← Incident database

expo-subcontractor-mail-2026 · Disclosed 2026-08-20

2025年日本国際博覧会協会: unauthorized access and impact

A phishing message impersonating an overseas firm preceded unauthorized Microsoft 365 access at a subcontractor. Potential scope includes stakeholder and performer mail and attachments. The reviewed notice gives no person count; the supplied 156-person figure remains unverified.

CredentialsSupply chain / CI

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A phishing message impersonating an overseas firm preceded unauthorized Microsoft 365 access at a subcontractor.

    [s1]§§1,2,4
  • Reported fact

    Potential scope includes stakeholder and performer mail and attachments. The reviewed notice gives no person count; the supplied 156-person figure remains unverified.

    [s1]§§1,2,4

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Access was blocked the same day; subcontractor management and retention are being reviewed.

    [s1]§§1,2,4

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The notice does not state the credential-theft procedure, prior MFA state or affected-person count.

Sources

  1. [s1] 2025年日本国際博覧会協会 · Primary source

    2025年日本国際博覧会協会:事故に関する公表資料 ↗

    Reviewed 2026-10-09