TOKYO - Major Japanese travel agency H.I.S. Co. said Wednesday that passport information for as many as 627 of its customers may have been leaked late last year through unauthorized access to a server of its Thai subsidiary.
H.I.S. Tours Co., the subsidiary, was alerted to the breach by an unauthorized-access detection system on Dec. 11, 2025, and disconnected the relevant server from the network and restricted access.
Investigations later determined that the server had been compromised and contained some personal information collected in Japan, according to the parent company.
H.I.S. said it had not immediately disclosed the breach publicly, even though a probe by external experts found in February that passport information may have been compromised, as it took "a long time to correctly analyze and cross-check the massive amount of data stored in the server."
The information that may have been leaked included names, genders, birth dates, passport numbers and expiration dates, as well as allergies, and pertained to people who used H.I.S. and traveled to Thailand in 2017, between 2019 and 2020, and between 2024 and 2025.
The information, however, did not include phone numbers, addresses, email addresses or credit card details.
H.I.S. apologized and said it will contact affected customers whose contact information could be identified.
Major non-life insurer Sompo Japan Insurance Inc. said the same day that around 60,000 items of customer information from its rental dashcam service may have been leaked via unauthorized access to a server of one of its contractors on Friday and Saturday.
Names, phone numbers, addresses, workplaces, email addresses and dashcam serial numbers may have been compromised, although it has not confirmed any misuse of the information.
"We sincerely apologize for any concerns and inconveniences caused," the company said in a release.