← Incident database

innovation-github-2026 · Disclosed 2026-08-04

イノベーション: unauthorized access and impact

A GitHub access token was embedded in a configuration file, acquired and abused by a third party. The August 7 final notice confirms leakage for 62,691 people; personal data stored in repositories was a separate contributing factor. No production-database intrusion was found.

CredentialsConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A GitHub access token was embedded in a configuration file, acquired and abused by a third party.

    [s1]確定報 §§1-4
  • Reported fact

    The August 7 final notice confirms leakage for 62,691 people; personal data stored in repositories was a separate contributing factor. No production-database intrusion was found.

    [s1]確定報 §§1-4

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The token was revoked, permissions and issuance governed, and personal-data audits and detection implemented.

    [s1]確定報 §§1-4

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Hardcoded repository secrets and stored personal data are reported. The precise account-entry route remains undisclosed.

Sources

  1. [s1] イノベーション · Primary source

    イノベーション:事故に関する公表資料 ↗

    Reviewed 2026-10-09