Skip to content
Back to Blog
high severity August 29, 2026 · 4 min read Unverified claim — what this is

Kindal data leak: 136,464 customers, names and home addresses exposed

If you are a customer of Kindal, here’s what is being claimed, and what it would mean for you.

Kindal, Treasure Factory’s second-hand brand clothing site, confirmed that a phishing email tricked a staff member and led to two bulk downloads of customer data on 23 August 2026. 136,464 people were affected, and 109,311 of them had a home address in the files, along with names, contact details and purchase records. Card numbers and shop passwords were not included.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Kindal data leak: 136,464 customers, names and home addresses exposed

On 22 August 2026, an employee at Kindal (カインドオル), the second-hand brand clothing site run by a Treasure Factory subsidiary, received an email pretending to come from the company that runs the shop’s online platform and typed staff login details into a fake page. An outsider used that staff account the same day. On 23 August they changed the email address registered on the account and ran two bulk downloads of customer data. Kindal found the problem on 24 August during ordinary work. Treasure Factory reported it to Japan’s Personal Information Protection Commission on 27 August and published an official filing on 28 August.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

136,464 people were in those downloads. For 109,311 of them, a physical address was included. Depending on the customer, the files could also contain a customer ID, name, telephone number, date of birth, email address, newsletter-subscription status, number of orders, total amount spent, tags the store kept on the account, and a history of points held, expired and accumulated. Credit-card details and the passwords people use to log into the shop were not included. Treasure Factory said it had not confirmed any follow-on misuse at the time of the announcement, and that it is notifying affected customers individually.

What “no cards or passwords were taken” leaves out

Coverage of this incident will reach for the same comfort line, because it is true: payment cards and login passwords were not in the stolen files. If you are waiting to hear whether your card number is circulating from this event, that particular fear does not match what the company disclosed.

What did leave is more personal than a card number, and it lasts longer. For 109,311 people, someone now has a name together with a home address. Across the wider group, the same files can also hold a phone number, a date of birth and an email address, sitting next to a shopper profile: that you use Kindal, how often you order, what you have spent, your points, even internal tags. That mix is what a stranger uses to sound like the store, a courier, or a company that “already knows” you. A message that uses your real name and a points balance is not proof it came from Kindal. It is proof the sender has seen a file like this one.

This is not a story about your house being chosen because you buy second-hand brand clothes. Nothing in the company’s filing supports that. The honest read is quieter and more lasting: a large record of who you are, where you live, and how you shop at Kindal is now outside the company’s control. It cannot be reeled back. No misuse had been confirmed as of 28 August. The risk that actually belongs to this incident is convincing fraud and impersonation built on details you did not give those people.

What to actually expect

  • If you were in the downloads, Kindal or Treasure Factory should contact you directly. That notice is how you find out. A scan, a social post, or an email from an address you do not already trust cannot reliably tell you whether your record was among the 136,464.
  • Expect copycat messages over the coming weeks that pretend to be Kindal, Treasure Factory, a delivery company, or the shop’s platform — especially ones that mention the incident, your points, or a need to “confirm your account.” The real company does not need you to type a password into a link to finish their investigation.
  • Phone numbers and email addresses in the files may see more spam and scam calls. A caller who already knows your name, or that you shop at Kindal, is not therefore genuine.
  • You should not expect card charges that come from this incident. Those numbers were not in the files. Watch instead for someone trying to use your identity details, not for a cloned card.

What you can and cannot fix

If your name, home address, telephone number, date of birth, email address, or Kindal purchase and points history were in those two downloads, that copy is out. It cannot be undone, recalled, or erased from whoever took it. Nobody can promise to remove the stolen file.

  • Treat any unexpected request to click, log in, pay a “verification” fee, or re-enter personal details in connection with Kindal or this incident as hostile. Use only contact details published on the company’s own site, or printed in a notice you already know is theirs.
  • Assume a scammer may know your name, that you shopped at Kindal, a spend or points figure, and possibly your address or date of birth. If you did not start the contact, hang up or ignore the message and go to the official site yourself.
  • You cannot fix the leak. You can make that leaked record harder to use against you by shrinking the extra public trail around it. People-search pages and public directories often add relatives, extra phone numbers, employers and previous addresses. A bare store record becomes much more dangerous when it can be joined to that wider map of your life. Unlike the stolen Kindal data, those listings can often actually be removed, which is why they are the lever still in your hands.
  • Keep questions about this incident for the company’s own inquiry channel. Do not hand over further documents, card numbers, or copies of ID to anyone who contacted you first claiming to help with the leak.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Kindal is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High contact details only, none of them permanent
Disclosed August 29, 2026
Last reviewed August 29, 2026
Affected Unconfirmed
Data exposed Full namesHome addressesPhone numbersDates of birthEmail addressesCustomer IDsOrder countsPurchase amounts +3 more
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email