← Commune Inc.

2026 Commune Inc. — invite-link abuse + admin impersonation; ~307k members

2026 307.0K records affected Share on X

Data compromised

Per Commune Oct 9 notice: ~307,000 members (estimate). ~126,000 with email (~42,000 of those Commune employees/demo accounts); ~181,000 without email (display name, self-intro, private-group membership, etc.). 144 members had passwords force-changed to temp passwords (temps expired; no evidence attacker received them). Passwords themselves and DMs not confirmed leaked; company holds no card data. Commune CRM/Engage: access attempted, no leak; Voice/Navigator/DataHub: no unauthorized access found.

Technical writeup

Verified Commune Inc. notice (9 Oct 2026). Unauthorized access from ~18:00 JST 5 Oct through ~21:00 6 Oct, plus residual path 13:17–14:36 on 7 Oct during maintenance. Full community stop ~21:00 6 Oct; phased reopen from ~12:00 8 Oct. Root cause: invite-link abuse + admin impersonation. ~307k members estimated after de-dupe. No confirmed misuse at disclosure. MIC telecom report; customers supported for PPC filings. companyConfirmed true; recordsAffected 307000.

Root cause

Attacker improperly obtained private-community invite links, registered as members, then impersonated admins to view/exfil member data and overwrite data (system flaw, not customer misconfiguration)

References