HOME > Notice and Apology regarding the Leakage of Personal Information from Our Website "GG internet shop" due to Unauthorized Access.

Notice and Apology regarding the Leakage of Personal Information from Our Website "GG internet shop" due to Unauthorized Access.

January 7th 2020

Dear Customers

Gendai Guitar Co., Ltd.

Notice and Apology regarding the Leakage of Personal Information from Our Website
"GG internet shop" due to Unauthorized Access.

We have found that 133 credit card information and 19,328 personal information were possibly leaked from Gendai Guitar website named "GG internet shop" by unauthorized access.

We sincerely apologize for any inconvenience caused by this incident to all of you. Also, to tell the incident and express our apologies, we have sent emails individually to the customers whose personal information and credit card information were possibly leaked since today, January 7th 2020.
When you suffer any actual harm caused by the incident, we would like to ask you to contact us immediately.
Taking the incident seriously, we promise to take measures to prevent its recurrence. Along with our sincere apology, we would like to announce the outline of the incident below.
1.Timeline.
October 23rd 2019.
We received an inquiry from a customer about an error on our website.

October 24th 2019.
As the result of an investigation of a website development and management company and us, it was found that some information was possibly leaked from our website "GG internet shop". Therefore, we closed the website.

October 29th 2019.
A third party investigation company started their investigation into the incident.

November 22nd 2019.
According to their investigation, it was confirmed that the credit card information of some customers used during a certain period on the website "GG internet shop" were leaked and some of the information has been possibly compromised.

December 3rd 2019.
Based on their investigation report, we reported the incident to the Personal Information Protection Commission (PPC).

December 4th 2019.
We reported the incident to Tokyo Metropolitan Police Department.

2. The outline of the leakage of personal information.
(1) Cause.
It is caused by that the payment application was defaced by the unauthorized access into a vulnerability of our website system.

(2) The customers whose personal information and the credit card information were possibly leaked.
After the unauthorized access, the credit card information used for payment were leaked by unauthorized transactions. Here are the affected customers and the leaked information.

133 customers who used the credit card for their payment from October 6th 2019 to October 24th 2019. Here are the information that were possibly leaked.

- Card holder name.
- Number of the credit card.
- Expiration date.
- Security Code.
We have sent emails individually to 133 customers.

(3) The customers whose personal information were possibly leaked.
Some data in the server were leaked by the unauthorized access. Here are the affected customers and the leaked information.

19,328 customers who registered personal information or bought items on our website from June 25th 2008 to October 24th 2019. Here are the information that were possibly leaked.

- Name.
- Sex.
- Postal code.
- Address.
- Phone numbers.
- Fax numbers.
- E-mail address.
- Encrypted passwords.

3. Request to the customers.
Under the cooperation with each credit card company, Gendai Guitar and they have been already monitoring every transaction of the credit cards that were possibly leaked to prevent unauthorized uses.
We apologize for any inconvenience, but we would like to ask you to confirm again whether or not your credit card statements have any unrecognized transactions.
If you find the unauthorized transactions, we would like to ask you to report that to your credit card companies.
For when you hope to reissue your credit cards, we have asked the credit card companies to accept that without charging the customers any extra fee.
Also, although the long-in-passwords on our website were encrypted, we would like to ask you to change your passwords used for our website. If you use the same ones for other websites, we would like you to change them as well.

4. Reason for our late announcement.
First of all, we sincerely apologize for our late announcement that has taken time since the incident found at October 24th 2019.
We might have had to announce the incident at once to express apologies and to call for attention for unrecognized transactions on your credit cards. As the result of consultation with a credit card collection agency, however, we decided that we would release the announcement after the investigation of the third party investigation company was completed and after we ensured the cooperation strategy with each credit card company. That is to avoid your unnecessary confusion caused by releasing an uncertain information.
Again, we sincerely apologize for our late announcement.

5. The measures to prevent recurrence and the date of "GG internet shop" reopening.
Taking the incident seriously, we promise to take proper measures to strengthen the security and the surveillance on our website "GG internet shop" to prevent any recurrence.
Also, we will continue to cooperate with the investigation of the police and the related institutions or companies.
About the date of "GG internet shop" reopening, we are going to announce it on our website when it is decided.

6. The information desk for the incident.

E-mail address: cs@gendaiguitar.com