Japanese Sex Toy Firm Tenga Suffers US Data Breach

TENGA suction cup against a data security background
Picture: Canva
The company took pains to reassure its Japanese customer base that information about their masturbatory habits was safe.

Don’t miss a thing – get our free newsletter

US customers of one of Japan’s most trusted brands for perverts may be feeling a little uneasy this week. Japanese manufacturer Tenga acknowledged it was the victim of a data breach impacting a “limited segment” of its American base.

A sex toy unlike any other

Tenga is a manufacturer of masturbatory sex toys primarily for men. Led by ex-mechanic Matsumoto Koichi (who, I’m assuming, knows a thing or two about priming the pump, if you know what I mean), the company has won awards and an international fan base for the unique design of its products.

The 28-person company, whose name means “elegant” in Japanese, is staffed with experts in the art of jerking off. Satō Masanobu, the Director of Overseas Business, reportedly holds the world record for the longest time spent masturbating at a skin-chafing 9 hours and 58 minutes. (Ouch?)

As opposed to other manufacturers, Tenga doesn’t pattern its product after the female vagina. Instead, it fashions itself as the Apple of the sex toy industry, and aims for a stylish presentation in its advertising that avoids overt sexual imagery.

Tenga frequently releases surveys tracking the state of sex both in Japan and around the world. Frequent UJ readers may remember its survey from way back when that found food was more popular in Japan than sex.

Company reassures Japanese customers

Translation into English: 

【Report Regarding Unauthorized Access to an Employee Email Account and Suspicious Email Distribution at TENGA's U.S. Office】

We have confirmed an incident at our U.S. office where an external party gained unauthorized access to the email account of one employee. As a result, spam emails were sent to the email addresses of companies and individuals who had corresponded with this account.

While some inaccurate information originating from the U.S. has spread on social media, causing concern among our Japanese customers, we wish to clarify that both the Japanese and international TENGA official e-commerce sites are managed under stricter security protocols. There has been no leakage of personal information for customers who have used the Japanese TENGA official e-commerce site.

We sincerely apologize for any concern this incident may have caused.
Tenga’s message of reassurance to its Japanese customer base.

Tenga acknowledged the US data breach in a post in English on its website. According to the manufacturer, someone compromised a single email account belonging to someone in customer service. The attacker gained access to the account and then used it to send a spam email containing an attachment. It’s not clear what the attachment was intended to do.

A small portion of customer records, including customers’ names, email addresses, and conversations with Tenga representatives, was potentially exposed. Tenga emphasized that no financial information, such as credit card numbers, was exposed in the breach. It also emphasized that the attack did not compromise any of its core data stores that hold such sensitive information.

More importantly for Japanese customers, the company emphasized that this only affects a small portion of its US customer base and that no Japanese accounts were compromised. That’s critical in Japan, where sex largely remains a taboo topic.

In a statement in Japanese on X, the company said, “both the Japanese and international TENGA official e-commerce sites are managed under stricter security protocols” (TENGA公式ECサイトは日本・海外ともに、より厳格なセキュリティで管理されており). This appears to refer to the enhanced security measures used to protect its e-commerce systems in Japan and abroad.

Want more news and views from Japan? Donate $5/month ($60 one-time donation) to the Unseen Japan Journalism Fund to join Unseen Japan Insider. You'll get our Insider newsletter with more news and deep dives, a chance to get your burning Japan questions answered, and a voice in our future editorial direction.

How Tenga is responding

According to press reports, the attack on the Tenga employee’s account was a Business Email Compromise (BEC) attack. This is a form of social engineering in which an attacker impersonates a trusted leader within the company to gain access to sensitive personal or financial information.

In response, Tenga said it reset the affected employee’s account. According to TechCrunch, the company has also instituted Multi-Factor Authentication (MFA) access for its employees’ accounts. (The company said it already used MFA and “rigorous user management” to protect its data stores containing customer financial information.)

The company said that customers should be unaffected if they didn’t run the suspicious attachment sent via email. It encouraged all customers to use common “recommended security practices,” such as regularly changing their account passwords and not reusing passwords across accounts, to remain safe.

Get More UJ

Support our work by subscribing to Unseen Japan Insider. You’ll get a bonus article, just for members, emailed to you every week. Plus, you’ll get access to our Insider back issues archive, “ask us anything” privileges, and a voice in our future editorial direction.

What to read next

Sources

TENGAの米国拠点で顧客情報が一部漏えい→ネットがざわつく→日本でも声明「流出はない」. ITMedia

Clarification on the Recent Email Incident for US Customers. TENGA

Sex toys maker Tenga says hacker stole customer information. TechCrunch

Understanding business email compromise (BEC). Microsoft

Tenga (company). Wikipedia

Don’t miss a thing – get our free newsletter

Before You Go...

Let’s stay in touch. Get our free newsletter to get a weekly update on our best stories (all human-generated, we promise). You’ll also help keep UJ independent of Google and the social media giants.

Want a preview? Read our archives.

Read our privacy policy