← Incident database

istyle-transfer-exposure-2026 · Disclosed 2026-09-16

アイスタイル: data exposure and authorization boundaries

A sharing-setting error made an internal-transfer file accessible to anyone knowing its URL. Email addresses and associated data for 10,997 users were exposed for 20 minutes; names and passwords were excluded.

Configuration / exposure

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    A sharing-setting error made an internal-transfer file accessible to anyone knowing its URL.

    [s1]§§1-4
  • Reported fact

    Email addresses and associated data for 10,997 users were exposed for 20 minutes; names and passwords were excluded.

    [s1]§§1-4

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The file was deleted after 20 minutes; automated handling and revised procedures are being considered.

    [s1]§§1-4

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The undisclosed details must remain unknown.

Sources

  1. [s1] アイスタイル · Primary source

    アイスタイル:事故に関する公表資料 ↗

    Reviewed 2026-10-09