Incident Database
A sourced list of incidents stemming from AI-assisted development, and of publicly disclosed data leaks and unauthorized-access cases.
Browse by theme
Data breach scale rank
Incidents are grouped into seven levels by the order of magnitude of publicly disclosed counts. This is not a rating of companies or services.
Counts mix people, records and accounts, so comparisons are not exact. Dashed borders indicate incidents where a leak has not been confirmed.
Go to the list and filtersS1,000,000 or more16 cases
A100,000 or more15 cases
B10,000 or more15 cases
C1,000 or more12 cases
D100 or more8 cases
E10 or more5 cases
FFewer than 102 cases
Count not disclosed (55 cases)
AI development impact rank
Incidents are grouped into seven levels by the scope of impact described in reports and news coverage. This is not a rating of products or companies.
These levels do not precisely compare the severity of damage. Dashed borders indicate unconfirmed incidents, including unverified reports.
Go to the list and filtersSProduction11 cases
AWhole machine or drive7 cases
BWhole project11 cases
CMultiple files22 cases
6 more cases
DSingle file5 cases
EHistory only15 cases
FNo confirmed damage5 cases
No rank (32 cases)
Filter incidents
Showing 236 of 236 incidents
| Date | Target | Summary | Classification | Source links |
|---|---|---|---|---|
| LEAK-115 | GMO Research & AI "infoQ" | A Up to 948,498 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-116 | Mr Max Holdings | S Up to 1,735,154 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-004 | LEAN BODY | Unauthorized access exploiting a vulnerability in Metabase, a tool used for internal data analysis, resulted in customer information such as email addresses and encrypted passwords being obtained for about 440,000 accounts, including those of former members. | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-006 | White Essence | A vulnerability in the reservation site program was used as a foothold for unauthorized access to the core system, and data of about 1.05 million accounts, including names, addresses, email addresses and encrypted passwords, was taken out. | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-111 | Daiwa Securities | A About 220,000 | Supply chainPossibleOfficial statement | |
| LEAK-112 | Daiki Suisan "Daiki Suisan Official App" | A 174,933 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-113 | Monogatari Corporation "Yakiniku King" | S 10,788,963 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-109 | Nikkei Inc. | C 1,646 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-106 | ABAHOUSE INTERNATIONAL | Unauthorized access by an overseas third party is presumed to have occurred from late on September 27 to September 28, 2026, and names, addresses, order information and other data may have leaked from the database holding member and e-commerce order information. The number of affected records was not disclosed. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-114 | Recruit "Studysapuri" | C 3,687 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-084 | Yamato Transport "Kuroneko Daikin Atobarai Service" | The "Kuroneko Daikin Atobarai Service" was accessed without authorization by a third party on September 28, and the investigation found that names, addresses, phone numbers, billing amounts and other data of some users, information on some partner merchants, and names of staff in charge may have been leaked. Card information and passwords are not included. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-085 | The Institute of Energy Economics, Japan | D 759 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-104 | Dai-ichi Life Group / Dai-ichi Life Insurance | A About 120,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-105 | The Japan Times | The company announced that part of a server managed by a group company was accessed without authorization. Whether information leaked, the scope of impact and the cause are under investigation with external specialists, and no impact has been confirmed on its digital edition, subscriber databases or payment system. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-107 | Moonstar | The company announced that an external intrusion into its system server may have led to the viewing or acquisition of online store customers' names, addresses, phone numbers, email addresses and past order information. No number of affected records was given. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-108 | Kodansha BECK | An employee's email account formerly used at Kodansha BC was accessed without authorization, and 50 suspicious emails were sent externally on September 14, 2026. Traces show mail data was obtained, so personal information stored in the account may have leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-110 | Sammy Networks "777CON-PASS" | The server of the 777CON-PASS app it operates was accessed without authorization, and user data was targeted on September 25, 2026. Gender, date of birth, profile photos, action areas and other data may have leaked. The number of affected users is under investigation. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-102 | Lashinbang Co.,Ltd. | The company's service was accessed without authorization from September 14 to 16, 2026, and names, ID document types and numbers, bank account details entered at buyback and other data may have leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-103 | Japan Atomic Energy Agency | D 175 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-099 | Benefit One Inc. | B 13,460 | Misdelivery & accidental exposureConfirmedOfficial statement | |
| LEAK-100 | Sagawa Express Co., Ltd. | Unauthorized access to the website's package inquiry service was confirmed on September 30, 2026, and personal information of shippers and recipients, fare-contract customers and Smart Club members may have leaked. The number is under investigation. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-101 | G-PLAN INC. (G Point) | B Up to about 70,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-131 | Shudo Gakuen | On September 26, 2026, unauthorized third-party access to a server managed by the school corporation was confirmed. Account information of business partners and names, addresses, phone numbers and account details of staff, some students and external lecturers may have been leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-074 | Seicomart "Seicomart App" | A About 570,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-075 | eplus | C 1,463 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-083 | Japan Post "Yubinkyoku App" | E 19 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-097 | QUO CARD (LINE official account campaign system) | The campaign system of the LINE official account was accessed without authorization, and LINE display names and campaign winning information of some users may have been viewed or leaked. Affected people and scope are under investigation. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-081 | Shinano Mainichi Shimbun "Shinano Mainichi Shimbun Digital" | Unauthorized access from outside to the Shinmai point exchange system of "Shinano Mainichi Shimbun Digital" was found on September 7, and some history data was temporarily erased. No leak of personal information has been confirmed, the data has been restored, and point balances were not affected. | Tampering & unauthorized operationConfirmedOfficial statement | |
