← Incident database

tixplus-cache-exposure-2026 · Disclosed 2026-10-01

チケットプラス: data exposure and authorization boundaries

A cache change intended to reduce load caused cross-user information display during concurrent access. Up to 107 data owners and 322 viewers are separate scopes. Their sum is not a confirmed leaked-person count.

Configuration / exposure

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    A cache change intended to reduce load caused cross-user information display during concurrent access.

    [s1]1. 発生経緯 / 4. 影響を受けた可能性のあるお客様
  • Reported fact

    Up to 107 data owners and 322 viewers are separate scopes. Their sum is not a confirmed leaked-person count.

    [s1]1. 発生経緯 / 4. 影響を受けた可能性のあるお客様

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The service was suspended, configuration corrected, and service resumed on September 30.

    [s1]1. 発生経緯 / 4. 影響を受けた可能性のあるお客様

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Overlap and the actual count displayed to other people are undisclosed.

Sources

  1. [s1] チケットプラス · Primary source

    チケットプラス:事故に関する公表資料 ↗

    Reviewed 2026-10-09