jst-mail-2026 · Disclosed 2026-08-07
科学技術振興機構: unauthorized access and impact
Unauthorized access affected 12 staff mailboxes; the entry route is undisclosed. The August 28 review revised affected mail to about 18,000 records; about 1,400 external addresses are a subset, replacing the supplied 16,000 figure.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
The abused route was blocked and access permissions revoked.
[s1]§§1-3
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
Email messages and unique contact addresses are different units; the follow-up message total supersedes the initial estimate.
Sources
[s1] 科学技術振興機構 · Primary source
科学技術振興機構:事故に関する公表資料 ↗Reviewed 2026-10-09