← Incident database

nichii-backup-exposure-2026 · Disclosed 2026-10-02

ニチイ学館: data exposure and authorization boundaries

A retained backup was downloadable without authentication from May 11, 2020 to September 11, 2026. Of 2,674 inquiry entries, 583 people had personal data and 99 had sensitive data. Structured customer fields were reportedly encrypted and inaccessible.

Configuration / exposure

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    A retained backup was downloadable without authentication from May 11, 2020 to September 11, 2026.

    [s1]p.1 §1 / p.2 §1(2)-(4), §2-3
  • Reported fact

    Of 2,674 inquiry entries, 583 people had personal data and 99 had sensitive data. Structured customer fields were reportedly encrypted and inaccessible.

    [s1]p.1 §1 / p.2 §1(2)-(4), §2-3

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The file was deleted and the retained three months of logs reviewed.

    [s1]p.1 §1 / p.2 §1(2)-(4), §2-3

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

No third-party access was found in the retained three months; missing earlier logs prevent excluding access throughout the full period.

Sources

  1. [s1] ニチイ学館 · Primary source

    ニチイ学館:事故に関する公表資料 ↗

    Reviewed 2026-10-09