| LEAK-098 | Shueisha Inc. (HAPPY PLUS COMMUNITY) | C 2,835 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-071 | Starts Publishing "OZmall" | A Up to 447,610 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-073 | Tokyo Metro "Metro Point Club" | B About 59,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-019 | Enoguya Sankichi | Through unauthorized access to the e-commerce system "ShopServe" of Estore Co., Ltd., which the shop uses, it was found on September 25, 2026 that the shop's customers' information was also subject to the leak. This includes names, addresses, email addresses, encrypted passwords and part of the card information. | Supply chainConfirmedOfficial statement | |
| LEAK-072 | Nippon Rent-A-Car Service "Nippon Rent-A-Car App" | E 41 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-003 | Times Mobility 'Times Car' | S About 6,600,000 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-067 | Japan Post "International Mail Inquiry Request Web Reception Service" | At around 15:00 on September 25, 2026, a possible unauthorized access from outside was found on the server used by the international mail inquiry request web reception service. The cause and scope are under investigation, and the service has temporarily stopped accepting requests. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-096 | LEGOLAND Japan (LEGOLAND Japan Hotel) | C 1,557 | Supply chainPossibleOfficial statement | |
| LEAK-130 | Fines Inc. | S 1,536,322 | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-095 | Nichirei Corporation | B 43,709 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-002 | Helpfeel 'Gyazo' | S About 23,620,000 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-027 | Daiko Printing "PhotoGoods" | A vulnerability and the file upload function of the e-commerce site it operates were abused, and from August 6 to September 11, 2026 a program that captures card information on the payment screen was installed. Card information, names, addresses, email addresses and other data may have been leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-061 | Rohto Pharmaceutical | A possible unauthorized access to systems used for mail-order sales was identified on September 10. The investigation found that call-recording data and related information in the customer-service system, and information in the customer management system, may have been obtained by a third party. The scope and number of records are under investigation. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-078 | Ainokaze Toyama Railway "Ichiman Sanzenjaku Monogatari" | C 1,409 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-128 | Odawara Engineering Co., Ltd. | A third party had unauthorized access to the email account of an employee seconded to the German subsidiary from March 27 to August 31, 2026, and viewing of about 3,500 emails was confirmed. The third party also sent payment-instruction emails impersonating the employee, causing financial losses to some business partners. | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-048 | Harada Sangyo Co., Ltd. "Beer no Engawa" | F 9 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-077 | Nihon University | F 5 | Tampering & unauthorized operationConfirmedOfficial statement | |
| LEAK-079 | Azuma Sangyo | Azuma Sangyo's official website was accessed without authorization by a third party exploiting a website vulnerability. The information concerned is limited to customer information obtained via the contact form, the timing and scope are under investigation, and no external impact has been confirmed. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-054 | Digital Agency "Government Solution Service (GSS)" | A About 246,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-064 | Nihon Torekusu | Parent company Kyokuto Kaihatsu Kogyo announced that a system failure caused by unauthorized access occurred at its subsidiary Nihon Torekusu on September 8. Online ordering, the dealer parts-order system and email exchange with customers and partners are suspended, and no external leak of personal or customer data has been confirmed. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-068 | Halmek Holdings "HALMEK up" | The ID and password of one employee were stolen, and unauthorized access to the administration screen of the website HALMEK up was confirmed on September 9, 2026. The current investigation has found no log evidence of access to customer management information, and details are still being investigated. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-070 | Tsuburaya Productions "ULTRA MART" | The digital ticket system (mogily) used for lottery sales at Tsuburaya Productions' "ULTRA MART" was accessed without authorization by a third party, causing inconsistencies in lottery result data and changing some winners to a losing display. No leak of personal information has been confirmed. | Supply chainConfirmedOfficial statement | |
| LEAK-076 | mogily digital ticket system | D 133 | Tampering & unauthorized operationConfirmedOfficial statement | |
| LEAK-050 | REVISIO Inc. | Malware infection of one business PC used by an officer or employee was confirmed on March 20. No remote connection from outside or unauthorized server access was found, but a leak of personal information from business cards stored on the PC cannot be ruled out. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-066 | Fuso Dentsu | B 26,489 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-063 | ApplyNow "Interview Cloud" "ApplyNow" "ApplyNow Sign" | A vulnerability in a data analysis tool used by the company was exploited, and traces of unauthorized access to part of the recruitment-management services' database were found. Applicant and corporate user information, and for the electronic employment contract service, contractor information including individual numbers and bank account details, may have been leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-065 | Enshu Yumesaki Agricultural Cooperative (JA Enshu Yumesaki) | On August 24, 2026, the website's program was tampered with through unauthorized access and could no longer be updated, so the site was temporarily closed. Because no personal information is stored on the server, no leak of personal information has been confirmed. | Tampering & unauthorized operationConfirmedOfficial statement | |
