Skip to content
Back to Blog
high severity August 29, 2026 · 4 min read

Kindol vintage shop leak: 136,464 customers and 109,311 home addresses taken

If you received a notice from Kindol vintage shop, here’s what the filing says was exposed, and what to do about it.

Treasure Factory confirmed on 28 August 2026 that a phishing email let an attacker into a staff account at Kindol, its vintage-clothing site, and that customer records were copied twice. 136,464 customers were affected; 109,311 of those records included a home address. Card numbers and site passwords were not in the stolen files.

Kindol vintage shop leak: 136,464 customers and 109,311 home addresses taken

On 28 August 2026, Treasure Factory told the Tokyo Stock Exchange that customer records from Kindol, its vintage-clothing online shop, had been stolen. An attacker sent a staff member a phishing email that impersonated the shop’s e-commerce platform, got into a staff account on 22 August, then on 23 August changed the email address on that account and copied customer records in two bulk downloads. Staff spotted the email change the next day, 24 August, during ordinary work.

The company says 136,464 customers were in those files. 109,311 of the records included a physical address. Depending on the customer, a file could also hold a name, customer ID, phone number, date of birth, email address, newsletter status, number of orders, total amount spent, tags stored on the platform, and point history. Credit-card details and site login passwords were not included. As of that 28 August statement, Treasure Factory said it had not found any further misuse. It shut the affected staff account, required an extra sign-in step on remaining staff accounts, told Japan’s privacy regulator on 27 August, and is notifying affected customers individually. If you have never been a customer of Kindol’s site, this file is not about you.

The sentence that makes this sound smaller than it is

Reports of this leak will lead with a true fact: payment cards and passwords were not in the stolen files. For anyone who shops at Kindol, that is not the same as “nothing useful was taken.”

What the attacker has is a labelled customer file. For more than a hundred thousand people it includes a name matched to a home address. For many of those people it also includes a date of birth, a phone number, an email address, and a record of how often they buy and how much they spend. That is the raw material for a convincing fake “your Kindol order” message, a phone call that already knows your address, or other impersonation that uses your name, birthday and where you live together. The thief does not need a card number to do any of that.

The honest read is not that your bank account is about to be emptied because of this incident. It is that a stranger now holds a shopper file on 136,464 people, and for 109,311 of them that file includes where they live. Those copies cannot be pulled back. When the company says no further misuse had been found as of 28 August, that only describes the few days after the downloads — not what happens to a customer list weeks or months later.

What to actually expect

  • A notice from Kindol or Treasure Factory. They said they are contacting affected customers one by one. A real notice can still be mimicked; do not treat a link or attachment in an unexpected email as proof it is from the shop.
  • Follow-up scams that use your real name, address, order history, or points balance. Those details are in the stolen files, so a message that “already knows” them is not evidence it is genuine.
  • You should not expect card charges that come from this leak itself. Treasure Factory said card details were not exported.
  • A quiet stretch, then contact much later. Stolen shopper lists are often used or sold on a delay. Silence in the first week does not mean the copies are gone.

What you can and cannot fix

What was copied cannot be undone. If your name, home address, date of birth, phone number, email address, or purchase history was in those two downloads, those copies are out. No company can recall them. An address that has left the shop is out; saying so is not pessimism, it is the limit of what a leak like this allows.

Your Kindol password and your card number were not in this file, according to the company. This incident is not evidence those were stolen. Changing a password you reuse elsewhere is still sensible; it does not reverse the customer-record leak.

  • Treat unexpected Kindol, delivery, refund, or points messages as untrusted until you check them through a channel you already use — the site or app you already log into, or a contact method you already have — not a link inside the message. The attacker has enough of your details to forge the first email or call.
  • Watch for impersonation that combines your name with your address and date of birth. That grouping is useful for fraud even without a card. In the months after a leak like this, the practical risk is fake shop contact and attempts to use your identity details, not an instant raid on a bank account.
  • Reduce what people-search and data-broker listings already publish about you. A bare Kindol record becomes much more dangerous when it can be joined to pages that add relatives, extra phone numbers, employers, and previous addresses. Those listings, unlike the stolen shop file, can actually be removed or suppressed. That is the lever still in your hands: make it harder to turn “name plus this address” into a full dossier on you.

Report details & sourcing

Severity High contact details only, none of them permanent
Disclosed August 29, 2026
Last reviewed August 29, 2026
Affected Unconfirmed
Data exposed Full namesHome addressesPhone numbersDates of birthEmail addressesPurchase historyCustomer IDsLoyalty point history +2 more
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email