← Incident database

en-midcareer-credential-stuffing-2026 · Disclosed 2026-06-05

エン: unauthorized access and impact

Credential stuffing used IDs and passwords apparently obtained elsewhere; internal credential leakage was not found. The total is 2,503 unauthorized logins, not a disclosed count of unique people.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Credential stuffing used IDs and passwords apparently obtained elsewhere; internal credential leakage was not found.

    [s1]pp.1-2 §§1-3
  • Reported fact

    The total is 2,503 unauthorized logins, not a disclosed count of unique people.

    [s1]pp.1-2 §§1-3

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Source traffic was blocked; passwords were reset and users notified regardless of identified compromise.

    [s1]pp.1-2 §§1-3

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.

Sources

  1. [s1] エン · Primary source

    エン:事故に関する公表資料 ↗

    Reviewed 2026-10-09