kodansha-phishing-2026 · Disclosed 2026-08-03
講談社: unauthorized access and impact
An employee entered credentials on a phishing site impersonating a business partner, enabling unauthorized mailbox login. Up to 3,812 contacts were stolen and 553 addresses received impersonation messages.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
The password was changed and sessions removed; no further unauthorized access was observed.
[s1]pp.1-2 本件の経緯 / 弊社の対応
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The notice does not establish prior MFA coverage or a more detailed credential-theft mechanism.
Sources
[s1] 講談社 · Primary source
講談社:事故に関する公表資料 ↗Reviewed 2026-10-09