← Incident database

trunk-mail-2026 · Disclosed 2026-09-01

TRUNK: unauthorized access and impact

Employee email was compromised and used for impersonation messages; the authentication bypass mechanism is undisclosed. Potentially exposed personal data totals 424 records.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Employee email was compromised and used for impersonation messages; the authentication bypass mechanism is undisclosed.

    [s1]§§1-3
  • Reported fact

    Potentially exposed personal data totals 424 records.

    [s1]§§1-3

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Passwords were changed, suspicious mail stopped and affected people notified.

    [s1]§§1-3

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The initial entry mechanism and actual exfiltration scope are undisclosed.

Sources

  1. [s1] TRUNK · Primary source

    TRUNK:事故に関する公表資料 ↗

    Reviewed 2026-10-09