Sompo Japan and H.I.S. hit by data breaches exposing personal info

Sompo Japan Insurance announced that there was unauthorized access to a server of a contractor responsible for managing customer inquiries.

The company said about 60,000 personal records may have been leaked as a result.

The information that may have been exposed includes name, address, phone number, work information and inquiry details.

Sompo Japan said no credit card information or My Number identification card data were included.

The contractor in question is Scala Communications, which provides inquiry management systems for businesses.

Daiwa Securities, which also uses Scala’s services, said on October 5 that 110,000 customer records were leaked.

Meanwhile, major travel agency H.I.S. said passport information belonging to as many as 627 people may have been exposed following unauthorized access to a server of its subsidiary in Thailand.

Those affected are customers who traveled to Thailand using H.I.S. services in 2017, 2019, 2020, 2024 and 2025.

The company said information that may have been leaked includes passport number, name, gender and date of birth but does not include address, phone number and credit card data.

Although the possible leak was identified in February this year, H.I.S. said it took more than seven months to announce the matter because the affected server contained a large amount of data unrelated to personal information in many different file formats, requiring time to identify and extract the data concerned.