| LEAK-062 | Kyoto Purple Sanga (Kyoto Sanga F.C.) | B 15,612 | Misdelivery & accidental exposureConfirmedOfficial statement | |
| LEAK-052 | Institute of Science Tokyo | The university's information infrastructure was accessed without authorization, and the names, addresses and email addresses of people enrolled at the time of the merger of the two former universities, among others, may have been leaked. The scope is under investigation, and no leak of hospital patient information has been confirmed. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-051 | East Nippon Expressway Company Limited (Tokyo Gaikan Project website) | Suspected unauthorized access by a third party was identified on the Tokyo Gaikan Project website; its publication has been suspended and the cause is under investigation. No leak of personal information has been confirmed. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-059 | Seibu Railway "Seibu Tabisuru Resutoran 52-seki no Shifuku" | D About 500 | Misdelivery & accidental exposureConfirmedOfficial statement | |
| LEAK-049 | Mitsui Fudosan Co., Ltd. | B Up to 36,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-060 | Chiba Prefecture "Inochi no Nigiwai Chosadan" (Biodiversity Center website) | C 1,963 | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-127 | TRUNK Co., Ltd. | D 424 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-094 | Mandarake Inc. | Unauthorized access to the company's servers was confirmed on August 27, 2026, and names, addresses, phone numbers and email addresses of mail-order customers who ordered by 6 a.m. on August 28 may have leaked. Mail-order and auction services were suspended. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-005 | kindal | A 136,464 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-056 | Co-op Yamaguchi "Co-op Yamaguchi LINE Mini App" | On August 27, 2026, a third party gained unauthorized access to the database of the LINE mini app, which is operated by an outsourced vendor, and all data was deleted. Service was restored from backup the same day, and the cooperative says it cannot rule out leakage of names, addresses, phone numbers and email addresses. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-058 | Shizugin TM Securities | Unauthorized access to customers' securities accounts and unauthorized trades, believed to stem from phishing and similar methods, were confirmed. For losses where third parties traded securities using customers' assets, the firm plans to examine each case and provide certain compensation according to individual circumstances. | Tampering & unauthorized operationConfirmedOfficial statement | |
| LEAK-093 | Treasure Factory Co., Ltd. (subsidiary Kaindoru) | A 136,464 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-126 | Corona | B Up to 35,000 | Supply chainPossibleOfficial statement | |
| LEAK-055 | CINRA, Inc. "CINRA JOB" | On August 18, 2026, credentials for the cloud environment were obtained by a third party, who accessed the member database and its backups. Because no records exist to confirm whether data was viewed or taken, the company says the personal information of members, including former members, may have been leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-057 | Tsunagu | D 157 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-092 | Zurich Insurance Company Ltd | C Up to 1,668 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-125 | 01Bank | On August 17, 2026, unauthorized third-party access to its systems was detected, and it was confirmed that customer identifiers used by the system and email addresses were stolen and leaked. The leak covers up to 100 companies, and the affected customers have not been identified. | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-046 | Tokai University Yamanakako Seminar House | D 274 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-014 | KDDI Web Communications 'CPI' | S 1,250,543 | Supply chainConfirmedOfficial statement | |
| LEAK-053 | Nihon Business Data Processing Center | Unauthorized access to the company's systems was confirmed at 11:53 on August 20, 2026, and the internal network was cut off. The cause and scope are being investigated with an external specialist, and the notice does not state whether any information was leaked. | Unauthorized access & data leakUnder investigationOfficial statement | |
| LEAK-091 | All Nippon Airways Trading Co., Ltd. (Eraberu e-GIFT) | The management system of the corporate digital gift service Eraberu e-GIFT was accessed without authorization on August 11-12, 2026, and part of contract company contacts' names and email addresses may have leaked. Unauthorized gift exchanges were also confirmed. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-047 | Kankyo Kiki Co., Ltd. "Mushitaiji.com" | E 15 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-044 | Central Consultant Inc. | A possible unauthorized access to its corporate website was identified, and the database storing the company names, names, contact details and inquiry contents submitted through the contact form during the period may have been viewed or obtained. No leak itself has been confirmed and the investigation continues. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-090 | Japan Association for the 2025 World Exposition (subcontractor of outsourced work) | At a subcontractor of outsourced work, phishing led to unauthorized access to Microsoft 365, and emails containing personal information of people involved and event performers may have been affected. It occurred on May 13, 2026. | Supply chainPossibleOfficial statement | |
| LEAK-008 | KDDI | S 12,231,954 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-082 | SAKURA internet Inc. | S 1,360,563 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-124 | GEX Corporation | B 77,619 | RansomwarePossibleOfficial statement | |
| LEAK-089 | VOISING Inc. | A Up to about 170,000 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-026 | GODAI KAIHATSU Corporation "Isabo Net" | The server of "Isabo Net" managed by the company was subjected to unauthorized access and attack on January 26, 2026, and members' names, email addresses, passwords, company names, addresses and phone numbers may have been viewed or obtained. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-043 | Innovation Inc. | B 62,691 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-087 | Digital Agency | D 150 | Misdelivery & accidental exposureConfirmedOfficial statement | |
