nichii-backup-exposure-2026 · Disclosed 2026-10-02
ニチイ学館: data exposure and authorization boundaries
A retained backup was downloadable without authentication from May 11, 2020 to September 11, 2026. Of 2,674 inquiry entries, 583 people had personal data and 99 had sensitive data. Structured customer fields were reportedly encrypted and inaccessible.
Outcome: Exposure / potential leak. Third-party theft unconfirmed.
Entry path and evidence
- Reported fact
A retained backup was downloadable without authentication from May 11, 2020 to September 11, 2026.
[s1]p.1 §1 / p.2 §1(2)-(4), §2-3 - Reported fact
Of 2,674 inquiry entries, 583 people had personal data and 99 had sensitive data. Structured customer fields were reportedly encrypted and inaccessible.
[s1]p.1 §1 / p.2 §1(2)-(4), §2-3
Timeline
Reported response
- Reported fact
The file was deleted and the retained three months of logs reviewed.
[s1]p.1 §1 / p.2 §1(2)-(4), §2-3
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
No third-party access was found in the retained three months; missing earlier logs prevent excluding access throughout the full period.
Sources
[s1] ニチイ学館 · Primary source
ニチイ学館:事故に関する公表資料 ↗Reviewed 2026-10-09