fancrew-credential-stuffing-2026 · Disclosed 2026-08-24
ファンくる: unauthorized access and impact
Credential stuffing caused unauthorized logins; the original credential source is undisclosed. There were 5,060,270 attempts and 59,389 successfully accessed member accounts; unauthorized point redemption occurred in two accounts.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Affected passwords were invalidated; network defenses, identity checks and monitoring were strengthened.
[s1]9月18日最終報 §§1-3
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.
Sources
[s1] ファンくる · Primary source
ファンくる:事故に関する公表資料 ↗Reviewed 2026-10-09