← Incident database

ozmall-2026 · Disclosed 2026-09-27

OZmall: unauthorized access and impact

Abnormal access was detected and the responsible vulnerability addressed; its type is undisclosed. Potential scope is up to 442,779 people including former users, revised from 447,610.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Abnormal access was detected and the responsible vulnerability addressed; its type is undisclosed.

    [s1]第2報 §§1-4
  • Reported fact

    Potential scope is up to 442,779 people including former users, revised from 447,610.

    [s1]第2報 §§1-4

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The page was suspended and fixed, and unaffected servers also checked.

    [s1]第2報 §§1-4

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The vulnerability and prior patch timing are undisclosed. The revised number replaces the initial count rather than adding to it.

Sources

  1. [s1] OZmall · Primary source

    OZmall:事故に関する公表資料 ↗

    Reviewed 2026-10-09