← Incident database

nimoca-2026 · Disclosed 2026-10-06

nimoca: unauthorized access to the public usage-history service

nimoca reported leakage of 521 records through unauthorized service access. Unexpected emails were generated automatically by the service.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Unauthorized public-service access was confirmed. The service, not the attacker, sent the emails.

    [s1]p.1 §2
  • Reported fact

    Affected data comprises 521 records with card numbers, birth dates, and email addresses; name and usage-history leakage is unconfirmed.

    [s1]p.1 §3 / p.2 §4

Timeline

  1. Access occurred around midnight–17:40. A customer report around 09:00 prompted investigation; the service stopped at 17:40. [s1]

  2. Impact and response disclosed. [s1]

Reported response

  • Reported fact

    The usage-history service was stopped; cause and scope remain under investigation.

    [s1]p.1 冒頭 / p.2 §6

Evidence relevant to prevention

Insufficient evidence

Inspect lookup authorization, input-driven recipients, retrieval limits, and logs.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The specific mechanism is undisclosed; SQL injection and authorization defects are unestablished.

Sources

  1. [s1] ニモカ · Primary source

    nimoca利用履歴照会サービスへの不正アクセスによる情報漏えい ↗

    Published 2026-10-06 · Reviewed 2026-10-09