← Incident database

pickleballone-plugin-2026 · Disclosed 2026-06-30

ピックルボールワン: unauthorized access and impact

An external plugin vulnerability was exploited to install malicious server programs. Up to about 1,853 members may be affected; extraction traces were not found and card data was not stored.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    An external plugin vulnerability was exploited to install malicious server programs.

    [s1]§§1-4
  • Reported fact

    Up to about 1,853 members may be affected; extraction traces were not found and card data was not stored.

    [s1]§§1-4

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Access was blocked, programs removed, credentials reset and the vulnerability fixed; administrator two-factor authentication and monitoring are being implemented.

    [s1]§§1-4

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The plugin vulnerability and prior fix availability are undisclosed. The provider found no extraction evidence and did not hold payment-card data.

Sources

  1. [s1] ピックルボールワン · Primary source

    ピックルボールワン:事故に関する公表資料 ↗

    Reviewed 2026-10-09