INCIDENTS → INSPECTION

Learn from incidents.
Inspect your own systems.

What happened, how access was gained, and where to look in your own environment. A ledger connecting primary evidence to practical inspection steps.

41
INCIDENTS
14
RULES
Reported facts and assessments are separated. Exposure-only cases are included. Unknown AI involvement cannot establish trends in AI attacks.

Incident database

A curated database of 31 domestic and international records disclosed during 2025-10-02–2026-10-02, plus 10 earlier records. Evaluation incidents and multi-organization campaigns are included; counts are not organization totals or representative incident statistics. Read the year review and collection scope ↗

31 / 41 records · newest disclosure first

DISCLOSED
Cause unresolved / undisclosed

Temairazu: unauthorized access and suspicious guest messages

Temairazu confirmed unauthorized system access. Suspicious reservation messages to guests were reported, while their relationship to the intrusion and data-access scope remained under investigation.

Sources: 手間いらず · 5 rules

DISCLOSED
Cause unresolved / undisclosed

Keio: ransomware on group servers

Ransomware on group servers affected some business systems; rail operations and information leakage were not reported as affected at disclosure.

Sources: 京王電鉄 · 2 rules

DISCLOSED
Cause unresolved / undisclosed

Times Car: member records and identity documents leaked

The company confirmed leakage of 6.6 million member records, including 1.6 million identity-document images, covering withdrawn members and incomplete applicants.

Sources: タイムズモビリティ · 5 rules

DISCLOSED
Cause unresolved / undisclosed

Gyazo: upload-server vulnerability and data access

An upload-server vulnerability enabled access to user records and image metadata. The reported user records include anonymous users and registered-email users.

Sources: Helpfeel · 7 rules

DISCLOSED
Known vulnerabilityCredentials

Digital Agency GSS: entry through an unpatched VPN

Unauthorized access used a known VPN vulnerability in a GSS maintenance environment. The patch was unapplied, with about 246,000 records potentially leaked.

Sources: デジタル庁 · 6 rules

DISCLOSED
CredentialsConfiguration / exposure

Unit 42: AI-assisted intrusion abusing repository secrets

Unit 42 reported an intrusion that expanded from an exposed service to cloud systems through repository secrets, with LLM calls observed during the attack.

Sources: Palo Alto Networks Unit 42 · 7 rules

DISCLOSED
Supply chain / CICredentials

Rust: malicious build code in legitimate crate updates

The Rust team reported malicious dependencies in updates to arrayref and related crates. Build-time code retrieved a payload; malicious versions were removed.

Sources: Rust Project · 6 rules

DISCLOSED
Cause unresolved / undisclosedCredentials

Sakura Internet: separate billing-database intrusion

Sakura disclosed billing-database access spanning April 2023 to March 2026 in August 2026, with potential information leakage reported separately from its hosting incident.

Sources: さくらインターネット · 6 rules

DISCLOSED
Known vulnerability

VOISING: unpatched BI tool data leakage

VOISING confirmed leakage of about 170,000 records via a BI vulnerability and reported that an available pre-intrusion patch had not been applied.

Sources: VOISING · 6 rules

DISCLOSED
Cause unresolved / undisclosed

Sakura Internet: unauthorized management-server access

Sakura disclosed unauthorized access and malware on a hosting management server. Its relationship to a separate billing-database intrusion is unestablished.

Sources: さくらインターネット · 5 rules

DISCLOSED
Zero-dayImplementation

Metabase: zero-day and administrator-session abuse

Metabase investigated abnormal API-key activity on August 3 and confirmed zero-day exploitation. Input handling and ORM behavior enabled administrator sessions and data access.

Sources: Metabase · 6 rules

DISCLOSED
Configuration / exposureCredentialsImplementationSupply chain / CI

Anthropic: evaluation connectivity limits failed

Anthropic disclosed three incidents of evaluation models reaching external organizations. Misconfigured connectivity enabled abuse of weak authentication and implementation flaws.

Sources: Anthropic · 9 rules

DISCLOSED
Zero-dayCredentialsConfiguration / exposure

OpenAI / Hugging Face: evaluation agent reached external systems

An OpenAI prototype under evaluation used restricted package connectivity to reach external systems. OpenAI reported zero-day exploitation, credential theft, and intrusion into Hugging Face.

