← Incident database

eplus-refund-2026 · Disclosed 2026-09-29

イープラス: unauthorized access and impact

Unauthorized access targeted the separate SmartTicket refund-management system. 1,463 records leaked: 751 bank transfers, 644 card refunds, and 68 postal transfers. Card details and member passwords were unaffected.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Unauthorized access targeted the separate SmartTicket refund-management system.

    [s1]1. 経緯 / 2. 漏えいした個人情報 / 4. 現時点の対応状況
  • Reported fact

    1,463 records leaked: 751 bank transfers, 644 card refunds, and 68 postal transfers. Card details and member passwords were unaffected.

    [s1]1. 経緯 / 2. 漏えいした個人情報 / 4. 現時点の対応状況

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Access was blocked on September 15 and all managed systems re-inspected.

    [s1]1. 経緯 / 2. 漏えいした個人情報 / 4. 現時点の対応状況

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The specific entry mechanism is undisclosed.

Sources

  1. [s1] イープラス · Primary source

    イープラス:事故に関する公表資料 ↗

    Reviewed 2026-10-09