← Incident database

yellowhat-booking-2026 · Disclosed 2026-08-28

イエローハット: unauthorized access and impact

Malicious-program activity targeted the booking system; the entry mechanism is undisclosed. Potential exposure concerns up to 1,801,499 members; card information was not stored.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Malicious-program activity targeted the booking system; the entry mechanism is undisclosed.

    [s1]§§1-3
  • Reported fact

    Potential exposure concerns up to 1,801,499 members; card information was not stored.

    [s1]§§1-3

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    External connections were blocked and system countermeasures are reported complete.

    [s1]§§1-3

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The initial entry path and confirmed exfiltration scope are undisclosed. This is separate from the 2rinkan incident.

Sources

  1. [s1] イエローハット · Primary source

    イエローハット:事故に関する公表資料 ↗

    Reviewed 2026-10-09