Further to our notice dated September 24, 2026, regarding suspicious messages impersonating our hotels or reservation websites, we have been informed by Temairazu Co., Ltd.* that guests’ personal information may have been leaked from “Temairazu,” the reservation management system we use.
*The company that operates the “Temairazu” reservation management system (hereinafter “Temairazu”).
Overview of the Potential Information Leak
Based on the information confirmed to date, Temairazu has identified cases in which suspicious messages were sent to some guests with reservations that meet both of the following conditions:
• Reservation date: The reservation was made by September 21, 2026.
• Stay date: The reservation includes a stay on or after September 21, 2026.
Temairazu has reported the following to us:
• The unauthorized access to “Temairazu” occurred only on Monday, September 21, 2026. No similar unauthorized access has been confirmed at any other time.
• Temairazu identified the cause on Saturday, September 26, 2026, and completed measures to address it.
• It cannot be ruled out that an unauthorized third party viewed or acquired certain guest information. Temairazu is currently investigating the full scope of the impact.
Neither our company nor Temairazu handles or stores credit card information.
We also conducted security checks on computers at our hotels and found no evidence of a cyberattack or virus infection.
Future Handling and Measures to Prevent Recurrence
We have strengthened information security for our hotels’ reservation and sales management systems, including updating various system settings. We will continue to work with Temairazu and other relevant organizations to prevent similar unauthorized access from occurring again.
Request to Guests
Please exercise caution if you receive a suspicious message, including by email or WhatsApp, that appears to come from one of our hotels or a reservation website. Such messages may contain fraudulent links leading to phishing sites.
We do not send emails requesting payment, nor do we direct guests to an external website without a legitimate reason. If you receive such an email, please do not click any link or make any payment.
Once again, we sincerely apologize for the considerable inconvenience and concern this incident has caused our guests.
Note: A “phishing site” refers to a fraudulent website designed to steal personal information, credit card numbers, etc., by mimicking a legitimate site.
If you have any questions or concerns regarding this incident, please contact us using the details below:
Contact Information
• Inquiries regarding this incident: Customer Relations Department (customer-mimaru@mimaruhotels.com)
• Inquiries regarding reservations: Please contact the hotel where you made your reservation directly.