SHINDO2

mogily

mogily.me

Personal data133people

NO LEAK FOUNDUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 11, 2026
Leak
No leak
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced
Corporate number
9011103010629

Not leaked

  • No personal information (names, contact details, etc.) was leaked at all

How many

  • Customers whose winning status was changed to lost 133 people
  • Client companies affected 1 organizations
  • Personal data leaked (none) 0 records

Who is affected

  • Lottery winners

Cause

An outside attacker broke into the management platform of the digital queue-ticket system and changed winning statuses to losing ones. The entry point was a vulnerability, which has been fixed

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. First disclosure
  4. Client Tsuburaya Productions (ULTRA MART) announced it; said lotteries from September 19 would be paused
  5. Service restored
  6. ULTRA MART announced lottery sales would reopen with new rules

Response

  • Patched
  • More monitoring

Restored the winning statuses, fixed the vulnerability used as the entry point and applied security hardening, strengthened monitoring for unauthorized access and log management

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources