A security flaw on the Hello Kitty website that exposed millions of citizens' personal data has been "fixed," according to the brand's owner.
Earlier this week, a computer security researcher revealed that the information of approximately 3.3 million Sanrio Town members was accessible.
Japanese company Sanrio, which owns Hello Kitty and runs Sanrio Town, said it had now closed the loophole. The Commission added that there is no information about Hello Kitty fans that has been stolen.
"We have investigated the issue and implemented fixes, including securing the servers deemed vulnerable," Sanrio said in a post on its website.
The Commission added that only personal information, such as names, email addresses and encrypted passwords, was available to those who knew where to find the servers.
Information for over 180,000 children was in this cache. No credit card or payment information was being processed on the vulnerable servers.
Sanrio added that it had conducted an internal investigation and review to learn why the servers were misconfigured so they could be accessed.
"We currently have no indication that users' personal information has been stolen by third parties," an advisor said in a note.
Even so, Sanrio has sent messages to Sanriotown members advising them to change the password used for the site and to change anything else where they used the same character sequence.
Chris Vickery, the researcher who revealed the data access, disputes Sanrio's claim that member data was not breached.
He said he used several different addresses to access the data and confirmed it was vulnerable. Sanrio is the latest in a long line of companies that have failed to protect their customers' data. In recent months, data about users of VTech, TalkTalk and Ashley Madison has been exposed online.

