pickleballone-plugin-2026 · Disclosed 2026-06-30
ピックルボールワン: unauthorized access and impact
An external plugin vulnerability was exploited to install malicious server programs. Up to about 1,853 members may be affected; extraction traces were not found and card data was not stored.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Access was blocked, programs removed, credentials reset and the vulnerability fixed; administrator two-factor authentication and monitoring are being implemented.
[s1]§§1-4
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The plugin vulnerability and prior fix availability are undisclosed. The provider found no extraction evidence and did not hold payment-card data.
Sources
[s1] ピックルボールワン · Primary source
ピックルボールワン:事故に関する公表資料 ↗Reviewed 2026-10-09