← Incident database

kyoto-kyotv-exposure-2026 · Disclosed 2026-08-04

京都府 KYO育tv: data exposure and authorization boundaries

A favorites-feature defect exposed member data on the internet. Potential scope is up to 1,338 members; search results actually showed data for 86.

Implementation

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    A favorites-feature defect exposed member data on the internet.

    [s1]p.1 §§1-3
  • Reported fact

    Potential scope is up to 1,338 members; search results actually showed data for 86.

    [s1]p.1 §§1-3

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The feature was disabled, search-result removal requested, and all services subsequently suspended.

    [s1]p.1 §§1-3

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Potentially accessible profiles and the 86 profiles actually shown have separate scopes; actual disclosure is not universal.

Sources

  1. [s1] 京都府 KYO育tv · Primary source

    京都府 KYO育tv:事故に関する公表資料 ↗

    Reviewed 2026-10-09