HomeSecurityJapan: Sharp rise in internet data leaks

Japan: Sharp rise in internet data leaks

Attackers behind a series of personal data breaches at organizations in Japan have been abusing mobile app APIs and targeting known software flaws, according to the JPCERT (JPCERT/CC). The Tokyo-based center issued an alert on Oct. 8, 2026, based on incident reports and other information. The alert does not name the attackers or affected organizations.

See also: Dark web leaks: How companies monitor and deal with data leaks

Article image: Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks Japan
Japan: Sharp rise in internet data leaks

JPCERT/CC described its knowledge as “limited and fragmentary,” noting that the same method may not have been used in every incident.

The systems affected include consumer applications, business intelligence (BI) tools, and employee management systems that were not expected to be publicly accessible. In some cases, data stored on these systems was leaked. For defenders, the warning includes eight source IP addresses, five User-Agent strings, and a list of API checks, including access checks on each endpoint.

The only product specifically targeted is Metabase, a BI tool with a known flaw that attackers have exploited. Metabase has urged users to upgrade to at least the minimum secure versions, which are newer than the initial fix for this flaw. The breaches have occurred sequentially around September 2026. These attacks are separate from ransomware and other common incidents, leading to significant data breaches, and may be increasing, according to JPCERT/CC.

JPCERT/CC did not provide a specific number of incidents. However, the Security Research Center of Japanese company Macnica reported 119 incidents made public this year through Oct. 6 where personal data was stolen or leaked through online systems operated by organizations in Japan. This is an increase from 84 incidents in 2025 and 62 in 2024, with 81 of this year’s incidents occurring since July.

See also: Curiosity: Impressive panoramic image of Mount Sharp on Mars

data leaks - SecNews.gr
Japan: Sharp rise in internet data leaks

The number only includes incidents that Macnica deemed similar to the current series and excludes ransomware and cases linked to other attack groups. Of the 81 incidents made public since July, 65 did not have sufficient detail to determine how the attackers gained access. Targets range from online stores to membership services, business systems and customer support. Recent cases include a library catalog search and a tourist train seat reservation system.

Two notable cases illustrate the scale of the leaks. Park24 reported on September 28 that a third party had obtained data for about 6.6 million accounts from car-sharing service Times Car. The following day, it revealed that identification documents, including images of driver’s licenses, had been leaked from about 1.6 million accounts. Monogatari Corporation, which operates the Yakiniku King, said that 10,788,963 records were leaked from the Yakiniku King app’s membership system, INTERNET Watch reported on October 5.

Both companies said the cause of the leaks was still under investigation. Macnica also identified 99 similar cases in 13 other countries and regions, mostly from July to September, including 30 in South Korea, 11 in France and 8 in Poland. It remains unclear whether Japan is the only target, as disclosure laws and practices vary by country.

The JPCERT/CC warning describes three patterns for how attackers gain access. The first involves unauthorized requests to the management APIs behind an application, with some requests capable of rewriting information.

See also: Sharp Healthcare: Looking at using Apple Vision Pro for patient care

Microsoft 365 Family Copilot AI family sharing
Japan: Sharp rise in internet data leaks

JPCERT/CC has received multiple reports describing three methods used by attackers:

  • 1. Analysis of publicly released smartphone applications to discover API endpoints and keys.
  • 2. Attacking internal APIs that are not accessible through the application's user interface. Reported actions include changing user privileges, creating unauthorized accounts, and exploiting server responses to modify headers or identifiers.
  • 3. Using API keys stolen from compromised systems. Macnica's report confirms these methods, based on incident response and log analysis.
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS