DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Study Sapuri Confirms Account Enumeration Attack on 3,687 Email Addresses

Recruit confirmed that its Study Sapuri service let outsiders check whether email addresses were registered: up to 3,687 came back yes. I run AliasFleet, an email-alias service built on one address per site, so a confirmed answer reveals nothing about your real inbox. Nobody stole a database here. The service itself answered the wrong question, and that is the part of this story that matters.

What Recruit announced

The disclosure came on October 3 in Recruit's own notice, and the details, via ITmedia NEWS, read like this:

Detail What Recruit said
Who Recruit, operator of the online learning service Study Sapuri (スタディサプリ)
What Unauthorized access exploiting a system specification flaw
How many Up to 3,687 email addresses may have been confirmed as registered
In scope Registered users' email addresses for the elementary, middle, high school and university exam-prep courses
Discovered September 30, 2026; the flawed function was fixed the same day
Response Emergency security checks, strengthened monitoring, individual notices to affected users
Who else was told Schools and local governments using the service (Chiyoda Ward reportedly announced on October 5 that eight of its children and students were among those affected, per a roundup of the disclosures; part of the same case, not additional victims)

A weekly roundup of the disclosures notes that names, passwords and payment information were not confirmed as leaked; the announcement covers only the registration status of email addresses.

The quiet leak: why "is this address registered?" is enough

Account enumeration is one of the least dramatic attacks in the book, which is what makes it dangerous. Most login and signup flows are supposed to answer every request the same way, valid address or not, precisely so nobody can use them as an oracle. Study Sapuri's system answered differently for registered and unregistered addresses, and a third party worked through addresses until 3,687 came back confirmed.

Those 3,687 addresses are now the highest-value kind of target list. A phisher who knows an address is registered at a learning service can write to it as that service, reference the courses, and sound exactly like the real thing. This is not hypothetical: Study Sapuri's own notice says a phishing email with that exact playbook is already circulating, dressed up as a mail-service settings change.


Study Sapuri's own notice names a phishing email already in circulation, titled "Notice of studysapuri.jp mail service specification change and request to update settings", which pushes recipients toward a URL to change their settings and lists a support phone number. The company says any mail with that title is not from them. Delete it. The rule holds for anything similar: open the official site or the official app yourself, and never enter a password or authentication code from a link in a message.

Parents have an extra reason to pay attention here. Study Sapuri serves schoolchildren, and while Recruit contacted affected users directly, a family address shared across services is now a confirmed-live address in someone's list. The addresses may belong to parents who registered for their children. That is the part nobody patches with a password reset.

If you use Study Sapuri

Work from Recruit's notice first. If you received an individual contact, keep it; it is the only source that says your address was in the set. Then:

  1. Do not click links in any Study Sapuri or Recruit email you did not expect. Go to the official site or open the official app directly.
  2. Do not enter your password or an authentication code from a link in a message, ever. Recruit says it will not ask you to.
  3. If you reused your Study Sapuri password anywhere else, change it there now. Enumeration did not expose passwords, but confirmed-live addresses invite credential-stuffing attempts, and this week's warnings from Aeon Bank, U-NEXT and others say reuse is the habit attackers are counting on.
  4. Check whether your address is already circulating from another leak at Have I Been Pwned. A confirmed address that also appears in an older breach is the one a phisher personalises with.
  5. The breach-response guide walks through the rest in order.

What one alias per service changes

Enumeration attacks feed on one fact: the same address everywhere. When the address you gave Study Sapuri is your real inbox address, a "yes, registered" answer hands the attacker a verified contact point for you as a person, not just as a Study Sapuri user. From there it travels. The attacker can try it against every other service, and every reply from anywhere confirms the same identity.

Give Study Sapuri its own alias and the geometry flips. The attacker confirms an address that exists only for Study Sapuri, which tells them nothing about your real inbox and nothing about your other accounts. There is no other account behind it. The confirmation is fenced to the service it came from. And that service already knew.

The second payoff arrives later, when the phishing Recruit warned about starts. If the address Study Sapuri holds is a dedicated alias, then a "Study Sapuri security alert" arriving on the alias you created for your shopping account is fake by definition. No inspection needed: the address mismatch is the whole answer. This is leak attribution working from the other direction. Instead of the alias naming which company leaked it, the alias exposes which sender is lying about who they are. This is what an email alias is, and the setup guide takes about two minutes. The habit it builds, one alias per site, is the one that makes every future enumeration answer land on a fenced address.

What is still unknown

Recruit has not said how many addresses the attacker tested in total, only how many may have been confirmed. It is not clear whether the attacker probed addresses one by one or extracted them in bulk. No attacker has been named, no origin given. The company says it has confirmed no unauthorized logins to user accounts tied to this case and no secondary harm so far. The company's announcement does not say how the flaw was found, only that it was fixed the day the access was discovered. Recruit's own notices are the place to watch. Anything beyond the 3,687 addresses, the September 30 fix, and the settings-change lure already in circulation is still guesswork.

Top comments (0)