Website and app breaches in Japan since September 2026
Since mid-September, a string of Japanese companies have disclosed breaches of their websites and apps. Car-sharing service Times Car said data from about 6.6 million accounts was taken, including ID images such as driver's licences for about 1.6 million. As of 9 October we found no official attribution, and the Chief Cabinet Secretary said on 6 October it was unclear whether the incidents were related. Readers outside Japan are affected only if they hold accounts with these services.
Since mid-September, Japanese services for image sharing, car sharing, convenience stores, restaurants, second-hand books and travel booking have disclosed breaches of their websites or apps, with the largest ranging from several million to over 20 million records. Car-sharing service Times Car said data from about 6.6 million accounts was taken, and that about 1.6 million of those included ID images such as driver's licences. JPCERT/CC, Japan's computer emergency response coordination centre, issued an alert on 8 October about a run of breaches around September, and on 9 October the Japanese government asked businesses handling large amounts of personal data to review their security promptly. As of 9 October we found no official attribution, and readers outside Japan are affected only if they hold accounts with these services.
On 6 August, the BI tool (software that turns databases into reports and charts) Metabase disclosed an SQL injection flaw that could give an unauthenticated attacker administrator access, and said it had been exploited. JGC Digital said on 18 September that its Metabase instance had been breached, and VOISING reported from 18 August that a BI tool, which it did not name, was breached through a known flaw.
Japan's Digital Agency said on 11 September that attackers had used a VPN device flaw to break into a government system, possibly exposing about 246,000 records on ministry staff and others involved in the work. The agency's notice says it detected unusual access on 25 June and identified the entry point on 9 July, but does not say when the intrusion began. According to Nikkei xTECH on 9 October, the intrusion began in late May, and the disclosure came about two and a half months after detection.
A research centre at Japanese security firm Macnica counted 119 public cases of personal data leaking from Japanese companies' web systems in 2026 up to 6 October, 81 of them disclosed from July onwards. Its count excludes ransomware and cases the author attributes to other groups, such as logins with credentials leaked from other sites. We found no count published by the Japanese government or JPCERT/CC.
Image-sharing service Gyazo said on 16 September that attackers used a flaw in its upload server on 11 September to run arbitrary commands, leaking about 23.62 million user records including hashed passwords and email addresses. Times Car detected the intrusion on 25 September and said on 28 September that names, addresses, birthdates and licence details were taken; on 29 September it confirmed that images of driver's licences, proof-of-address documents and other IDs leaked for about 1.6 million accounts. As of 9 October it had not said how the attackers got in.
Restaurant chain Yakiniku King said on 5 October that about 10.79 million app member records leaked, including the name registered in the app, email and phone number, and convenience store chain Lawson said about 2.16 million records leaked after the security mechanism that shows users their own data in its app was breached. On 9 October, second-hand bookseller BOOKOFF said member data was taken, with up to about 6.43 million records (counted by membership number) possibly affected, and travel booking site skyticket disclosed three separate intrusion routes, one involving about 14.64 million records.
Outsourced systems were hit as well. The operator of the FAQ system i-ask said an attacker logged in to its admin site without authorisation on the evening of 2 October and planted a program, possibly taking enquiry records from up to five client companies on the same server. One client, Daiwa Securities, said names, email addresses and account numbers of about 110,000 customers may have leaked, and the company said the data cannot be used to log in or trade. Pharma DIGITAL, a drug maker's website for medical professionals run by an outsourced operator, said its member database was breached and data on up to about 514,000 medical professionals may have leaked.
Ransomware attacks also continued in the same period. According to Japanese tech outlet TECH+, Keio Electric Railway confirmed a ransomware attack on its group servers on 26 September. JPCERT/CC's alert covers the attack types behind mass personal data leaks and is separate from routine ransomware incidents.
JPCERT/CC said its information was limited and fragmentary, and that not every case used the same method. Based on reports it received, it grouped the possible methods into four types: scanning each target for known vulnerabilities, possibly also stealing configuration and backup files; attacks on the admin APIs (interfaces programs use to exchange data) behind mobile apps; the Metabase flaw; and, added in its 9 October update, WAR files (packaged Java web applications) planted on application servers as web shells (programs that let attackers run commands remotely). For the API type, the reported techniques include analysing public apps to find API endpoints and keys, attacking internal APIs not exposed in the app's screens, and using API keys stolen from other systems.
The alert does not name victims or match incidents to methods. Macnica sorted the 81 cases since July into vulnerabilities, authentication and configuration by the causes given in disclosures, and only 16 contained enough detail to fit, while 65 did not. Hosting provider SAKURA internet said in its third notice on 10 September that data on about 1.36 million member accounts in its sales management system may have leaked. SAKURA internet and relaxation and beauty booking service EPARK both said they would not disclose the intrusion route, to avoid similar attacks.