| LEAK-088 | Japan Science and Technology Agency | B About 18,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-036 | Shin FA Com | A third party stole account credentials and intruded into the network, and files containing some business partners' employees' names, employers, departments and transaction-related information may have been viewed or obtained. No secondary damage has been confirmed. | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-029 | Waiefushii "ADVAN" | Estore Co., Ltd., the system provider of the company's online shop, was accessed without authorization, and customer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs, encrypted passwords and part of the card information. | Supply chainConfirmedOfficial statement | |
| LEAK-030 | JA Raifu Kurieito Fukushima "E-gyu Shop" | Estore Co., Ltd. announced that buyer and member information leaked from "ShopServe", which the shop uses. Whether the shop's customers are included is under confirmation, and members are advised to change their passwords. | Supply chainUnder investigationOfficial statement | |
| LEAK-031 | Amtrans | Estore Co., Ltd. announced that buyer information leaked through unauthorized access to the mail-order system "ShopServe", which the company uses. The company cannot confirm whether its own customers are affected and advises members to change their passwords. | Supply chainUnder investigationOfficial statement | |
| LEAK-016 | Designphil | The Shop Serve cart system used by Midori Online Store and others suffered unauthorized access, leaking names, addresses, email addresses, encrypted passwords and partial card data. The scope of those affected is under investigation. | Supply chainConfirmedOfficial statement | |
| LEAK-017 | Remedikomu | The shopping cart system Shop Serve used by the store suffered unauthorized access, leaking purchaser information of the store, including names, addresses, email addresses, member IDs and encrypted passwords. Card data was kept on a separate server and was not affected. | Supply chainConfirmedOfficial statement | |
| LEAK-028 | PRGR | "ShopServe" of Estore Co., Ltd., used by the company's online shop, was accessed without authorization, and buyer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs and encrypted passwords. | Supply chainConfirmedOfficial statement | |
| LEAK-015 | Estore 'Shoppu Sabu' | S 8,853,839 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-042 | Sen Corporation "Hai Cheese! Photo" | In unauthorized access from the evening of June 4 to the morning of June 5, the names, addresses, phone numbers and organization names of purchasers and recipients tied to some orders were confirmed leaked. The count was reported to the Personal Information Protection Commission but is withheld from publication. | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-045 | EPARK Relax & Este "PeakManager" | S About 33,000,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-037 | ASKUL Corporation | A About 600,000 | RansomwarePossibleOfficial statement | |
| LEAK-038 | TV Asahi Mediaplex Inc. | C 2,786 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-039 | C Connect Co., Ltd. "Ink Kakumei" | B 24,166 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-040 | Meitetsu Kyosho (customer information of Chuden Fudosan) | C About 4,000 | RansomwarePossibleOfficial statement | |
| LEAK-080 | Murauchi.com | S 7,716,811 | Unauthorized access & data leakConfirmedOfficial statement | |
| AI-067 | Claude Code | C Multiple filesClaude Code overwrote existing user file without confirmation — irreversible data loss | Data loss caused by AIUnverified reportFirst-party report | |
| AI-033 | OpenAI Codex | B Whole projectData loss: sub-agent TemporaryDirectory cleanup traversed an active bind mount and deleted the host repository | Data loss caused by AIUnverified reportFirst-party report | |
| AI-034 | OpenAI Codex | E History onlyCodex/ChatGPT update deleted all the conversations | Session & history lossUnverified reportFirst-party report | |
| AI-068 | Claude Code | E History onlyAssistant text in the same response as an AskUserQuestion tool_use is never persisted to the session JSONL (silent data loss) | Session & history lossUnverified reportFirst-party report | |
| LEAK-033 | media4u Inc. SMS sending system | B 95,412 | Unauthorized access & data leakConfirmedOfficial statement | |
| AI-016 | Cursor agent: entire D drive lost | A Whole machine or driveAfter asking to "clean up unneeded branches", projects, other work folders, apps and more under the D drive disappeared. Some unpushed work could not be recovered (cause/issue: a misfire of `git clean -fdx` or a wrongly resolved deletion path by Cursor Agent was presumed, but the history was also lost, so the executed command is unconfirmed). | Data loss caused by AIUnverified reportFirst-party report | |
| AI-069 | Claude Code | D Single filePlan file comments lost after "keep planning" rejected exit—silent data loss and orphaned threads | Session & history lossUnverified reportFirst-party report | |
| AI-070 | Claude Code | B Whole projectCowork broken since Chat/Cowork merge rollout 8–9 July: projects disappear within 24h (ongoing data loss) and connector tools never reach Cowork sessions (Windows 11, Desktop 1.20186.0) | Session & history lossUnverified reportFirst-party report | |
| AI-071 | Claude Code | A Whole machine or driveMajor Data loss. Agent-constructed test payload with $(...) executed for real due to bash double-quote handling — rm -rf ~ ran against live home directory | Data loss caused by AIUnverified reportFirst-party report | |
| AI-011 | Kaikatsu CLUB official app unauthorized access case | S ProductionMember information on over 7 million records may have been leaked. Suspected of halting some functions with over 7.24 million malicious commands (cause/issue: a high school student created and refined an attack program with ChatGPT and shared it on social media; several minors are suspected of running it). | Abuse of AIPossibleNews report |
|
| AI-072 | Claude Code | D Single fileSonnet 5 deleted my app off my phone out of the blue causing data loss | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-034 | First Co., Ltd. member page | Through unauthorized access exploiting a vulnerability or similar flaw in the system managing the member page, members' names, addresses, contact details, workplaces, debt status, bank account information and login credentials may have been leaked. | Unauthorized access & data leakPossibleOfficial statement | |
