← Incident database

weblife-oem-2026 · Disclosed 2026-08-18

ウェブライフ: unauthorized access and impact

A customer-management access-control defect enabled unauthorized activity from August 14 to 17. Up to 7,425 people were affected; the August 28 update ruled out exposure of names, addresses, phone numbers and other fields, while email exposure remains possible.

Implementation

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A customer-management access-control defect enabled unauthorized activity from August 14 to 17.

    [s1]初報 §§1-4 / 続報 §§2-4
  • Reported fact

    Up to 7,425 people were affected; the August 28 update ruled out exposure of names, addresses, phone numbers and other fields, while email exposure remains possible.

    [s1]初報 §§1-4 / 続報 §§2-4

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Access controls were fixed and the same retrieval path verified blocked.

    [s1]初報 §§1-4 / 続報 §§2-4

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The exact implementation defect and confirmed email extraction scope are undisclosed.

Sources

  1. [s1] ウェブライフ · Primary source

    ウェブライフ:事故に関する公表資料 ↗

    Reviewed 2026-10-09