ozmall-2026 · Disclosed 2026-09-27
OZmall: unauthorized access and impact
Abnormal access was detected and the responsible vulnerability addressed; its type is undisclosed. Potential scope is up to 442,779 people including former users, revised from 447,610.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
The page was suspended and fixed, and unaffected servers also checked.
[s1]第2報 §§1-4
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The vulnerability and prior patch timing are undisclosed. The revised number replaces the initial count rather than adding to it.
Sources
[s1] OZmall · Primary source
OZmall:事故に関する公表資料 ↗Reviewed 2026-10-09