Skip to article
← Tech Blog

Tech Blog · Cybersecurity

Noah's Ark · Analysis of public disclosures · English summary

Protecting credentials and permissions: security incidents in Japan (English summary)

The disclosures from Asahi Group Holdings, ASKUL and CAMPFIRE describe different paths into company systems. ASKUL confirmed misuse of an administrator account exempt from MFA. CAMPFIRE traced misuse of a GitHub credential to a personal development server. Asahi believes password weaknesses were used to gain administrator privileges.

Read the full analysis in Japanese →
Published
Information as of

Methodology and scope

This English summary accompanies the full Japanese article. It draws on company disclosures and GitHub, CISA and NIST guidance reviewed as of October 7, 2026. Incident and disclosure dates, confirmed leaks and possible exposure, and company findings and our recommendations are kept separate.

English summary

English summary

Some details remain unresolved. ASKUL could not establish how the credentials leaked. CAMPFIRE confirmed a query output containing personal information, but found no traces of external file transfer; missing logs leave possible viewing unresolved. Asahi distinguishes confirmed leaks from employee devices from possible exposure of personal information on servers. The cited material does not establish attacker use of AI.[2][3][5][8]

For a practical review, start with what a compromised identity can reach: other systems, privileged operations, data and backups. Check MFA exceptions, limit machine credentials and their permissions, protect audit logs with separate administration, revoke active sessions and test restoration in isolation. For AI agents, check authorization outside the model and match approved actions to the operations actually executed.[9][10][11]

Limitations

This article reviews public material available as of October 7, 2026. Noah's Ark did not conduct the named companies' forensic investigations or assessments and reports no original vulnerability discovery. Gateway is under development. The measures discussed here are design proposals, with no claim of deployment at these companies or validated protection.

Primary sources

  1. アサヒグループホールディングス — サイバー攻撃によるシステム障害発生について

    Publication date: · Accessed:

    https://www.asahigroup-holdings.com/newsroom/detail/20250929-0102.html
  2. アサヒグループホールディングス — サイバー攻撃被害の再発防止策とガバナンス体制の強化について

    Publication date: · Accessed:

    https://www.asahigroup-holdings.com/en/newsroom/detail/20260218-0101.html
  3. アサヒグループホールディングス — サイバー攻撃に係る漏えいのおそれがある個人情報について

    Publication date: · Accessed:

    https://www.asahigroup-holdings.com/en/newsroom/detail/20260717-0101.html
  4. アスクル — ランサムウェア感染によるシステム障害発生のお知らせとお詫び(第1報)

    Publication date: · Accessed:

    https://www.askullogist.co.jp/pdf/20251020.pdf
  5. アスクル — ランサムウェア攻撃の影響調査結果および安全性強化に向けた取り組みのご報告(第13報)

    Publication date: · Accessed:

    https://pdf.irpocket.com/C0032/PDLX/O3bg/N4O3.pdf
  6. アスクル — ランサムウェア攻撃に伴う情報漏えいのおそれに関する本人通知の追加実施について(第19報)

    Publication date: · Accessed:

    https://www.askullogist.co.jp/pdf/20260730.pdf
  7. CAMPFIRE — GitHubアカウントへの不正アクセス発生に関するお知らせとお詫び

    Publication date: · Accessed:

    https://campfire.co.jp/press/2026/04/03/campfire/
  8. CAMPFIRE — 不正アクセス事案にかかる調査結果について

    Publication date: · Accessed:

    https://campfire.co.jp/press/2026/06/02/campfire/
  9. GitHub — OpenID Connect

    Accessed:

    https://docs.github.com/en/actions/concepts/security/openid-connect
  10. CISA — #StopRansomware Guide

    Accessed:

    https://www.cisa.gov/stopransomware/ransomware-guide
  11. NIST — SP 800-207: Zero Trust Architecture

    Accessed:

    https://csrc.nist.gov/pubs/sp/800/207/final