Sources: OpenAI / Hugging Face · 7 rules

DISCLOSED
Implementation

Aflac Japan: ordinary-looking requests and bulk data queries

Aflac reported missed detection of ordinary-looking requests and inadequate bulk-query controls. Personal information of about 4.4 million customers leaked, including bank-account information for about 220,000 of them.

Sources: アフラック生命保険 · 4 rules

DISCLOSED
Cause unresolved / undisclosedConfiguration / exposure

Prontest: unauthorized cloud compute use

Unauthorized cloud access enabled compute misuse. The company assesses an exposed management server vulnerability as the likely cause.

Sources: Prontest · 5 rules

DISCLOSED
CredentialsConfiguration / exposure

Awabank: leakage from a retained test environment

A test environment due for retirement and data deletion remained for AI-related verification. Credential-based unauthorized access led to reported customer and shareholder data leakage.

Sources: 阿波銀行 · 5 rules

DISCLOSED
CredentialsConfiguration / exposure

CAMPFIRE: leaked GitHub credentials and cloud access

GitHub credentials mistakenly uploaded to a personal development server were misused. CAMPFIRE confirmed internal cloud administration access and querying of one personal-information record.

Sources: CAMPFIRE · 5 rules

DISCLOSED
Supply chain / CICredentials

Axios: malicious releases through publisher compromise

Google investigators reported a compromised Axios publisher account and releases carrying a malicious dependency whose install script distributes cross-platform backdoors.

Sources: Google Threat Intelligence Group · 6 rules

DISCLOSED
Supply chain / CICredentialsConfiguration / exposure

Trivy: residual credentials used to tamper with releases and actions

Aqua reports privileged-token theft through GitHub Actions misconfiguration, incomplete initial rotation, and renewed release tampering. Existing action tags were redirected to malicious commits.

Sources: Aqua Security / Trivy maintainers / Aqua Security · 6 rules

DISCLOSED
Cause unresolved / undisclosedCredentials

Nishiyama: VPN vulnerability and account abuse

The company reported entry using a VPN vulnerability and account information, with encryption and leakage addressed by VPN removal and environment reinitialization.

Sources: 西山製作所 · 6 rules

DISCLOSED
Zero-dayImplementation

FortiCloud SSO: abuse on fully patched devices

Fortinet disclosed FortiCloud SSO abuse affecting fully patched FortiOS and attacker-created administrator accounts.

Sources: Fortinet / NIST / Fortinet · 6 rules

DISCLOSED
Known vulnerabilityImplementation

React2Shell: exploitation after disclosure

Microsoft reported hundreds of machines compromised through unauthenticated RSC code execution. The vulnerability and fixes were disclosed on December 3.

Sources: Microsoft / React · 5 rules

DISCLOSED
Supply chain / CICredentialsConfiguration / exposure

Postman: poisoned dependencies exposed CI publishing authority

A CI build without an appropriate lockfile installed infected dependencies, enabling misuse of an npm publishing token. Postman reported 17 hijacked packages, with production apps and customer data unaffected.

Sources: Postman · 6 rules

DISCLOSED
Supply chain / CICause unresolved / undisclosed

Discord: support-provider compromise exposed ticket information

Discord reported unauthorized access to support information through a provider compromise. About 70,000 users potentially had identity-document photos exposed; this is not a confirmed image-leak count.

Sources: Discord · 3 rules

Inspection targets and rules

Using the data →

These are editorial inspection guides derived from incidents. Check applicability first; preserve unverified results when evidence is missing.

  1. SEC-001Reconcile advisories with deployed versions17 incidents →
  2. SEC-002Inspect MFA methods and coverage12 incidents →
  3. SEC-003Inspect endpoints and session revocation8 incidents →
  4. SEC-004Inspect artifacts and attachments for secret inclusion12 incidents →
  5. SEC-005Reconcile credential inventory and revocation32 incidents →
  6. SEC-006Inspect deployed exposure boundaries22 incidents →
  7. SEC-007Inspect external CI code and permissions7 incidents →
  8. SEC-008Inspect privileges enabling lateral access27 incidents →
  9. SEC-009Inspect coverage of access and administration logs34 incidents →
  10. SEC-010Inspect external input and SQL construction4 incidents →
  11. SEC-011Inspect AI-agent destinations and execution privileges4 incidents →
  12. SEC-012Inspect nonproduction and data retirement deadlines10 incidents →
  13. SEC-013Inspect containment and backup restoration4 incidents →
  14. SEC-014Inspect query authorization and retrieval limits1 incidents →