← Incident database

tokyometro-metpo-mail-2026 · Disclosed 2026-09-27

東京メトロ: unauthorized access and impact

Unauthorized access to a mail-delivery server was confirmed; the cause remains under investigation. About 59,000 suppressed email addresses may have been viewed or retrieved; that server contained no other member information.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Unauthorized access to a mail-delivery server was confirmed; the cause remains under investigation.

    [s1]§§1-3
  • Reported fact

    About 59,000 suppressed email addresses may have been viewed or retrieved; that server contained no other member information.

    [s1]§§1-3

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The suspected path was secured and access records preserved for investigation.

    [s1]§§1-3

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The initial entry method and actually exfiltrated scope are undisclosed. Suppressed notification addresses are not all affected members.

Sources

  1. [s1] 東京メトロ · Primary source

    東京メトロ:事故に関する公表資料 ↗

    Reviewed 2026-10-09