H.I.S.Co., Ltd.Unauthorized server access at its Thai subsidiary may have leaked passport data of up to 627 customers, triggering a data-breach investigation and regulatory reporting.

Travel giant HIS announced on the 7th that a server at its Thai subsidiary was subjected to unauthorized access by a third party, and passport information for up to 627 people may have been leaked. Those affected are customers who departed for Thailand using the company's services in 2017, 2019-2020, and 2024-2025. Information such as passport numbers and expiration dates may have been leaked, but phone numbers and credit card information were not included. The unauthorized access was detected on December 11, 2025, and the server in question was promptly disconnected from the network and external access was restricted. On December 29 of the same year, the company confirmed that some of the personal information obtained in Japan was contained within the server, and reported the matter to personal information protection organizations and others. On February 24, 2026, an investigation by outside experts revealed that passport information was included, leading the company to decide to scrutinize all stored files. Regarding the reason it took time to make the announcement, the company explained that a large amount of data unrelated to personal information was also stored on the server, and because file formats and storage conditions varied widely, work to scrutinize and cross-check the data, including manual efforts, was necessary.
H.I.S.Co., Ltd.Unauthorized server access at its Thai subsidiary may have leaked passport data of up to 627 customers, triggering a data-breach investigation and regulatory reporting.