September 2026 brought an unusually high number of public breach announcements in Japan. A Japanese tech writer publishing under the name Cabbage (キャベツ) noted that breaches had been disclosed at Seicomart, a convenience store chain, as well as at Sagawa Express and Yamato Transport, companies many people use every week. The writer's conclusion is blunt: organizations that hold large amounts of customer data cannot fully prevent leaks, so individuals need a plan for both sides of an incident.
The source text available to us is brief, so this article does not detail what data was taken at each company. Instead, it uses the wave of disclosures as a prompt to explain what to do after data breach news arrives, and what you can do beforehand to make it matter less.
Why Breaches at Everyday Companies Are Now Unavoidable
Retailers and delivery firms are not obvious security targets in the way banks are, yet they hold names, addresses, phone numbers and purchase or delivery histories for huge numbers of people. That makes them valuable, and it makes them hard to defend perfectly. The practical takeaway from the source is a shift in mindset: you cannot control whether a company you use gets breached, but you can control how much of your information it holds and how much damage a leak can do.
This is also why one breach rarely stays contained. Exposed records are reused for phishing, impersonation and attempts to log in to other services. Our coverage of the Thailand Council of Engineers breach, which exposed records of roughly 350,000 members, shows how a single exposed database can become a long-term risk for the people in it.
Before a Leak: Limiting What Companies Hold About You
The most effective protection is data you never handed over. A few habits help:
- Share the minimum. If an optional field asks for a birth date, a second phone number or a home address you do not need to give, skip it.
- Use a unique password for every account. A password manager makes this realistic. If one service leaks your credentials, the others stay safe.
- Turn on multi-factor authentication (MFA) wherever it is offered, preferably with an authenticator app rather than SMS.
- Delete accounts you no longer use. Old loyalty and delivery accounts keep your data in someone else's database for no benefit to you.
- Consider a separate email address for shopping and deliveries, so a leak does not expose your main identity.
None of this is dramatic, but it changes the outcome of a breach from a serious problem to an inconvenience.
After a Leak: Passwords, MFA and Phishing Watch
When a company you use announces unauthorized access, work through these steps in order.
- Read the notice carefully. Find out which categories of data were involved: contact details, account credentials, payment information, or something else. Your response depends on this.
- Change the password on the affected service, and on any other account where you reused it. Do this by going to the service directly, not through a link in a message.
- Enable or review MFA and check the list of logged-in devices or active sessions if the service shows one.
- Check payment activity. If card details may have been involved, review statements and contact your card issuer if anything looks wrong.
- Expect phishing. Leaked contact details are often used to craft convincing messages. For delivery companies in particular, fake notices about missed parcels or address problems are an obvious pretext. Treat unexpected texts and emails with suspicion, even if they mention a real company you use.
A useful rule: if a message creates urgency and asks you to click, log in or pay, stop and open the official app or website yourself instead.
Where a VPN Helps and Where It Doesn't
A VPN encrypts your connection and hides your IP address from the sites you visit and from anyone on the same network. That is valuable on public Wi-Fi and for general privacy. But it does nothing to protect data that a company already stores. If Seicomart, Sagawa Express or Yamato Transport holds your details on its servers, a VPN cannot stop an attacker who breaks into those servers.
So treat a VPN as one layer among several, not a response to a breach. Strong unique passwords, MFA and careful data sharing do far more for this particular problem.
What This Means For You
If you live in Japan or use these services, check any official notices for the companies you deal with and follow their guidance. If you are elsewhere, the lesson is the same: breaches at ordinary, trusted companies are now a routine risk. Your goal is not to avoid every leak but to make sure a leak finds little to use and no easy way to reach your other accounts.
Takeaways: Steps to Take Today
Knowing what to do after data breach announcements is useful, but doing the groundwork now is better. Set aside twenty minutes:
- Install a password manager and replace reused passwords, starting with email, banking and shopping accounts.
- Turn on MFA for your most important accounts.
- Close accounts you no longer use and trim optional personal details from the ones you keep.
- Be skeptical of any unexpected delivery or account message.
For another example of how exposed records can be misused and why the response matters, read our report on the Thailand COE breach.




