← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Japan Reports Sharp Increase in Web Data Leaks from Mobile API Abuse and Metabase Attacks

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Japanese organizations experienced a rise in data leaks.
  • Attacks exploited mobile app APIs and software flaws.
  • Metabase BI tool was a specific target due to known vulnerabilities.
  • 119 incidents reported in Japan this year, 81 since July.

Increase in Data Leaks

The JPCERT Coordination Center (JPCERT/CC) has observed a significant increase in personal data leaks affecting Japanese organizations. These incidents are distinct from ransomware attacks and often result in the compromise of substantial amounts of personal information. The center noted that the frequency of these attacks appears to be rising.

Attack Vectors Identified

JPCERT/CC indicates that attackers are primarily exploiting APIs associated with mobile applications and targeting known software vulnerabilities. While specific attackers and affected organizations were not named, the alert highlighted that business intelligence (BI) tools and internal employee management systems, not intended for public access, have been compromised. Data stored within these systems was subsequently leaked.

Metabase Vulnerability Exploited

The BI tool Metabase was specifically identified as a target. Attackers have exploited a known flaw in Metabase, prompting the vendor to urge users to upgrade to specific safe releases. These recommended versions are newer than the initial patch for the vulnerability, indicating ongoing risk.

Scale of Incidents

According to an analysis by Macnica's Security Research Center, 119 incidents of personal data theft or leakage via web systems in Japan were made public this year through October 6. This compares to 84 incidents in 2025 and 62 in 2024. A notable acceleration occurred in the latter half of the year, with 81 of this year's incidents reported in July or later. These figures exclude ransomware and incidents linked to other known attack groups.

Impact and Scope

The affected systems span various sectors, including online shops, member services, business systems, and customer support. Recent examples include a library's catalog search system and a tourist train's seat booking system. Two large-scale incidents involved Park24, which reported data on approximately 6.6 million accounts from its Times Car service, and another unnamed organization.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

JPCERT/CC reported a surge in personal data leaks at Japanese organizations, attributing them to mobile app API abuse and exploitation of known software flaws, including in the Metabase BI tool. These incidents, separate from ransomware, have led to large-scale data compromises and are increasing, with 81 of 119 incidents this year occurring since July.