SHINDO3

@cosme

cosme.net

Members10,997people

POSSIBLE LEAKEmail address / Member / user IDMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Sep 16, 2026
Detected
Sep 2, 2026
Detection to disclosure
14 days
Leak
Leak possible
Type
Misconfiguration
Status
Closed (final report)
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
1010401057595

What leaked

ContactEmail address
Account dataNewsletter setting (opted in or out), User ID issued at registration

How many

  • Members 10,997 people

Who is affected

  • Members

Cause

When an external file transfer service was used to hand over a file internally, its sharing scope was set inappropriately, so anyone who knew the download URL could view it (for about 20 minutes, 2026-09-02 14:20 to 14:40)

Timeline

  1. Detected
  2. Data as of
  3. Exposure began
  4. Exposure ended
  5. First disclosure

Response

  • Data deleted

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources