istyle-transfer-exposure-2026 · Disclosed 2026-09-16
アイスタイル: data exposure and authorization boundaries
A sharing-setting error made an internal-transfer file accessible to anyone knowing its URL. Email addresses and associated data for 10,997 users were exposed for 20 minutes; names and passwords were excluded.
Outcome: Exposure / potential leak. Third-party theft unconfirmed.
Entry path and evidence
Timeline
Reported response
- Reported fact
The file was deleted after 20 minutes; automated handling and revised procedures are being considered.
[s1]§§1-4
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The undisclosed details must remain unknown.
Sources
[s1] アイスタイル · Primary source
アイスタイル:事故に関する公表資料 ↗Reviewed 2026-10-09