Shueisha says a CMS flaw exposed 2,835 bloggers' details
The publisher says a privileged account created through an API credential mistake reached blogger profiles, 11,237 emails and a 10,780-entry supplier list at its HAPPY PLUS COMMUNITY system.

Shueisha has confirmed that a misconfigured content management system let an intruder reach stored data on 2,835 people who blog for its magazines, after the attacker created a privileged account and repeatedly called the platform's API.
In a notice dated 28 September, the Japanese publisher said the breach affected HAPPY PLUS COMMUNITY, the system it uses to manage and contact bloggers for titles including non-no, MORE, MAQUIA, LEE, SPUR, BAILA, Marisol and éclat. The exposed fields include names, email and postal addresses, telephone numbers, dates of birth, gender, occupation, profile photographs, profile text, social media accounts, follower counts, marital status, whether a blogger has children, height and skin type. Which fields exist depends on the magazine and on what the blogger or the editorial team entered.
What else was exposed
The blogger profiles are not the whole of it. Shueisha also lists 630 project records, covering blog commissions, photo shoots and event invitations, 11,237 emails sent from the system, and a supplier directory of 10,780 entries. The supplier records include every company name along with 26 email addresses and 113 telephone numbers; no personal names of contacts were stored, the company said.
Two visits, one afternoon
Shueisha places the unauthorised access in two windows on 9 September, between 00:45 and 01:25 and again between 13:42 and 16:46 Japan time. During the second window the intruder used the platform's own template to send three messages to 100 email addresses. A recipient reported those messages at 14:53 that afternoon, which is how the company learned it had been breached.
The cause and the clean-up
The company attributes the incident to a configuration flaw in the CMS that was used to reach API credentials. With those credentials the attacker created an unauthorised privileged account and made repeated API requests until the data was exposed. In response, Shueisha says it deleted the fraudulent account and changed the configuration, brought in the development vendor to investigate, wrote to the affected bloggers on 25 September and commissioned an external forensics review. It has filed a preliminary report with Japan's Personal Information Protection Commission and is preparing the final version.
Our opinion
The uncomfortable detail here is what actually detected the breach: not monitoring, not an alert, but three emails that a recipient found strange enough to report. An attacker with API credentials can read a database quietly, and it was only when he used the mailer that anyone noticed. The other lesson is narrower but worth repeating for publishers running legacy CMS installs: the credential that was abused sat behind a settings mistake rather than a clever exploit, and the data that followed included profile photographs, follower counts and family details that no blog commission ever needed to store.