← Incident database

legoland-amadeus-2026 · Disclosed 2026-09-25

レゴランド・ジャパン: unauthorized access and impact

The outsourced Amadeus hotel-booking platform was accessed without authorization; its entry cause is undisclosed. Contact data from 1,557 bookings may be affected; payment, password, financial and passport access was not confirmed.

Supply chain / CICause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The outsourced Amadeus hotel-booking platform was accessed without authorization; its entry cause is undisclosed.

    [s1]本文
  • Reported fact

    Contact data from 1,557 bookings may be affected; payment, password, financial and passport access was not confirmed.

    [s1]本文

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Customers were warned about fraudulent messages citing reservation details and given official contact information.

    [s1]本文

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The reservation count is not a distinct-person count. The vendor’s initial entry route is undisclosed.

Sources

  1. [s1] レゴランド・ジャパン · Primary source

    レゴランド・ジャパン:事故に関する公表資料 ↗

    Reviewed 2026-10-09