won merchandise. The conditions are strict, though: cash only, no points, no credit cards or QR-code payments, and you must bring your reservation slip. Hold periods for new trading card set pre-orders and lottery sales were extended as well.

One thing that is easy to overlook is the suspension of buyback at WonderREX. For a reuse retailer, buyback is procurement itself, and halting intake and appraisal is the same as closing the front door for anyone trying to sell. Even a few days of suspension flows straight through to store inventory later on.

What the official announcement admitted

The release published by parent company REXT Holdings on August 10, 2026 states the following.

"On Sunday, August 9, 2026, we confirmed that unauthorized access by ransomware had occurred within part of the internal network systems of our subsidiary REXT Corporation."

The impacts listed are temporary store closures and partial operations, changes to opening hours, restrictions on cashless payments and similar services, suspension of buyback intake and appraisal, suspension of the points program, and delays in online order shipping. That matches what is actually happening in the stores.

The key point to grasp here is that all five brands are operated by a single company, REXT Corporation. A June 2022 reorganization consolidated the separate per-brand operating companies into one, and the store systems run on a shared platform. That is why a single attack simultaneously stopped the bookstores, the reuse shops, the CD stores, the variety goods stores and the apparel stores. Had there been as many companies as brands, the damage might have been far more contained.

In terms of ownership, REXT Corporation sits under REXT Holdings, which in turn sits under the RIZAP Group. RIZAP Group is listed on the Sapporo Securities Exchange Ambitious market, but no timely disclosure has been filed with the exchange over this incident; it has been announced only as a corporate press release. RIZAP Group is also due to report quarterly earnings on August 14.

What happened over five days

Here is the sequence of events, based on the official announcements and individual store notices.

← Swipe to navigate

The information was coming from store accounts

Another striking aspect of this incident is the route the information traveled.

On the morning of August 9, when the registers went down, the first to report the situation was neither headquarters nor a brand's official account, but the social media accounts run by individual stores. A short post saying: chain-wide server trouble, registers unusable.

WonderGOO's official account did not mention the incident until 1:11 p.m. on August 12. That was three days after the outage began and two days after the company's own public announcement. In the meantime, only store accounts kept posting individual updates on the situation.

Customers voiced their frustration with that silence in multiple posts, along the lines of "the whole chain is down and only individual store accounts are saying anything; nothing from the official account or the website" and "if the official account says nothing about a system outage, what is it official for?" There are also reports of people traveling to a store only to leave empty-handed, or being turned away when asking for an item to be held.

Communications during an outage are not a matter of corporate appearances. They are practical information customers need to decide whether to go to that store today. When they lag, everyone who shows up has wasted the trip, and complaints and front-line workload rise accordingly. In fact, the fastest and most accurate source for the specific terms of the partial reopening (cash only, bring your reservation slip, no points) was, again, the store accounts. Designing the first response to an outage, deciding what to isolate and how to communicate it, matters just as much as the technical preparations.

Was customer data leaked?

The REXT Holdings release says the following.

"Based on our investigation to date, we cannot completely rule out the possibility that customers' personal information, business partner information and similar data held by REXT Corporation has leaked externally."

In other words, a leak has not been confirmed, but it has not been ruled out either. Neither the number of records nor the data fields have been disclosed. The company says it will "proceed with" the legally required reports to bodies such as the Personal Information Protection Commission, and does not state that they have been completed. In incidents of this kind, the scope typically becomes more concrete as the investigation advances.

As for the attackers, almost nothing is known at this point. Here is the state of play.

✓ Confirmed facts

  • Unauthorized access by ransomware was confirmed on August 9 (source)
  • The company has publicly stated that the possibility of customer and other data leaking externally cannot be completely ruled out
  • Neither REXT nor any of the five brands appears on attacker-run leak sites (as of August 13)
  • As of August 13 systems are not fully restored, and no target recovery date has been announced

? Not yet known

  • ?The name of the group behind the attack — no claim of responsibility has been confirmed
  • ?The intrusion route — the company has disclosed nothing at all
  • ?Whether a ransom was demanded, and how much — no information
  • ?The number of records and data fields exposed — undisclosed
  • ?The exact number of closed stores — no store-by-store list has been published

The absence of a leak-site listing does not by itself mean "nothing was stolen." Attackers typically go public only after ransom negotiations break down, and a gap of two to four weeks between encryption and publication is not unusual. We have covered the names and methods of the major ransomware groups in a separate article, but in this case no group's name has surfaced yet.

Why the registers stopped while online stores kept running

This part is about the technology. The damage in this incident shows a clear pattern.

What stopped: in-store registers, electronic payments, points, buyback appraisal, and online order processing. Meanwhile, the official online shops of JEANS MATE and HAPiNS kept running normally. Same group, same attack, and yet one side was wiped out while the other was untouched.