| AI-021 | Claude Code: fictitious prompt injection detection report | F No confirmed damageClaude Code reported receiving an `rm -rf` request and a fake System warning, but verification of a 505-entry, 1.2MB conversation log found the strings only in assistant output, showing it was confabulation rather than external injection (cause/issue: misrecognition of a security event and confabulation; no actual execution of destructive commands or data damage has been confirmed). | Tampering & unauthorized operationUnverified reportFirst-party report | |
| AI-073 | Claude Code | D Single file[claude-sonnet-4-6] Data Loss — Claude Code Overwrote User's Confluence Page Despite Explicit Instruction | Data loss caused by AIUnverified reportFirst-party report | |
| AI-074 | Claude Code | C Multiple filesDesktop app worktree mechanism wiped gitignored directories from MAIN working tree (data loss; only .gitignore literal-path entries deleted) | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-035 | Sakata Seed Corporation (Brazilian subsidiary Sakata Seed Sudamerica LTDA.) | Unauthorized access to a server of its Brazilian consolidated subsidiary was detected on June 27, and an investigation concluded that some information was accessed and may have been leaked. No damage causing business suspension and no impact on other group companies has been confirmed. | Unauthorized access & data leakPossibleOfficial statement | |
| AI-075 | Claude Code | A Whole machine or driveWindows: stale-worktree cleanup rm -rf traverses NTFS junctions and deletes data OUTSIDE the worktree (~800 GB data loss) | Data loss caused by AIUnverified reportFirst-party report | |
| AI-001 | Bandai Channel | S ProductionRoughly 46,800 accounts were fraudulently unsubscribed (cause/issue: a 15-year-old created an attack program with ChatGPT; the intrusion route has not been disclosed). | Abuse of AIPossibleNews report |
|
| LEAK-010 | Nifty '@nifty Mail' | S 2,248,708 | Supply chainConfirmedOfficial statement | |
| LEAK-011 | Chubu Telecommunications (ctc) | A 727,176 | Supply chainConfirmedOfficial statement | |
| LEAK-012 | STNet 'Pikara' | A 456,159 | Supply chainConfirmedOfficial statement | |
| LEAK-013 | JCOM | S 2,473,191 | Supply chainConfirmedOfficial statement | |
| AI-076 | Claude Code | E History onlyWindows: auto-updater reports success while claude.exe is locked (version never switches); session transcripts silently never written / stop being written (permanent data loss) | Session & history lossUnverified reportFirst-party report | |
| AI-077 | Claude Code | C Multiple filesUnrecoverable data loss from folder deletion due to malformed command syntax | Data loss caused by AIUnverified reportFirst-party report | |
| AI-078 | Claude Code | Unguarded `rm -rf` after a silently-failed `mv` causes irreversible data loss on a cloud-sync (file-provider) mount | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-025 | Kaga Solution Network "Akademiko Navi" | A Up to about 170,000 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-032 | Aflac Life Insurance Japan Ltd. | S About 4,400,000 | Unauthorized access & data leakConfirmedOfficial statement | |
| LEAK-123 | Nihon Gotochi Character Kyokai | A data-storage NAS was infected with ransomware and its data was encrypted. It holds contact data of character-related parties who took part in past events; no external leak has been confirmed so far. | RansomwareConfirmedOfficial statement | |
| AI-079 | Claude Code | `claude agents` background-session docs do not cover data loss when read by an older Claude Code version (v2.1.195 fix) | Session & history lossUnverified reportFirst-party report | |
| AI-080 | Claude Code | S ProductionI repeatedly ignore my own memory, saved scripts, and user instructions — causing production data loss 5 times in a row | Data loss caused by AIUnverified reportFirst-party report | |
| AI-012 | Generative-AI-built ransomware case: 19-year-old company employee in Otsu | F No confirmed damageArrested on suspicion of creating ransomware. According to public information, no specific damage from the malware has been confirmed (cause/issue: built the ransomware himself using several conversational generative AIs). | Abuse of AIPossibleNews report | |
| AI-035 | OpenAI Codex | B Whole projectCritical Data Loss: Turn-diff git corruption after rollback deletes all workspace files | Data loss caused by AIUnverified reportFirst-party report | |
| AI-081 | Claude Code | Stale/duplicate session titles + no wrong-session safeguard → silent data loss in Bypass-permissions mode | Session & history lossUnverified reportFirst-party report | |
| AI-082 | Claude Code | Path encoding strips all non-Latin characters — different directories collide, sessions cross-project visible, cleanup causes data loss | Session & history lossUnverified reportFirst-party report | |
| LEAK-009 | BIGLOBE 'BIGLOBE Mail' | S 5,016,432 | Supply chainConfirmedOfficial statement | |
| AI-083 | Claude Code | C Multiple filesClaude Code caused irreversible data loss: entire site UI redesign destroyed by unauthorized git stash | Data loss caused by AIUnverified reportFirst-party report | |
| AI-084 | Claude Code | xargs rm -rf without null delimiter caused data loss on paths with spaces | Data loss caused by AIUnverified reportFirst-party report | |
| AI-085 | Claude Code | E History onlyPhone/app session that runs locally is silently lost — transcript never persisted to host (consistent, data-loss) | Session & history lossUnverified reportFirst-party report | |
| AI-036 | OpenAI Codex | Plugins from built-in marketplace are deleted after restart — marketplace source not persisted to config.toml | Data loss caused by AIUnverified reportFirst-party report | |
| AI-037 | OpenAI Codex | B Whole projectDELETED DATABASE YET AGAIN | Data loss caused by AIUnverified reportFirst-party report | |
| AI-086 | Claude Code | B Whole projectAuto-accept mode runs destructive framework DB commands (e.g. `php artisan migrate:fresh`) without confirmation → data loss | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-021 | ACT1000 | On May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained. | RansomwarePossibleOfficial statement | |
| LEAK-022 | Daitsu Shisutemu | On May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained. | RansomwarePossibleOfficial statement | |
| LEAK-023 | Superioru Adobantekku | On May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained. | RansomwarePossibleOfficial statement | |
| LEAK-024 | Ofisu Integuraru | On May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained. | RansomwarePossibleOfficial statement | |
| AI-038 | OpenAI Codex | E History onlyPossible local transcript data loss after Codex Desktop update on Windows | Session & history lossUnverified reportFirst-party report | |
