← Incident database

awabank-test-environment-2026 · Disclosed 2026-04-03

Awabank: leakage from a retained test environment

A test environment due for retirement and data deletion remained for AI-related verification. Credential-based unauthorized access led to reported customer and shareholder data leakage.

CredentialsConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    External unauthorized access used an ID and password against the test environment.

    [s1]原因
  • Reported fact

    The bank reported missing post-development retirement and data deletion, and insufficient access controls.

    [s1]原因 / 再発防止策

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    The bank announced planned retirement after police investigation and reviews of system management and access controls.

    [s1]再発防止策

Evidence relevant to prevention

Operational controls to inspect

Inspect real data in nonproduction, exposure, ownership, retirement deadlines, and deletion evidence.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

AI is mentioned as a business reason for retaining the environment, not evidence of attacker AI use.

Credential acquisition and detailed decisions behind retaining the environment are unknown.

Sources

  1. [s1] 阿波銀行 · Primary source

    情報流出に関する調査結果および再発防止策について ↗

    Published 2026-06-03 · Reviewed 2026-10-02