Data Breaches and Unauthorized Access in Japan (2026)

This page collects 128 data breach and unauthorized-access cases disclosed in Japan in 2026: 90 cases of unauthorized access or data leaks, 19 supply chain cases (through contractors or external services), 10 ransomware cases, 5 cases of tampering or unauthorized operations and 4 cases of accidental disclosure. The content of every case was confirmed in a statement from the organization involved or from a government body.

Matching cases: 128Last updated:

Data breach scale rank

Incidents are grouped into seven levels by the order of magnitude of publicly disclosed counts. This is not a rating of companies or services.

Counts mix people, records and accounts, so comparisons are not exact. Dashed borders indicate incidents where a leak has not been confirmed.

Go to the list and filters
Count not disclosed (55 cases)
LEAN BODYWhite EssenceABAHOUSE INTERNATIONALPossibleYamato Transport "Kuroneko Daikin Atobarai Service"PossibleThe Japan TimesUnder investigationMoonstarPossibleKodansha BECKPossibleSammy Networks "777CON-PASS"PossibleLashinbang Co.,Ltd.Cards / bank accountsIdentity documentsPossibleSagawa Express Co., Ltd.PossibleShudo GakuenCards / bank accountsPossibleQUO CARD (LINE official account campaign system)PossibleShinano Mainichi Shimbun "Shinano Mainichi Shimbun Digital"Enoguya SankichiPasswordsCards / bank accountsvia Estore platformJapan Post "International Mail Inquiry Request Web Reception Service"Under investigationDaiko Printing "PhotoGoods"PasswordsCards / bank accountsPossibleRohto PharmaceuticalPossibleOdawara Engineering Co., Ltd.Azuma SangyoUnder investigationNihon TorekusuUnder investigationHalmek Holdings "HALMEK up"Under investigationTsuburaya Productions "ULTRA MART"REVISIO Inc.PossibleApplyNow "Interview Cloud" "ApplyNow" "ApplyNow Sign"PossibleEnshu Yumesaki Agricultural Cooperative (JA Enshu Yumesaki)Institute of Science TokyoPossibleEast Nippon Expressway Company Limited (Tokyo Gaikan Project website)Under investigationMandarake Inc.PossibleCo-op Yamaguchi "Co-op Yamaguchi LINE Mini App"PossibleShizugin TM SecuritiesCINRA, Inc. "CINRA JOB"Possible01BankNihon Business Data Processing CenterUnder investigationAll Nippon Airways Trading Co., Ltd. (Eraberu e-GIFT)PossibleCentral Consultant Inc.PossibleJapan Association for the 2025 World Exposition (subcontractor of outsourced work)PossibleGODAI KAIHATSU Corporation "Isabo Net"PasswordsPossibleShin FA ComPossibleWaiefushii "ADVAN"PasswordsCards / bank accountsvia Estore platformJA Raifu Kurieito Fukushima "E-gyu Shop"Under investigationvia Estore platformAmtransUnder investigationvia Estore platformDesignphilPasswordsCards / bank accountsvia Estore platformRemedikomuPasswordsvia Estore platformPRGRPasswordsvia Estore platformSen Corporation "Hai Cheese! Photo"First Co., Ltd. member pageCards / bank accountsPossibleSakata Seed Corporation (Brazilian subsidiary Sakata Seed Sudamerica LTDA.)PossibleNihon Gotochi Character KyokaiACT1000PasswordsPossibleDaitsu ShisutemuPasswordsPossibleSuperioru AdobantekkuPasswordsPossibleOfisu InteguraruPasswordsPossibleKyushu UniversityPossiblecocoloniPasswordsDorii Myujikku Paburisshingu "Otopuri"Passwordsvia Estore platform

Breakdown

By incident type
GroupCases
Unauthorized access & data leak90
Supply chain19
Ransomware10
Tampering & unauthorized operation5
Misdelivery & accidental exposure4
By month
GroupCases
Oct 202619
Sep 202643
Aug 202633
Jul 202615
Jun 20269
May 20261
Apr 20261
Mar 20262
Feb 20262
Jan 20262
Unknown1

Ransomware cases: confirmed damage and cases that remain at the possibility stage

We classify 10 cases as ransomware, and the level of certainty differs by company. Nihon Gotochi Character Kyokai announced that its NAS was infected and encrypted, but says no external leak of information has been confirmed. At Anabuki Housing Service, many files were taken from file servers, and the number of personal data records that may have leaked was fixed at 207,773.

GEX Corporation says 77,619 records with names, addresses and other data were viewable by the intruder, and no external leak or misuse has been confirmed. ASKUL Corporation newly identified about 600,000 records but no actual leak has been confirmed, and in the Meitetsu Kyosho case about 4,000 records may have been leaked, with no specific leak confirmed.

