cmic-ra-connect-2026 · Disclosed 2026-07-24
旭化成セラピューティクス・シミックHCI: unauthorized access and impact
Files in the publicly served area of a patient-support service were retrieved by a third party. The disclosed groups are 30 patients, 216 email-only patient records, 1,535 medical professionals and two client-staff groups of 113 and 46, totaling 1,940.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Access was blocked and credentials changed; publication permissions, access management and file monitoring were reviewed.
[s1]§§1-4
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The public-storage configuration and scopes are established; actual third-party downloads are unresolved. This is separate from the October Pharma DIGITAL event.
Sources
[s1] 旭化成セラピューティクス・シミックHCI · Primary source
旭化成セラピューティクス・シミックHCI:事故に関する公表資料 ↗Reviewed 2026-10-09