Japan's government is treating a two-week barrage of data breaches at major companies and public bodies as a national emergency. Digital Minister Masaaki Taira convened a crisis meeting of the National Cybersecurity Office (NCSO) on Friday, telling reporters Japan faces a "state of emergency in cyberspace," while Cybersecurity Minister Toshiharu Furukawa called the situation "extremely critical," according to the Financial Times and heise online.
Public broadcaster NHK has catalogued at least 18 comparable incidents; the Financial Times counts at least 20 affected organisations — among them rail group JR East, SoftBank, brokerage Daiwa Securities, car-rental operators and barbecue chains. Almost all involve personal data, and the government has begun warning citizens about fraud and identity theft built on the leaked records.
What has leaked so far
- Tokyo Metro disclosed on 27 September that 59,000 customer email addresses had been exposed, and warned the data may have reached third parties. - Nikkei said on 5 October that a compromised Microsoft 365 account belonging to an employee was used to send spoofed emails to internal and external recipients — including the business newspaper's confidential sources. - The Japan Atomic Energy Agency (JAEA) revealed on 8 October that identity documents and medical examination results for 175 people had left the organisation, among them driving licences and passports complete with photographs. The access came through a cloud platform run by a contractor. - Yakiniku King, a large restaurant chain, lost data on 10.8 million customers after what it described as illegal access to its membership system — the single biggest loss reported so far.
The security research centre at Macnica, cited in the JPCERT alert, counted 119 publicly reported personal-data leaks in Japanese web systems this year to 6 October — against 84 in all of 2025 and 62 in 2024. Eighty-one of them came since July.
The three attack paths behind the wave
JPCERT/CC issued an alert on 8 October describing three observed attack paths, listing eight source IP addresses and five User-Agent strings:
1. Targeted hunting for unpatched vulnerabilities in exposed systems. 2. Abuse of internal APIs that an app's user interface never reveals — found by reverse-engineering mobile apps or by reusing API keys stolen elsewhere, and exploited by stripping headers, using modified tokens, or blind NoSQL injection to pull account details. JPCERT's advice: enforce access controls on every endpoint, public or not. 3. Exploitation of CVE-2026-72898, an SQL injection flaw in the Metabase analytics platform that has been public since August.
None of the three is exotic. The picture emerging is less "AI superweapon" and more unglamorous plumbing: mobile back ends that trust their own clients, and a widely deployed analytics tool that nobody patched.
The response
As a first concrete step, Japan's banking regulator has recommended that banks stop accepting driving licences as identity proof for new accounts and instead require documents carrying an NFC chip. Warnings are cascading from ministries through the NCSO to local authorities and to companies holding customer data.
Since 1 October, legislation enabling pre-emptive "active cyber defence" has been in force, allowing measures against hostile servers before damage occurs, alongside a law obliging critical-infrastructure operators to harden defences and prepare recovery plans.
The wider regional context is uncomfortable. Japan's National Police Agency logged a record 123 ransomware incidents in the first half of 2026 alone. Reuters reports that nine South Korean banks and two mega-churches are investigating attacks that may have involved AI tooling, with experts warning that AI is lowering the barrier for criminals with limited technical skill.
Attribution remains unknown, which is itself notable: a campaign spanning rail, telecoms, media, nuclear research and hospitality is not the signature of a single opportunistic crew.
Why it matters
Japan's breach wave is a reminder that the most damaging intrusions rarely require novel techniques. An unauthenticated SQL injection in a BI tool, an undocumented mobile API, a reused key — the same short list appears in incident reports everywhere. What is new is velocity: eighteen-plus organisations in roughly two weeks, and an officialdom that has stopped calling it bad luck and started calling it an emergency.
Sources
- heise.deheise online: Japan reagiert auf Welle von Cyberangriffen
- ft.comFinancial Times: Japan declares cyber space emergency as attacks soar
- reuters.comReuters: South Korea, Japan buffeted by hacks as AI lowers bar for cybercriminals
- thehackernews.comThe Hacker News: Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
- cyberstack.orgJPCERT/CC alert coverage: wave of personal data leaks at Japanese organisations
- asahi.comAsahi Shimbun: Japan issues warning over rising cyberattacks
- japannews.yomiuri.co.jpYomiuri: Cyber Defense — Improving Japan's Capabilities is an Urgent Issue




