kindal-phishing-2026 · Disclosed 2026-08-28
カインドオル: unauthorized access and impact
An employee entered staff credentials into a phishing site; the account lacked two-step authentication. Two bulk exports occurred on August 23, affecting 136,464 customers.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
The compromised account was deleted and two-step authentication required for all staff.
[s1]§§1-4,6
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
Phishing, weak passwords and absent MFA are reported; the exact original compromise date and extraction completeness are undisclosed.
Sources
[s1] カインドオル · Primary source
カインドオル:事故に関する公表資料 ↗Reviewed 2026-10-09