inkrevolution-payment-2025 · Disclosed 2025-12-18
インク革命: unauthorized access and impact
A system vulnerability was exploited to alter the payment application; product and CVE are undisclosed. Personal and card data for 24,166 customers may have been disclosed; the two categories are not additive.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Card payments were stopped; the backdoor was removed and alterations fixed. External investigators verified completion and no new compromise.
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
Prior patch availability and the exact initial entry mechanism are undisclosed. The same 24,166 customers appear in both personal-data and card-data categories.
Sources
[s1] インク革命 · Primary source
インク革命:事故に関する公表資料 ↗Reviewed 2026-10-09
[s2] インク革命 · Primary source
インク革命:事故に関する公表資料 ↗Reviewed 2026-10-09