← Incident database

mrmax-2026 · Disclosed 2026-10-06

MrMax: software-function abuse leads to member-data leakage

MrMax confirmed server intrusion and some member-data leakage. The maximum potential scope is 1,735,154 people; the confirmed leaked-person count is unspecified.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The intruder abused functions of software composing the service.

    [s1]1. 経緯
  • Reported fact

    Potential scope is up to 1,735,154 people. MrMax confirmed addresses, birth dates, cards, passwords, and purchase histories were not leaked.

    [s1]2. 情報流出の可能性がある対象のお客様および情報

Timeline

  1. Suspicious access was detected; services and external access were stopped. [s1]

  2. Impact and response disclosed. [s1]

Reported response

  • Reported fact

    MrMax blocked the path, strengthened monitoring, and engaged external investigators.

    [s1]4. 今後の対応

Evidence relevant to prevention

Insufficient evidence

Compare deployed software with advisories and inspect exposure, permissions, and access logs.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Product, CVE, and patch timing are undisclosed; patch neglect and implementation defects are unestablished.

Sources

  1. [s1] ミスターマックス · Primary source

    不正アクセスによる情報流出に関するお詫びとお知らせ ↗

    Published 2026-10-06 · Reviewed 2026-10-09