eplus-refund-2026 · Disclosed 2026-09-29
イープラス: unauthorized access and impact
Unauthorized access targeted the separate SmartTicket refund-management system. 1,463 records leaked: 751 bank transfers, 644 card refunds, and 68 postal transfers. Card details and member passwords were unaffected.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Unauthorized access targeted the separate SmartTicket refund-management system.
[s1]1. 経緯 / 2. 漏えいした個人情報 / 4. 現時点の対応状況 - Reported fact
1,463 records leaked: 751 bank transfers, 644 card refunds, and 68 postal transfers. Card details and member passwords were unaffected.
[s1]1. 経緯 / 2. 漏えいした個人情報 / 4. 現時点の対応状況
Timeline
Reported response
- Reported fact
Access was blocked on September 15 and all managed systems re-inspected.
[s1]1. 経緯 / 2. 漏えいした個人情報 / 4. 現時点の対応状況
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The specific entry mechanism is undisclosed.
Sources
[s1] イープラス · Primary source
イープラス:事故に関する公表資料 ↗Reviewed 2026-10-09