← Incident database

inkrevolution-payment-2025 · Disclosed 2025-12-18

インク革命: unauthorized access and impact

A system vulnerability was exploited to alter the payment application; product and CVE are undisclosed. Personal and card data for 24,166 customers may have been disclosed; the two categories are not additive.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A system vulnerability was exploited to alter the payment application; product and CVE are undisclosed.

    [s1]§§1-2,5
  • Reported fact

    Personal and card data for 24,166 customers may have been disclosed; the two categories are not additive.

    [s1]§§1-2,5

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Card payments were stopped; the backdoor was removed and alterations fixed. External investigators verified completion and no new compromise.

    [s1][s2]§§1-2,5

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Prior patch availability and the exact initial entry mechanism are undisclosed. The same 24,166 customers appear in both personal-data and card-data categories.

Sources

  1. [s1] インク革命 · Primary source

    インク革命:事故に関する公表資料 ↗

    Reviewed 2026-10-09

  2. [s2] インク革命 · Primary source

    インク革命:事故に関する公表資料 ↗

    Reviewed 2026-10-09