The difference comes down to where the systems run. The online shops run on external services, in a different place from the internal network. Store registers, points and buyback appraisal, by contrast, only work once they are connected to the internal core systems. What was attacked was "part of the internal network systems," and only the things hanging off it were dragged down with it.

Registers are in a particularly tough spot. A terminal can scan a product barcode on its own, but looking up the price, allocating inventory, calculating points and authorizing a credit card all require querying a central system and waiting for an answer. The moment the other end goes silent, the register cannot produce a total. JEANS MATE and HAPiNS were able to switch to handwritten slips and cash and keep their doors open presumably because they sell clothing and variety goods, with little dependence on points or buyback. Handling trading card lottery sales or appraising used goods by hand is simply not realistic.

This pattern, where an IT failure directly halts a physical business, has appeared again and again in recent domestic incidents. The same thing happened in the case where a cyberattack stopped warehouses and the frozen food supply chain and in the case where an intrusion through a single VPN appliance held up a company's financial closing. According to National Police Agency statistics, more than 60 percent of ransomware intrusions came through VPN equipment, and although over 95 percent of victim companies had antivirus software installed, in more than 70 percent of those cases it failed to detect the attack.

The same group was hit two months ago

What cannot be overlooked is that this is not a first for the REXT group.

On June 1, 2026, D&M, a consolidated subsidiary of REXT Holdings, was infected with ransomware via a VPN appliance, and disclosed it on June 12. Data on 633 orders received by fax was said to have possibly been exposed. That was just two months before the current incident.

On the parent side, a separate matter was disclosed on the same day, August 10: a suspicious external-transmission program was found on an online store operated by RIZAP Group, and the site was taken down. That means two security incidents of different natures were disclosed on the same day by the same group.

No causal link between the individual incidents has been disclosed, so they cannot be tied together with any certainty. Still, it is a fact that, viewed across the group as a whole, incidents are recurring at short intervals. In corporate groups where each subsidiary has its own systems and its own management structure, lessons learned at one company can fail to reach the others, and the same weakness ends up being exploited somewhere else. The same pattern kept surfacing when we examined the seven Japanese manufacturers that disclosed breaches in March alone.

How long will recovery take?

No recovery estimate has been announced. For reference, here is how long recent domestic incidents actually took.

IncidentOccurredPartial sales
resumed
Full
normalization
Financial impact
Tokiwa
Industry
March 2025Next day (all stores)Card payments down
for over 2 months
Parent fell into
negative net worth
AskulOctober 202510 days117 days22.1 billion yen
net loss
Asahi
Group
September 202510 days190 daysRoughly 40
billion yen
KADOKAWA
/ DWANGO
June 2024Book shipments
about 70 days
About 4 monthsRevenue down
about 8.3 billion yen
NichireiJuly 202611 daysSpread to
business partners
REXT
(this case)
August 20262 days
(reserved items only)
UndeterminedUndisclosed

In National Police Agency statistics, about 47 percent of ransomware victims needed more than a month to recover. Only about 21 percent were done in under a week. REXT managed to resume handing over reserved items on day two, which puts its initial response on the fast side. But with core store functions such as registers, points and buyback appraisal still offline, the realistic yardstick for full normalization is weeks or months, not days.

What is especially concerning is the timing. The company stands to lose nearly all of the sales from a period that combines the Obon shopping season, summer vacation and new trading card set releases. As noted when we tracked how the damage at Asahi Group eventually showed up in its financial results, losses of this kind take shape not right after the incident but in earnings reports months later. RIZAP Group reports earnings on August 14.

157 stores go down, and it still isn't news

Finally, the thing about this incident that bothered me most.

Five brands and 157 stores have not functioned properly for five days, and yet the only coverage is a single INTERNET Watch article. Security trade outlets and local newspapers have not moved as of this writing. On X, customers are asking why this isn't making the news.

If I had to guess at the reasons: the stores are concentrated in a region centered on northern Kanto; the parent is not a nationally recognized listed company; and the damage is a "service outage" rather than a confirmed "large-scale data breach." Put those three together and it does not make the national papers.

But for the people who use those stores every day, scale is beside the point. You cannot pick up the new release you reserved, you cannot spend the points you saved, and the items you brought in to sell cannot be appraised. One post described re-reserving through another online retailer a CD that could not be reserved at Shinseido. During the days a business is down, customers drift elsewhere, and that share does not come back once systems are restored.

Reported ransomware cases in Japan hit a record 226 in 2025, and most involved small and midsize companies whose names nobody knows. Cases like this one, where "it never becomes national news but daily life in that area has definitively stopped," pile up behind those statistics every month. We will update this article with any follow-up from REXT and with any mention at RIZAP Group's earnings announcement on August 14.

References

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django