Kindal data leak: 136,464 customers, names and home addresses exposed
If you are a customer of Kindal, here’s what is being claimed, and what it would mean for you.
Kindal, Treasure Factory’s second-hand brand clothing site, confirmed that a phishing email tricked a staff member and led to two bulk downloads of customer data on 23 August 2026. 136,464 people were affected, and 109,311 of them had a home address in the files, along with names, contact details and purchase records. Card numbers and shop passwords were not included.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Kindal customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On 22 August 2026, an employee at Kindal (カインドオル), the second-hand brand clothing site run by a Treasure Factory subsidiary, received an email pretending to come from the company that runs the shop’s online platform and typed staff login details into a fake page. An outsider used that staff account the same day. On 23 August they changed the email address registered on the account and ran two bulk downloads of customer data. Kindal found the problem on 24 August during ordinary work. Treasure Factory reported it to Japan’s Personal Information Protection Commission on 27 August and published an official filing on 28 August.
136,464 people were in those downloads. For 109,311 of them, a physical address was included. Depending on the customer, the files could also contain a customer ID, name, telephone number, date of birth, email address, newsletter-subscription status, number of orders, total amount spent, tags the store kept on the account, and a history of points held, expired and accumulated. Credit-card details and the passwords people use to log into the shop were not included. Treasure Factory said it had not confirmed any follow-on misuse at the time of the announcement, and that it is notifying affected customers individually.
What “no cards or passwords were taken” leaves out
Coverage of this incident will reach for the same comfort line, because it is true: payment cards and login passwords were not in the stolen files. If you are waiting to hear whether your card number is circulating from this event, that particular fear does not match what the company disclosed.
What did leave is more personal than a card number, and it lasts longer. For 109,311 people, someone now has a name together with a home address. Across the wider group, the same files can also hold a phone number, a date of birth and an email address, sitting next to a shopper profile: that you use Kindal, how often you order, what you have spent, your points, even internal tags. That mix is what a stranger uses to sound like the store, a courier, or a company that “already knows” you. A message that uses your real name and a points balance is not proof it came from Kindal. It is proof the sender has seen a file like this one.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
This is not a story about your house being chosen because you buy second-hand brand clothes. Nothing in the company’s filing supports that. The honest read is quieter and more lasting: a large record of who you are, where you live, and how you shop at Kindal is now outside the company’s control. It cannot be reeled back. No misuse had been confirmed as of 28 August. The risk that actually belongs to this incident is convincing fraud and impersonation built on details you did not give those people.
What to actually expect
- If you were in the downloads, Kindal or Treasure Factory should contact you directly. That notice is how you find out. A scan, a social post, or an email from an address you do not already trust cannot reliably tell you whether your record was among the 136,464.
- Expect copycat messages over the coming weeks that pretend to be Kindal, Treasure Factory, a delivery company, or the shop’s platform — especially ones that mention the incident, your points, or a need to “confirm your account.” The real company does not need you to type a password into a link to finish their investigation.
- Phone numbers and email addresses in the files may see more spam and scam calls. A caller who already knows your name, or that you shop at Kindal, is not therefore genuine.
- You should not expect card charges that come from this incident. Those numbers were not in the files. Watch instead for someone trying to use your identity details, not for a cloned card.
What you can and cannot fix
If your name, home address, telephone number, date of birth, email address, or Kindal purchase and points history were in those two downloads, that copy is out. It cannot be undone, recalled, or erased from whoever took it. Nobody can promise to remove the stolen file.
- Treat any unexpected request to click, log in, pay a “verification” fee, or re-enter personal details in connection with Kindal or this incident as hostile. Use only contact details published on the company’s own site, or printed in a notice you already know is theirs.
- Assume a scammer may know your name, that you shopped at Kindal, a spend or points figure, and possibly your address or date of birth. If you did not start the contact, hang up or ignore the message and go to the official site yourself.
- You cannot fix the leak. You can make that leaked record harder to use against you by shrinking the extra public trail around it. People-search pages and public directories often add relatives, extra phone numbers, employers and previous addresses. A bare store record becomes much more dangerous when it can be joined to that wider map of your life. Unlike the stolen Kindal data, those listings can often actually be removed, which is why they are the lever still in your hands.
- Keep questions about this incident for the company’s own inquiry channel. Do not hand over further documents, card numbers, or copies of ID to anyone who contacted you first claiming to help with the leak.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Betterment Robo-Advisor 1.4M Customers — January 2026
Robo-advisor Betterment disclosed a breach affecting ~1.4 million customers in January 2026 via a fa…
Brightspeed Fiber Broadband Incident — January 2026
Crimson Collective ransomware group allegedly stole personal data of over 1 million Brightspeed cust…