← Incident database

kodansha-phishing-2026 · Disclosed 2026-08-03

講談社: unauthorized access and impact

An employee entered credentials on a phishing site impersonating a business partner, enabling unauthorized mailbox login. Up to 3,812 contacts were stolen and 553 addresses received impersonation messages.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    An employee entered credentials on a phishing site impersonating a business partner, enabling unauthorized mailbox login.

    [s1]pp.1-2 本件の経緯 / 弊社の対応
  • Reported fact

    Up to 3,812 contacts were stolen and 553 addresses received impersonation messages.

    [s1]pp.1-2 本件の経緯 / 弊社の対応

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The password was changed and sessions removed; no further unauthorized access was observed.

    [s1]pp.1-2 本件の経緯 / 弊社の対応

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The notice does not establish prior MFA coverage or a more detailed credential-theft mechanism.

Sources

  1. [s1] 講談社 · Primary source

    講談社:事故に関する公表資料 ↗

    Reviewed 2026-10-09