← Incident database

studysapuri-enumeration-2026 · Disclosed 2026-10-03

スタディサプリ: unauthorized access and impact

A feature-specification defect may have enabled identification of registered email addresses. 3,687 is the count of addresses whose membership may have been identified; user-account compromise was not confirmed.

Implementation

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A feature-specification defect may have enabled identification of registered email addresses.

    [s1]#ssntc_303 原因 / 影響範囲 / 当社の対応
  • Reported fact

    3,687 is the count of addresses whose membership may have been identified; user-account compromise was not confirmed.

    [s1]#ssntc_303 原因 / 影響範囲 / 当社の対応

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The feature was corrected on September 30 to prevent the same enumeration.

    [s1]#ssntc_303 原因 / 影響範囲 / 当社の対応

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Affected email addresses are not a count of compromised logins. Vulnerability identifiers and prior remediation timing are undisclosed.

Sources

  1. [s1] スタディサプリ · Primary source

    スタディサプリ:事故に関する公表資料 ↗

    Reviewed 2026-10-09