| AI-087 | Claude Code | C Multiple files[area:tool-use] [platform:macos] Write tool's full-file-replacement default causes irrecoverable data loss on governed, untracked state files — no append-only or protected-path mechanism available | Data loss caused by AIUnverified reportFirst-party report | |
| AI-088 | Claude Code | B Whole projectData Loss: Database content deleted after Claude Code update | Data loss caused by AIUnverified reportFirst-party report | |
| AI-089 | Claude Code | E History onlyv2.1.173 regression: TUI writes no transcript records when CLAUDE_CODE_CHILD_SESSION is inherited from a parent claude session — silent data loss, --resume broken | Session & history lossUnverified reportFirst-party report | |
| AI-003 | Survey of iOS LLM-integrated apps | LLM credentials were exposed in 282 of 444 apps. 92 used unauthenticated backends and 136 used reusable JWTs (cause/issue: direct client communication, plaintext keys, unauthenticated proxies, flawed token design). | Secret & credential exposureConfirmedResearch | |
| AI-090 | Claude Code | B Whole projectAuto-update DELETES sessiondata.vhdx — all Cowork projects, tasks and conversations destroyed (data loss, 2nd incident in 4 days, forensic evidence) | Session & history lossUnverified reportFirst-party report | |
| LEAK-122 | Kyushu University | On May 25, 2026, a terminal managed by a research laboratory was attacked and appears to have been infected with ransomware. Names and surgery video data of 43 Kyushu University Hospital patients stored on it may have been leaked. | RansomwarePossibleOfficial statement |
|
| AI-018 | Shared dependency folder lost through parallel work by Claude Code and Codex | C Multiple filesA shared folder of several hundred MB containing DLLs and AI models was caught up in working-copy cleanup and lost, and it recurred the next day (cause/issue: Windows junctions were shared among the working copies of multiple AIs, and Git reportedly deleted the link target as a normal folder). | Data loss caused by AIUnverified reportFirst-party report | |
| AI-091 | Claude Code | C Multiple filesSilent data loss: Cowork file writes truncated after successful md5 verification on Windows OneDrive folders | Data loss caused by AIUnverified reportFirst-party report | |
| AI-019 | Claude Code multi-agent operation: governance incident group | C Multiple files11 incidents consolidated into one for the same operating period. The main actual damage was the temporary unpublishing of 5 Zenn articles, 404 errors on 4 Hatena Blog URLs, and garbled posts. All were recovered (cause/issue: the AI changed configuration values on its own, ran an external CLI directly without consulting the procedure manual, and skipped fact-checking). | Tampering & unauthorized operationUnverified reportFirst-party report | |
| LEAK-121 | Fujita Health University Hospital | C 1,365 | Unauthorized access & data leakPossibleOfficial statement | |
| AI-092 | Claude Code | C Multiple filesClaude Code deleted client video files without confirmation — data loss on production work | Data loss caused by AIUnverified reportFirst-party report | |
| AI-093 | Claude Code | E History onlyCritical data loss: startup GC silently deletes all session transcripts | Session & history lossUnverified reportFirst-party report | |
| AI-096 | Gemini CLI | CRITICAL INCIDENT: Catastrophic Data Loss (1.2TB): Architectural Failure in Agent Reasoning & Destructive File I/O Logic | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-119 | Anabuki Housing Service | A 207,773 | RansomwareConfirmedOfficial statement | |
| AI-094 | Claude Code | C Multiple filesData Loss: Claude Code deleted important files from user system | Data loss caused by AIUnverified reportFirst-party report | |
| AI-039 | OpenAI Codex | E History onlyMy conversations are getting deleted accidentally | Session & history lossUnverified reportFirst-party report | |
| AI-020 | Codex Desktop: uncommitted changes lost | C Multiple filesOn a request to "revert it", Codex ran `git restore`. Several hours of uncommitted changes that existed before the task were also lost and could not be recovered from Git (cause/issue: ambiguity about what to roll back, no backup before the task, no approval step to protect uncommitted diffs). | Data loss caused by AIUnverified reportFirst-party report | |
| AI-097 | Gemini CLI | Issue Report: Gemini CLI Agent: Data Destruction and Permanent Loss of Source Code | Data loss caused by AIUnverified reportFirst-party report | |
| AI-005 | Survey of vibe-coded apps on Lovable, Replit, Base44 and others | S ProductionMore than 5,000 apps were found with virtually no authentication, and about 2,000 of them reportedly exposed private data such as corporate documents, conversation logs, and medical and financial information (cause/issue: no authentication, guessable URLs, public databases, no access control implemented). | Unauthorized access & data leakConfirmedResearch | |
| AI-040 | OpenAI Codex | E History onlyData loss: resumed-thread errors due missing rollout JSONL files (state still has threads, files gone) | Session & history lossUnverified reportFirst-party report | |
| AI-041 | OpenAI Codex | E History onlyChat History Deleted | Session & history lossUnverified reportFirst-party report | |
| AI-098 | Gemini CLI | gemini-3-flash-preview poor code analysis and refactoring led to catastrophic data loss | Data loss caused by AIUnverified reportFirst-party report | |
| AI-002 | Vercel / Context.ai | S ProductionStarting from the compromise of Context.ai, a third-party AI tool used by an employee, the employee's Google Workspace and Vercel accounts were taken over, and environment variables not marked as sensitive were enumerated and decrypted. Vercel notified the affected customers and says its published npm packages were not compromised. | Supply chainConfirmedOfficial statement | |
| AI-042 | OpenAI Codex | B Whole projectcodex-rescue invocation deleted user source repo on disk (destructive cleanup before auth check) | Data loss caused by AIUnverified reportFirst-party report | |
| AI-022 | Cursor / PocketOS | S ProductionPocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6 | Data loss caused by AIPossibleAIID | |
| LEAK-001 | Nirinkan Yellow Hat 'Nirinkan App' | S 3,179,454 | Unauthorized access & data leakConfirmedOfficial statement | |
| AI-043 | OpenAI Codex | F No confirmed damageDestructive cleanup can be auto-approved during premature rewrite "finalization" under guardian auto-review | Data loss caused by AIUnverified reportFirst-party report | |
| AI-044 | OpenAI Codex | A Whole machine or driveCodex Desktop deleted workspace roots + installed apps on failed archive (bypassed Recycle Bin) | Data loss caused by AIUnverified reportFirst-party report | |
| AI-099 | Gemini CLI | C Multiple filesMajor data loss (entire music library) while managing library via cli. | Data loss caused by AIUnverified reportFirst-party report | |
