>>79144998Background of the leak
Since the viewing/editing range of Google form's editing URL was set to "Everyone on the Internet who knows this link can view it," anyone who knows the editing URL link can , it was possible to access the editing URL and view the above personal information.
However, the URL posted on the audition application form (URL for responses) and the URL where you can check the answer content (URL for editing) are different, and the URL posted on the audition page is for responses. Because it was a URL, the URL where personal information could be viewed was not publicly available on the audition page.
Judging from this incident, there are three possibilities for accessing the editing URL, which are currently under investigation.
It is possible that a request for editing permission was received from a third party to the administrator regarding the editing URL, and the request was granted for some reason.
However, when we checked on 2024/6/25 17:15, we did not find any incidents where editing privileges were granted to specific users outside our group. Therefore, this possibility is considered low.
There is a possibility that for some reason, the editing URL was leaked from within our group to a third party, and the information leakage of the editing URL from that third party has expanded.
The editing URL may have been leaked due to unauthorized access.
Furthermore, after this incident was discovered, we implemented restrictions on access to files on the cloud service at 17:50 on 2024/06/25, and the situation in which third parties could access the editing URL has been resolved.
Furthermore, at this time, we have not confirmed any damage caused by unauthorized use.
How this case came to light
After reconfirming the contents of the inquiry within the company, two people who noticed the above event contacted Buspo! on 2024/6/18 11:23 and 2024/6/25 16:28. We received an inquiry in the request section of Official X's DM.
However, since the inquiry was made in the request section of the DM, there was a delay in confirmation within our group, and the X post by one person who made the inquiry on 2024/6/25 17:01 has become a hot topic. This was discovered on June 25, 2024 at 17:15, and this incident, including the existence of the two inquiries above, was revealed within our group.