Japan Reports Sharp Rise in Web Data Leaks

 

Japan is experiencing a sharp rise in personal-data leaks from web systems, according to an October 2026 alert from the JPCERT Coordination Center. The incidents, which surged around September, are separate from ransomware and other routine breaches, and JPCERT/CC says they may be increasing. While the agency did not identify attackers or affected organizations, it described the available evidence as limited and fragmentary, and cautioned that the same technique was not necessarily used in every case. The pattern points to attackers systematically probing web applications and APIs for basic security weaknesses rather than relying on one universal exploit.
The scale is substantial. Security firm Macnica counted 119 publicly disclosed incidents in Japan through October 6 in which personal data was stolen or leaked through organizations’ web systems—up from 84 in all of 2025 and 62 in 2024. Eighty-one of this year’s cases occurred in July or later. Targets have ranged from online shops and member services to business systems and customer-support platforms, including a library catalog and a tourist train booking system. High-profile examples include Park24’s Times Car service, where data on about 6.6 million accounts was obtained, and Yakiniku King’s app, where more than 10.7 million records reportedly leaked. 
JPCERT/CC identified three main intrusion patterns. First, attackers analyze publicly released mobile apps to discover API endpoints and keys, then send unauthorized requests—sometimes to internal APIs that should not be reachable through the app. These requests have been used to alter user privileges, create unauthorized accounts, test authentication behavior, and extract data through blind NoSQL injection. Attackers have also used API keys stolen in earlier compromises. In other cases, they exploit weak administrator passwords, known software vulnerabilities, excessive data exposure, broken access controls, and session-management flaws. 
A particularly serious vector involves Metabase, an open-source business-intelligence tool. Attackers exploited CVE-2026-72898, a maximum-severity SQL injection flaw that requires no account to abuse and can grant administrator access to Metabase’s application database. From there, an intruder could steal credentials for connected databases and export their contents. Metabase patched the issue on August 6, but attacks continued afterward; the company has urged users to move to newer minimum-safe releases and, where upgrading is not immediately possible, to block the affected password-reset endpoint. 
For defenders, JPCERT/CC recommends applying access controls to every API endpoint, including internal ones; enforcing least-privilege permissions; rate-limiting sensitive functions such as login, password reset, and search; and ensuring tokens expire and can be revoked quickly. Organizations should also avoid embedding API keys or database credentials in shipped apps, review admin functions in vulnerability testing, restrict regional access where appropriate, and remove data no longer needed. Japan’s Personal Information Protection Commission issued a parallel alert, urging businesses to reassess whether the personal data they hold remains necessary. The message is clear: basic API hygiene, configuration review, and prompt patching remain decisive defenses.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: