yellowhat-booking-2026 · Disclosed 2026-08-28
イエローハット: unauthorized access and impact
Malicious-program activity targeted the booking system; the entry mechanism is undisclosed. Potential exposure concerns up to 1,801,499 members; card information was not stored.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
External connections were blocked and system countermeasures are reported complete.
[s1]§§1-3
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The initial entry path and confirmed exfiltration scope are undisclosed. This is separate from the 2rinkan incident.
Sources
[s1] イエローハット · Primary source
イエローハット:事故に関する公表資料 ↗Reviewed 2026-10-09