← Incident database

fukuoka-editable-application-2026 · Disclosed 2026-09-29

福岡県: data exposure and authorization boundaries

An application file was published with editing and saving enabled instead of read-only access, retaining applicants’ information. Information about 183 officers from 24 organizations was accessible; actual view counts are unknown.

Configuration / exposure

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    An application file was published with editing and saving enabled instead of read-only access, retaining applicants’ information.

    [s1]§§1-5
  • Reported fact

    Information about 183 officers from 24 organizations was accessible; actual view counts are unknown.

    [s1]§§1-5

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The file was removed and organizations notified; multi-person permission checks before publication are planned.

    [s1]§§1-5

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.

Sources

  1. [s1] 福岡県 · Primary source

    福岡県:事故に関する公表資料 ↗

    Reviewed 2026-10-09