According to The Japan Times, the Chief Cabinet Secretary said on 6 October that it was not yet clear whether the incidents were related. As of 9 October we found no claim of responsibility and no official finding on whether a single group was involved. The same day as the Chief Cabinet Secretary's remarks, the Digital Minister urged people not to reuse passwords, to turn on multi-factor authentication and to go to official sites or apps rather than click links in suspicious messages. On 7 October, the Personal Information Protection Commission (PPC), Japan's data protection authority, issued an alert reminding businesses of their security obligations and of the need to delete personal data they no longer need.
On 9 October, the National Cybersecurity Office (NCO) asked businesses handling large amounts of personal data to promptly review their web systems, supply chains (including contractors) and data management. It also asked affected organisations to share technical details with the NCO, relevant ministries and expert bodies. The Financial Services Agency (FSA) told financial institutions the same day to check again whether ID images and users' photos look unnatural during online identity checks.
NHK's 6 October report said in its lead that a security company, citing the rise in cases since July, considered it likely that AI was being used. Macnica wrote that it found no logs or traces proving AI was used, though the author considers AI use hard to rule out because probing this many sites by hand is not realistic. The NCO's document mentions in a single line that attack methods, including AI misuse, are growing more sophisticated, and the alerts from JPCERT/CC and the Information-technology Promotion Agency (IPA) do not mention AI.
Perspective
The APIs behind mobile apps are meant to be called by the app, but anyone can download and analyse the app, and finding API endpoints and keys in apps is one of the techniques in JPCERT/CC's second type. JPCERT/CC recommends access control on every endpoint, rate limits and avoiding long-lived tokens. The PPC's alert, revised on 7 October, separately describes an attacker who logs in and then changes parameters such as member IDs in the URL to read other users' data. It recommends checking on every request whether the user is allowed to read that record, using random member IDs and limiting request rates.
Times Car's breach covered members, former members and people who never finished signing up. Its FAQ says names, addresses and birthdates are kept for seven years under tax law, and licence data and images for seven years to prevent impersonation. The PPC's alert reminds businesses to delete personal data they no longer need and to confirm the legal basis for what they keep.
Times Car's FAQ says financial institutions also match a user's photo or check an account in the user's name during online identity checks, but it cannot rule out impersonation using leaked ID images. Under amended rules of Japan's anti-money-laundering law (the Act on Prevention of Transfer of Criminal Proceeds), regulated businesses such as financial institutions will stop accepting uploaded ID images for online identity checks from 1 April 2027. The FSA says checks will in principle switch to reading the ID card's IC chip, and asks institutions not to wait until then.
SAKURA internet and EPARK withheld technical details to avoid copycat attacks. Macnica wrote that while a new type of attack is spreading, even partial disclosure of methods can help reduce the next victims. The NCO asked victims to share technical details with the NCO, ministries and expert bodies.
Japan requires businesses to report breaches caused by unauthorised access, including possible ones, to the PPC and to notify the people affected, with guidance suggesting a preliminary report within three to five days. South Korea's rules, in force since 11 September 2026, require notifying individuals within 72 hours. Breaches involving 1,000 or more people, sensitive or unique identifiers, or external unauthorised access must also be reported within 72 hours to the regulator or the Korea Internet & Security Agency (KISA), unless the leak route has been confirmed and the data recovered or deleted.
Korea's data protection commission warned in July 2026 about leaks through APIs that check only whether a user is logged in, not whether the user may view the data. Singapore requires organisations to notify the regulator within three calendar days of assessing a breach as notifiable, for example one affecting 500 or more people, and to notify individuals only where significant harm is likely.
Taiwan's current Personal Data Protection Act requires only notifying affected people after the facts are established, with reporting to regulators set by sector rules, such as 72 hours for serious incidents under the financial regulator and the digital ministry. An amendment promulgated in November 2025 adds a duty to report to the regulator, but as of 9 October no effective date had been set. In Hong Kong, reporting to the Privacy Commissioner was still voluntary as of 9 October; the Commissioner's office has proposed making it mandatory, and the government is still studying the change. Macao's Personal Data Protection Act had no breach notification clause as of the same date.
Disclosures are posted on each company's official website. The Digital Minister and several of the companies advise going to the official website or app directly rather than following links in email or text messages. Gyazo and skyticket asked users to change their passwords, including on other services where the same password is used, and skyticket warned against messages asking for transfers or app installs in the name of refunds or compensation. Changing passwords and turning on multi-factor authentication protect the account itself, but names, addresses and ID images that have already leaked cannot be recalled.
As of 9 October, Times Car and Yakiniku King said the causes were still under investigation. According to The Japan Times, the National Police Agency is surveying the incidents and methods with a private company, with results expected in March 2027.