| AI-100 | Gemini CLI | Critical data loss and unauthorized code deletion during file updates. | Data loss caused by AIUnverified reportFirst-party report | |
| AI-004 | Google API key / Gemini exposure in Android apps | 22 apps with over 500 million cumulative installs. Risk of unauthorized use of AI features and files in apps such as ELSA Speak (cause/issue: Google API keys hardcoded in the apps and excessive API permissions). | Secret & credential exposureConfirmedResearch | |
| AI-045 | OpenAI Codex | E History onlySession logs data loss | Session & history lossUnverified reportFirst-party report | |
| AI-046 | OpenAI Codex | Deleted my dictation | Session & history lossUnverified reportFirst-party report | |
| AI-095 | Claude Code | C Multiple filesDestructive batch rename operation caused data loss | Data loss caused by AIUnverified reportFirst-party report | |
| AI-047 | OpenAI Codex | E History onlyThread history data loss on restart — async persistence not flushed on shutdown (RolloutRecorder, SQLite WAL, session_index) | Session & history lossUnverified reportFirst-party report | |
| AI-048 | OpenAI Codex | C Multiple filesHTML files being 0 bytes and being deleted | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-086 | Mynavi Corporation | B 74,224 | Unauthorized access & data leakPossibleOfficial statement | |
| AI-017 | AI coding agent: wrong S3 deletion target | B Whole project`aws s3 sync --delete` was run against an S3 bucket for important data, generating 47,204 delete markers. Data returned 404 on normal access, but everything was restored from versioning (cause/issue: selected a non-frontend bucket from the Terraform output and ran a destructive sync with broad S3 delete permissions). | Data loss caused by AIUnverified reportFirst-party report | |
| AI-049 | OpenAI Codex | Plan Mode updates are destructive: existing sections are rewritten/condensed instead of preserved | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-120 | zetton Inc. | B 18,553 | Unauthorized access & data leakPossibleOfficial statement | |
| AI-006 | Survey of ChatGPT API key exposure on GitHub and public sites | A survey reporting that over 8,000 OpenAI / ChatGPT API keys were exposed (cause/issue: hardcoding in source, public repositories, frontend bundles). | Secret & credential exposurePossibleResearch | |
| AI-101 | Gemini CLI | TOCTOU Race Condition in `MemoryTool` Causes Auto-Overwrite / Data Loss | Data loss caused by AIUnverified reportFirst-party report | |
| AI-050 | OpenAI Codex | A Whole machine or driveCodex deleted my entire Drive | Data loss caused by AIUnverified reportFirst-party report | |
| AI-051 | OpenAI Codex | C Multiple filesCodex deleted unstaged changes outside the requested edit scope. | Data loss caused by AIUnverified reportFirst-party report | |
| AI-008 | Google API key scope change for Gemini | A survey reporting that 2,863 keys, including those of financial institutions, were affected (cause/issue: a change that allowed existing Google API keys to use the Gemini API, with insufficient notice and permission control). | Secret & credential exposurePossibleResearch | |
| AI-024 | Claude Code / DataTalks.Club | S ProductionClaude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform | Data loss caused by AIPossibleAIID | |
| AI-052 | OpenAI Codex | A Whole machine or driveCodex deleted my entire dev drive | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-117 | Fujikura Composites | E 64 | Unauthorized access & data leakPossibleOfficial statement | |
| LEAK-118 | NS Bio Japan | E 40 | Unauthorized access & data leakConfirmedOfficial statement | |
| AI-053 | OpenAI Codex | A Whole machine or driveCodex wiped the whole drive by accident. Oops! | Data loss caused by AIUnverified reportFirst-party report | |
| AI-007 | Moltbook / AI agent social network | S ProductionRoughly 1.5 million authentication tokens, 30,000 email addresses and private messages were exposed (cause/issue: Supabase public key with RLS not configured). | Unauthorized access & data leakConfirmedResearch | |
| AI-054 | OpenAI Codex | F No confirmed damagecodex try to wipe out uncommited git diff | Data loss caused by AIUnverified reportFirst-party report | |
| AI-055 | OpenAI Codex | C Multiple filesData loss due to the harness not understanding symlinks and overwriting files (?) | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-020 | Yamamoto Kami Hososha "Package Shop JP" | C 3,973 | Unauthorized access & data leakPossibleOfficial statement | |
| AI-102 | Gemini CLI | D Single fileData Loss: replace Tool Causes Silent Truncation of Large Files | Data loss caused by AIUnverified reportFirst-party report | |
| LEAK-007 | cocoloni | Unauthorized access from outside occurred between November 27 and December 13, 2025, and email addresses and encrypted passwords were leaked. No trace of attempted unauthorized logins has been confirmed. | Unauthorized access & data leakConfirmedOfficial statement | |
| AI-056 | OpenAI Codex | Important Early Context Gets Deleted During Context Window Compaction | Session & history lossUnverified reportFirst-party report | |
| AI-057 | OpenAI Codex | HUGE Scope creep and destructive revert | Data loss caused by AIUnverified reportFirst-party report | |
| AI-058 | OpenAI Codex | C Multiple filesCodex VS Code extension/agent ran git restore despite explicit “never touch git” instruction, overwriting uncommitted work (data loss) | Data loss caused by AIUnverified reportFirst-party report | |
| AI-014 | OpenAI API key misuse: over $6,200 charged | The balance changed by over $5,400 from the previous day, and the actual charge was $6,200 or more. According to the poster, the credit was restored later (cause/issue: the API key distributed to Roo Code, Codex CLI and others may have leaked from the inside; the usage limit not forcing a stop also enlarged the damage). | Secret & credential exposureUnverified reportFirst-party report | |
| AI-059 | OpenAI Codex | /undo destructively interacts with git staging | Data loss caused by AIUnverified reportFirst-party report | |
| AI-023 | Kiro / AWS Cost Explorer | S ProductionKiro AI Coding Tool Was Reportedly Implicated in 13-Hour AWS Cost Explorer Outage in Mainland China | Tampering & unauthorized operationPossibleAIID | |
| AI-103 | Gemini CLI | Gemini CLI Agent Caused Irrecoverable Data Loss, Repeatedly Violated Instructions, and Failed Core Engineering Task Due to Environmental Mismanagement. | Data loss caused by AIUnverified reportFirst-party report | |
| AI-060 | OpenAI Codex | B Whole projectCRITICAL AI SAFETY ISSUE: AI model (codex-high) with shell access ran "rm -rf *" and deleted all files | Data loss caused by AIUnverified reportFirst-party report | |
