← Incident database

shueisha-hapicomi-2026 · Disclosed 2026-09-28

集英社: unauthorized access and impact

Shueisha attributes the incident to attacks on API credentials arising from CMS misconfiguration, privileged-account creation, and repeated API requests. Affected scopes include 2,835 bloggers, 630 projects, 11,237 sent emails, and 10,780 vendor entries.

Configuration / exposureCredentials

Outcome: Confirmed breach

Entry path and evidence

  • Assessment

    Shueisha attributes the incident to attacks on API credentials arising from CMS misconfiguration, privileged-account creation, and repeated API requests.

    [s1]p.1 §1 / p.2 §2-4
  • Reported fact

    Affected scopes include 2,835 bloggers, 630 projects, 11,237 sent emails, and 10,780 vendor entries.

    [s1]p.1 §1 / p.2 §2-4

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Unauthorized accounts were removed, settings changed, and external investigation and notifications undertaken.

    [s1]p.1 §1 / p.2 §2-4

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The cause is the organization's assessment; detailed configuration and independent validation are undisclosed.

Sources

  1. [s1] 集英社 · Primary source

    集英社:事故に関する公表資料 ↗

    Reviewed 2026-10-09