The JPCERT Coordination Center (JPCERT/CC) has observed a significant increase in personal data leaks affecting Japanese organizations. These incidents are distinct from ransomware attacks and often result in the compromise of substantial amounts of personal information. The center noted that the frequency of these attacks appears to be rising.
JPCERT/CC indicates that attackers are primarily exploiting APIs associated with mobile applications and targeting known software vulnerabilities. While specific attackers and affected organizations were not named, the alert highlighted that business intelligence (BI) tools and internal employee management systems, not intended for public access, have been compromised. Data stored within these systems was subsequently leaked.
The BI tool Metabase was specifically identified as a target. Attackers have exploited a known flaw in Metabase, prompting the vendor to urge users to upgrade to specific safe releases. These recommended versions are newer than the initial patch for the vulnerability, indicating ongoing risk.
According to an analysis by Macnica's Security Research Center, 119 incidents of personal data theft or leakage via web systems in Japan were made public this year through October 6. This compares to 84 incidents in 2025 and 62 in 2024. A notable acceleration occurred in the latter half of the year, with 81 of this year's incidents reported in July or later. These figures exclude ransomware and incidents linked to other known attack groups.
The affected systems span various sectors, including online shops, member services, business systems, and customer support. Recent examples include a library's catalog search system and a tourist train's seat booking system. Two large-scale incidents involved Park24, which reported data on approximately 6.6 million accounts from its Times Car service, and another unnamed organization.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
JPCERT/CC reported a surge in personal data leaks at Japanese organizations, attributing them to mobile app API abuse and exploitation of known software flaws, including in the Metabase BI tool. These incidents, separate from ransomware, have led to large-scale data compromises and are increasing, with 81 of 119 incidents this year occurring since July.