| AI-061 | OpenAI Codex | C Multiple filesDeleted/Reset File With Uncomitted Changes w/o Backup, Unable to Restore | Data loss caused by AIUnverified reportFirst-party report | |
| AI-062 | OpenAI Codex | B Whole projectCodex agent deleted entire repo instead of specific folder after ZIP operation | Data loss caused by AIUnverified reportFirst-party report | |
| AI-063 | OpenAI Codex | E History onlyLoss of session data/messages | Session & history lossUnverified reportFirst-party report | |
| AI-064 | OpenAI Codex | Critical Bug: Agent executed destructive `rm -rf` command without safeguards | Data loss caused by AIUnverified reportFirst-party report | |
| AI-104 | Gemini CLI | Gemini CLI Becomes Unresponsive on API Error, Leading to Session and Data Loss | Session & history lossUnverified reportFirst-party report | |
| AI-025 | Nx npm packages | Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration | Supply chainPossibleAIID | |
| AI-105 | Gemini CLI | E History onlySilent data loss and conversation truncation in chat save/resume operations | Session & history lossUnverified reportFirst-party report | |
| AI-106 | Gemini CLI | C Multiple filesGemini agent performed a 'git reset --hard' without user confirmation, causing data loss of uncommitted files. | Data loss caused by AIUnverified reportFirst-party report | |
| AI-107 | Gemini CLI | Repeated Git Commit Errors and Data Loss | Data loss caused by AIUnverified reportFirst-party report | |
| AI-026 | Google Gemini CLI | C Multiple filesGoogle Gemini CLI Reportedly Deletes User Files After Misinterpreting Command Sequence | Data loss caused by AIPossibleAIID | |
| AI-028 | Replit | S ProductionLLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data | Data loss caused by AIPossibleAIID | |
| AI-027 | Amazon Q | Alleged Malicious Wiping Command Found in Amazon Q AI Assistant | Supply chainPossibleAIID | |
| AI-108 | Gemini CLI | C Multiple filesCritical Data Loss: Gemini agent overwrote user file instead of modifying it. | Data loss caused by AIUnverified reportFirst-party report | |
| AI-015 | Claude Code 1.0.35 settings file overwritten | D Single fileA user reported on X that the contents of their `~/.claude/settings.json` were lost (cause/issue: switching models with `/model` at startup was suspected of rewriting the settings file; this is a single-user report and no official confirmation from the product side has been found). | Session & history lossUnverified reportFirst-party report | |
| AI-065 | OpenAI Codex | E History onlyesc esc to "cancel" completely wipes chat history | Session & history lossUnverified reportFirst-party report | |
| AI-066 | OpenAI Codex | C Multiple filesInstead of editing my files, it deleted them | Data loss caused by AIUnverified reportFirst-party report | |
| AI-029 | Lovable | Jailbroken Lovable AI Allegedly Used to Generate and Host Phishing Pages, Steal Credentials, and Bypass Security | Abuse of AIPossibleAIID | |
| AI-010 | Rakuten Mobile fraudulent line contract case | S ProductionThree junior and senior high school students are suspected of fraudulently contracting 105 eSIMs using other people's accounts. The group as a whole reportedly resold about 2,500 lines and obtained the equivalent of about 7.5 million yen (cause/issue: repeated unauthorized logins with stolen IDs and passwords using an automation program created and sped up with generative AI). | Abuse of AIPossibleNews report | |
| AI-013 | ChatGPT-built card information collection program case | A high school student collected about 7,000 sets of card information, and fraudulent payments of at least about 1.3 million yen were substantiated (cause/issue: starting with no knowledge of how to write code, used ChatGPT to create a card number collection program in about a week). | Abuse of AIConfirmedNews report | |
| AI-009 | Generative-AI-built ransomware case: man in Kawasaki | F No confirmed damageCreated malware that encrypts files and demands a cryptocurrency transfer. No actual damage has been confirmed. Convicted in October 2024 (cause/issue: split the goal across several conversational generative AIs and combined the design information and code obtained). | Abuse of AIConfirmedNews report | |
| AI-031 | AI-hallucinated software packages | Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers | Supply chainPossibleAIID | |
| AI-032 | Microsoft AI research team | Reported Accidental Exposure of 38TB of Data by Microsoft's AI Research Team | Misdelivery & accidental exposurePossibleAIID | |
| AI-030 | ChatGPT / Samsung | ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes | Unauthorized access & data leakPossibleAIID | |
| UnknownLEAK-018 | Dorii Myujikku Paburisshingu "Otopuri" | The "ShopServe" platform operated by Estore Co., Ltd., which the shop uses, was accessed without authorization, and the shop's customer information was confirmed to have been leaked externally. The notice states that member IDs, passwords and email addresses were also leaked. | Supply chainConfirmedOfficial statement |
Showing 20 of 236 cases
How to read this database
- Each entry is based on the public statements, news articles or reports linked as evidence. Our service has not independently established these facts.
- Certainty reflects the wording of the source. Confirmed: the affected party or authorities have confirmed harm. Possible: a potential leak or harm has been disclosed or reported, or the case involves allegations. Under investigation: whether harm occurred or its extent is being investigated. Unverified report: a report by a user or other involved party without confirmation by a third party or the provider.
- Entries marked First-party report are user reports, such as those submitted to a product’s public issues. They do not mean the provider has acknowledged the report as fact.
- Dates are the publication or disclosure dates of the sources, and may differ from when the incident occurred. For entries sourced from AIID, the date is the incident date listed in AIID.
- Details may change with follow-up reports. Check the source links for the latest information.
Scope of coverage
AI development: Deletion, overwriting or destruction by AI coding agents; authentication or secret-handling flaws in AI-generated code or AI-built apps; supply-chain problems involving AI development tools or packages; attack code created with generative AI; and loss of history or data in AI development services. Deepfakes, general misinformation and autonomous driving are excluded.
Data leaks & unauthorized access: Cases publicly disclosed in Japan in 2026 whose details could be verified in statements by the affected party or a government agency.
Request a correction or removal
If an entry contains an error, or you would like to request a correction or removal, please contact us.
Contact us