← Incident database

takaratomy-dmp-auth-2026 · Disclosed 2026-07-28

タカラトミー: data exposure and authorization boundaries

The app had a user-authentication design and implementation defect from release. Potential scope is up to approximately 155,000 registered users; third-party access or misuse was not confirmed.

Implementation

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    The app had a user-authentication design and implementation defect from release.

    [s1]pp.1-2 本文 / §§1-2
  • Reported fact

    Potential scope is up to approximately 155,000 registered users; third-party access or misuse was not confirmed.

    [s1]pp.1-2 本文 / §§1-2

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The defect was fixed by July 13 and security review is being strengthened.

    [s1]pp.1-2 本文 / §§1-2

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Potentially accessible accounts are not confirmed accessed accounts. The implementation defect does not establish a library vulnerability.

Sources

  1. [s1] タカラトミー · Primary source

    タカラトミー:事故に関する公表資料 ↗

    Reviewed 2026-10-09