The affiliated companies sharing a work management system say employee data may have been viewed or obtained in the encryption damage of May 1, 2026, and Kyushu University says it cannot rule out that the names of 43 patients and surgery video data were leaked.

All matching cases

Filter incidents

Showing 128 of 128 incidents

Data Breaches and Unauthorized Access in Japan (2026)
DateTargetSummaryClassificationSource links
LEAK-115GMO Research & AI "infoQ"A Up to 948,498 recordsThe survey site infoQ was breached by exploiting a software vulnerability, and from October 2, 2026, up to 948,498 members' records were taken out. Points worth 2,869,500 yen across 611 cases were fraudulently exchanged for Amazon gift codes.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-116Mr Max HoldingsS Up to 1,735,154 peopleThe servers for the MrMax app and online store were accessed without authorization, and it was confirmed that member IDs, names, email addresses and phone numbers of up to 1,735,154 members registered as of October 3, 2026 were partly leaked.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-004LEAN BODYUnauthorized access exploiting a vulnerability in Metabase, a tool used for internal data analysis, resulted in customer information such as email addresses and encrypted passwords being obtained for about 440,000 accounts, including those of former members.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-006White EssenceA vulnerability in the reservation site program was used as a foothold for unauthorized access to the core system, and data of about 1.05 million accounts, including names, addresses, email addresses and encrypted passwords, was taken out.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-111Daiwa SecuritiesA About 220,000 recordsThe server of Scala Communications, the provider of an external service used for inquiry management, was accessed without authorization from October 2 to 3, 2026, and about 220,000 records, including names and account numbers of about 110,000 customers, may have leaked.
Supply chainPossibleOfficial statement
LEAK-112Daiki Suisan "Daiki Suisan Official App"A 174,933 peopleThe official app's system was accessed without authorization, and the company announced it cannot rule out that names, phone numbers, addresses and other data of 174,933 users registered from November 2024 to September 15, 2026, including former members, leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-113Monogatari Corporation "Yakiniku King"S 10,788,963 recordsThe membership management system of the Yakiniku King official app was accessed without authorization, and a leak was confirmed on October 3, 2026. Member numbers, names, email addresses and phone numbers were leaked for 10,788,963 of 10,808,784 registered users.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-109Nikkei Inc.C 1,646 peopleEmployees' Google Workspace accounts were illegally logged into from late July 2026, and the email addresses and names of 1,646 people, including employees and business partners, may have leaked. It came to light in early August through a notice from Google.
Unauthorized access & data leakPossibleOfficial statement
LEAK-106ABAHOUSE INTERNATIONALUnauthorized access by an overseas third party is presumed to have occurred from late on September 27 to September 28, 2026, and names, addresses, order information and other data may have leaked from the database holding member and e-commerce order information. The number of affected records was not disclosed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-114Recruit "Studysapuri"C 3,687 recordsOn September 30, 2026, it came to light that a third party may have checked whether specific email addresses were registered by exploiting a flaw in a feature's specification. 3,687 email addresses may have been identified. Leakage of names, passwords and other data has not been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-084Yamato Transport "Kuroneko Daikin Atobarai Service"The "Kuroneko Daikin Atobarai Service" was accessed without authorization by a third party on September 28, and the investigation found that names, addresses, phone numbers, billing amounts and other data of some users, information on some partner merchants, and names of staff in charge may have been leaked. Card information and passwords are not included.
Unauthorized access & data leakPossibleOfficial statement
LEAK-085The Institute of Energy Economics, JapanD 759 recordsA detailed investigation into the unauthorized access to the Microsoft 365 accounts of six staff members confirmed the leak of 13 items of passport information and found that 759 email addresses and other data may have been leaked. No public disclosure to an unspecified audience or misuse has been confirmed.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-104Dai-ichi Life Group / Dai-ichi Life InsuranceA About 120,000 peopleOn September 24, 2026, the two companies detected unauthorized access to their employee HR system and announced that personal information of about 120,000 current and former employees may have been viewed and leaked. No unauthorized access to customer information was confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-105The Japan TimesThe company announced that part of a server managed by a group company was accessed without authorization. Whether information leaked, the scope of impact and the cause are under investigation with external specialists, and no impact has been confirmed on its digital edition, subscriber databases or payment system.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-107MoonstarThe company announced that an external intrusion into its system server may have led to the viewing or acquisition of online store customers' names, addresses, phone numbers, email addresses and past order information. No number of affected records was given.
Unauthorized access & data leakPossibleOfficial statement
