← Incident database

nishiyama-2026 · Disclosed 2026-02-13

Nishiyama: VPN vulnerability and account abuse

The company reported entry using a VPN vulnerability and account information, with encryption and leakage addressed by VPN removal and environment reinitialization.

Cause unresolved / undisclosedCredentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The company reported abuse of a VPN vulnerability and specific account information.

    [s1]調査結果
  • Reported fact

    Some data could not be restored; monitoring for leaked information continued.

    [s1]復旧状況 / 情報流出

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    The company reported removing the VPN, credential resets, reinitialization, and backup changes.

    [s1]再発防止策

Evidence relevant to prevention

Insufficient evidence

Undisclosed product and patch timing prevent a neglect finding. Inspect VPN deployment, credentials, and backups.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

VPN product, CVE, pre-attack patch availability, and credential origin are unknown.

Sources

  1. [s1] 西山製作所 · Primary source

    サイバー攻撃に関するお知らせ(第3報) ↗

    Published 2026-04-03 · Reviewed 2026-10-02