conoha-wing-2026 · Disclosed 2026-09-20
ConoHa WING: unauthorized access and impact
Some hosted web-server areas were accessed and malicious programs installed; technical entry details are undisclosed. 426 hosting accounts are affected; separately stored membership, contract and payment information is reported unaffected.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
The scope was determined and malicious programs removed by September 18; affected customers were individually contacted.
[s1]§§1-3
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The initial entry mechanism and prior patch availability are unknown. Hosting and membership/billing systems have separate scopes.
Sources
[s1] ConoHa WING · Primary source
ConoHa WING:事故に関する公表資料 ↗Reviewed 2026-10-09