Incidents on Oct 7, 2026

Publication date: Dates are source publication dates (JST), not occurrence dates.

Details and evidence links

Filter incidents

Showing 6 of 6 incidents

Incidents on Oct 7, 2026
DateTargetSummaryClassificationSource links
LEAK-134Charm "Charm Honten"B About 25,000 recordsCharm published its fourth report on third-party unauthorized access to its pet supplies store "Charm Honten". About 25,000 records of former customers are included; leakage has been confirmed for most of them, and the rest, which cannot be verified, are treated as possibly leaked. Personal information of people registered as delivery recipients on past orders is also included. No unauthorized logins to former customers' accounts have been confirmed.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-133CERES "Point Income"D 195 recordsOn the point site "Point Income", unauthorized access was detected intermittently from the early hours of October 5, 2026, and the company announced that personal information in some accounts may have been viewed by a third party. 195 records are affected: 88 for members and 107 for employees and related persons. Payment information such as credit card data is not stored on its servers and was not leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-135Hokkai-Gakuen UniversityA student's account was accessed by an unauthorized third party, and from September 10 to 12, 2026, phishing emails concerning five faculty members and related people who had previously exchanged emails with the account were sent. The university confirmed it on September 14, suspended the account, reset the password, blocked the source IP address, and reported to MEXT and the Personal Information Protection Commission. No secondary damage has been confirmed.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-136Toyama Prefectural UniversityOne student's Microsoft 365 account was accessed without authorization, and a total of 1,092 spam emails were sent to unspecified recipients between August 23 and 27, 2026. The university suspects the student's own PC was infected with malware and the ID and password were stolen. No unauthorized operations other than sending email, and no leak of confidential information, have been confirmed. From October 1, passkeys or multi-factor authentication became mandatory for all students' off-campus logins.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-137Eco Green HoldingsThe company's email account may have been misused by a third party, and on October 7, 2026, suspicious emails disguised as "accounts payable invoice (AP)" and "shipping documents" were confirmed to have been sent from addresses on its own domain (@eco-g.com). It changed the password, blocked access and is investigating the cause. Whether any information leaked has not been announced.
Unauthorized access & data leakPossibleOfficial statement
LEAK-160IDC Frontier "IDCF Cloud"From around 3:40 a.m. on October 7, 2026, virtual servers in part of East Japan Region 1 of the cloud service "IDCF Cloud" (four zones: tesla, henry, pascal and joule) stopped and could not be restarted, and IDC Frontier announced that the cause was a ransomware attack by a third party. 495 companies and local governments are affected. Customer data in the four zones is expected to be difficult to retrieve or restore, and the company says restoration is possible only from backups held by customers themselves. East Japan Region 1 was cut off from the network, and the intrusion route and scope are being investigated with an outside security firm. The company has not said whether any information leaked. It reported to the supervising ministries and the Tokyo Metropolitan Police Department.
RansomwareConfirmedOfficial statement
Incidents on Oct 7, 2026