trunk-mail-2026 · Disclosed 2026-09-01
TRUNK: unauthorized access and impact
Employee email was compromised and used for impersonation messages; the authentication bypass mechanism is undisclosed. Potentially exposed personal data totals 424 records.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
Passwords were changed, suspicious mail stopped and affected people notified.
[s1]§§1-3
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The initial entry mechanism and actual exfiltration scope are undisclosed.
Sources
[s1] TRUNK · Primary source
TRUNK:事故に関する公表資料 ↗Reviewed 2026-10-09