jogmec-directory-2026 · Disclosed 2026-10-02
JOGMEC: unauthorized access and impact
Investigation found possible leakage through unauthorized system access on September 9. Potential scope covers about 1,100 staff and 7,400 external email addresses.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
Access and traffic controls were applied and authentication and monitoring strengthened.
[s1]§§1-5
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The initial entry mechanism and actual exfiltration scope are undisclosed; internal and external contact counts are separate.
Sources
[s1] JOGMEC · Primary source
JOGMEC:事故に関する公表資料 ↗Reviewed 2026-10-09