legoland-amadeus-2026 · Disclosed 2026-09-25
レゴランド・ジャパン: unauthorized access and impact
The outsourced Amadeus hotel-booking platform was accessed without authorization; its entry cause is undisclosed. Contact data from 1,557 bookings may be affected; payment, password, financial and passport access was not confirmed.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
Customers were warned about fraudulent messages citing reservation details and given official contact information.
[s1]本文
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The reservation count is not a distinct-person count. The vendor’s initial entry route is undisclosed.
Sources
[s1] レゴランド・ジャパン · Primary source
レゴランド・ジャパン:事故に関する公表資料 ↗Reviewed 2026-10-09