← Incident database

kindal-phishing-2026 · Disclosed 2026-08-28

カインドオル: unauthorized access and impact

An employee entered staff credentials into a phishing site; the account lacked two-step authentication. Two bulk exports occurred on August 23, affecting 136,464 customers.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    An employee entered staff credentials into a phishing site; the account lacked two-step authentication.

    [s1]§§1-4,6
  • Reported fact

    Two bulk exports occurred on August 23, affecting 136,464 customers.

    [s1]§§1-4,6

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The compromised account was deleted and two-step authentication required for all staff.

    [s1]§§1-4,6

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Phishing, weak passwords and absent MFA are reported; the exact original compromise date and extraction completeness are undisclosed.

Sources

  1. [s1] カインドオル · Primary source

    カインドオル:事故に関する公表資料 ↗

    Reviewed 2026-10-09