LEAK-108Kodansha BECKAn employee's email account formerly used at Kodansha BC was accessed without authorization, and 50 suspicious emails were sent externally on September 14, 2026. Traces show mail data was obtained, so personal information stored in the account may have leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-110Sammy Networks "777CON-PASS"The server of the 777CON-PASS app it operates was accessed without authorization, and user data was targeted on September 25, 2026. Gender, date of birth, profile photos, action areas and other data may have leaked. The number of affected users is under investigation.
Unauthorized access & data leakPossibleOfficial statement
LEAK-102Lashinbang Co.,Ltd.The company's service was accessed without authorization from September 14 to 16, 2026, and names, ID document types and numbers, bank account details entered at buyback and other data may have leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-103Japan Atomic Energy AgencyD 175 peopleOn September 25, 2026, 2,419 files were illegally downloaded from a research support site for the JRR-3 research reactor, which runs on a cloud platform, and leakage was confirmed of 367 files covering 175 users, including ID images and health examination results.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-099Benefit One Inc.B 13,460 peopleA defect in the Benefit One Platform survey function showed employee information of other companies and organizations when survey results were downloaded. 13,460 people at 2,322 companies and organizations are covered; one contact person downloaded the data.
Misdelivery & accidental exposureConfirmedOfficial statement
LEAK-100Sagawa Express Co., Ltd.Unauthorized access to the website's package inquiry service was confirmed on September 30, 2026, and personal information of shippers and recipients, fare-contract customers and Smart Club members may have leaked. The number is under investigation.
Unauthorized access & data leakPossibleOfficial statement
LEAK-101G-PLAN INC. (G Point)B Up to about 70,000 recordsAn anomaly was detected in the G Point system on September 25, 2026, and unauthorized access from outside was found. Up to about 70,000 member identifiers may have leaked, and the system and related services are suspended.
Unauthorized access & data leakPossibleOfficial statement
LEAK-131Shudo GakuenOn September 26, 2026, unauthorized third-party access to a server managed by the school corporation was confirmed. Account information of business partners and names, addresses, phone numbers and account details of staff, some students and external lecturers may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-074Seicomart "Seicomart App"A About 570,000 accountsA third party accessed the member information server via the Seicomart App server without authorization, and names, addresses, phone numbers and other data of about 570,000 accounts may have been viewed. Passwords and purchase history are stated not to have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-075eplusC 1,463 recordsThe system managing refund information for the e-ticket service "Smachike" was accessed without authorization on September 11-12, and email addresses, names, bank transfer account details and similar data of 1,463 customers who had applied for refunds were leaked. Credit card information was not included.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-083Japan Post "Yubinkyoku App"E 19 peopleThe Yubinkyoku App was accessed without authorization from outside, and customer information of 19 people (69 items), including Yu-ID member information, address books and shipping label data, was improperly obtained. Emergency maintenance was carried out on September 25 and service resumed on September 26.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-097QUO CARD (LINE official account campaign system)The campaign system of the LINE official account was accessed without authorization, and LINE display names and campaign winning information of some users may have been viewed or leaked. Affected people and scope are under investigation.
Unauthorized access & data leakPossibleOfficial statement
LEAK-081Shinano Mainichi Shimbun "Shinano Mainichi Shimbun Digital"Unauthorized access from outside to the Shinmai point exchange system of "Shinano Mainichi Shimbun Digital" was found on September 7, and some history data was temporarily erased. No leak of personal information has been confirmed, the data has been restored, and point balances were not affected.
Tampering & unauthorized operationConfirmedOfficial statement
LEAK-098Shueisha Inc. (HAPPY PLUS COMMUNITY)C 2,835 peopleThe bloggers' information management system was accessed without authorization on September 9, 2026; information on 2,835 registrants, 11,237 sent emails and a 10,780-entry client list may have been viewed or obtained, and a leak was determined.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-071Starts Publishing "OZmall"A Up to 447,610 peopleA large volume of unauthorized access from overseas hit Starts Publishing's "OZmall" site, and the email addresses of up to 447,610 members, plus names and addresses (down to prefecture) of some people, may have been viewed. Credit card information is stated to be out of scope.
Unauthorized access & data leakPossibleOfficial statement
LEAK-073Tokyo Metro "Metro Point Club"B About 59,000 recordsA third party accessed the Metro Point Club member services without authorization, and about 59,000 email addresses may have been viewed or obtained from a server holding addresses for which delivery had been suspended. The server is stated to hold no member information other than email addresses.
Unauthorized access & data leakPossibleOfficial statement
LEAK-019Enoguya SankichiThrough unauthorized access to the e-commerce system "ShopServe" of Estore Co., Ltd., which the shop uses, it was found on September 25, 2026 that the shop's customers' information was also subject to the leak. This includes names, addresses, email addresses, encrypted passwords and part of the card information.
Supply chainConfirmedOfficial statement
