nishiyama-2026 · Disclosed 2026-02-13
Nishiyama: VPN vulnerability and account abuse
The company reported entry using a VPN vulnerability and account information, with encryption and leakage addressed by VPN removal and environment reinitialization.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
The company reported removing the VPN, credential resets, reinitialization, and backup changes.
[s1]再発防止策
Evidence relevant to prevention
Insufficient evidence
Undisclosed product and patch timing prevent a neglect finding. Inspect VPN deployment, credentials, and backups.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
VPN product, CVE, pre-attack patch availability, and credential origin are unknown.
Sources
[s1] 西山製作所 · Primary source
サイバー攻撃に関するお知らせ(第3報) ↗Published 2026-04-03 · Reviewed 2026-10-02