estore-shopserve-2026 · Disclosed 2026-08-01
ショップサーブ: unauthorized access and impact
A malicious server program transmitted buyer data externally; the entry mechanism remains under investigation. 8,853,839 registered records may include multiple entries per person; merchant credentials were also affected.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Attack-source traffic was blocked and customer and merchant password changes requested.
[s1]第2報 §§1-4 / 対象件数
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The initial entry chain, product, CVE and availability of a prior fix are undisclosed.
Sources
[s1] ショップサーブ · Primary source
ショップサーブ:事故に関する公表資料 ↗Reviewed 2026-10-09