← Incident database

fancrew-credential-stuffing-2026 · Disclosed 2026-08-24

ファンくる: unauthorized access and impact

Credential stuffing caused unauthorized logins; the original credential source is undisclosed. There were 5,060,270 attempts and 59,389 successfully accessed member accounts; unauthorized point redemption occurred in two accounts.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Credential stuffing caused unauthorized logins; the original credential source is undisclosed.

    [s1]9月18日最終報 §§1-3
  • Reported fact

    There were 5,060,270 attempts and 59,389 successfully accessed member accounts; unauthorized point redemption occurred in two accounts.

    [s1]9月18日最終報 §§1-3

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Affected passwords were invalidated; network defenses, identity checks and monitoring were strengthened.

    [s1]9月18日最終報 §§1-3

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.

Sources

  1. [s1] ファンくる · Primary source

    ファンくる:事故に関する公表資料 ↗

    Reviewed 2026-10-09