LEAK-072Nippon Rent-A-Car Service "Nippon Rent-A-Car App"E 41 peopleA third party accessed the Nippon Rent-A-Car App system without authorization, and the names, contact details and usage history of 41 members may have been viewed. For members who registered driver's license details and similar data, that information is also in scope.
Unauthorized access & data leakPossibleOfficial statement
LEAK-003Times Mobility 'Times Car'S About 6,600,000 accountsUnauthorized access to the Times Car web system led to the acquisition of about 6.6 million accounts of members and former members, including names, addresses, driver's license information and identity document data. Passwords were stored in a non-recoverable form.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-067Japan Post "International Mail Inquiry Request Web Reception Service"At around 15:00 on September 25, 2026, a possible unauthorized access from outside was found on the server used by the international mail inquiry request web reception service. The cause and scope are under investigation, and the service has temporarily stopped accepting requests.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-096LEGOLAND Japan (LEGOLAND Japan Hotel)C 1,557 recordsUnauthorized access occurred on the external booking platform (Amadeus IT Group) used by the hotel's official reservation site, and names, email addresses and phone numbers in 1,557 reservations may have been affected.
Supply chainPossibleOfficial statement
LEAK-130Fines Inc.S 1,536,322 recordsOn September 22, 2026, unauthorized third-party access to its reservation system was confirmed. The scope covers reservers' names, phone numbers, email addresses, reserved stores and dates, with 1,536,322 records in scope. A detailed investigation is under way with lawyers.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-095Nichirei CorporationB 43,709 recordsIn the cyberattack behind the July 13, 2026 system outage, leakage of personal information stored on some servers was confirmed: 3,308 items for recipients of deliveries it handled, 6,849 for staff of business partners, and 43,709 for employees, their families and job applicants.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-002Helpfeel 'Gyazo'S About 23,620,000 recordsThe company confirmed that on September 11, 2026 a vulnerability in the image upload server was exploited, and about 23.62 million user records and about 490 million image metadata records were leaked.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-027Daiko Printing "PhotoGoods"A vulnerability and the file upload function of the e-commerce site it operates were abused, and from August 6 to September 11, 2026 a program that captures card information on the payment screen was installed. Card information, names, addresses, email addresses and other data may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-061Rohto PharmaceuticalA possible unauthorized access to systems used for mail-order sales was identified on September 10. The investigation found that call-recording data and related information in the customer-service system, and information in the customer management system, may have been obtained by a third party. The scope and number of records are under investigation.
Unauthorized access & data leakPossibleOfficial statement
LEAK-078Ainokaze Toyama Railway "Ichiman Sanzenjaku Monogatari"C 1,409 peopleThe seat management system of the sightseeing train "Ichiman Sanzenjaku Monogatari" was accessed without authorization multiple times from September 2, and the names, addresses, phone numbers and email addresses of 1,409 customers may have been leaked. Several reservations had been cancelled unintentionally.
Unauthorized access & data leakPossibleOfficial statement
LEAK-128Odawara Engineering Co., Ltd.A third party had unauthorized access to the email account of an employee seconded to the German subsidiary from March 27 to August 31, 2026, and viewing of about 3,500 emails was confirmed. The third party also sent payment-instruction emails impersonating the employee, causing financial losses to some business partners.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-048Harada Sangyo Co., Ltd. "Beer no Engawa"F 9 peopleA vulnerability was exploited to obtain administrator privileges, and a malicious program ran from August 11 to 14. Card and other data entered on the order confirmation screen by 9 customers may have been leaked, of whom 4 completed payment and 5 did not.
Unauthorized access & data leakPossibleOfficial statement
LEAK-077Nihon UniversityF 5 peopleThe email accounts of five faculty members were taken over using credentials believed to have been stolen through phishing or similar means, and 1,333 spam emails were sent inside and outside the university. Some data may have been accessed, but no trace of large-scale extraction has been found.
Tampering & unauthorized operationConfirmedOfficial statement
LEAK-079Azuma SangyoAzuma Sangyo's official website was accessed without authorization by a third party exploiting a website vulnerability. The information concerned is limited to customer information obtained via the contact form, the timing and scope are under investigation, and no external impact has been confirmed.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-054Digital Agency "Government Solution Service (GSS)"A About 246,000 recordsA third party broke in by exploiting a vulnerability in a VPN device, and about 246,000 items of personal information, including names and email addresses of staff of ministries and agencies and people involved in their work, may have been leaked. It does not include My Number or similar data; the activity was detected on June 25 and the intrusion identified on July 9.
Unauthorized access & data leakPossibleOfficial statement
LEAK-064Nihon TorekusuParent company Kyokuto Kaihatsu Kogyo announced that a system failure caused by unauthorized access occurred at its subsidiary Nihon Torekusu on September 8. Online ordering, the dealer parts-order system and email exchange with customers and partners are suspended, and no external leak of personal or customer data has been confirmed.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-068Halmek Holdings "HALMEK up"The ID and password of one employee were stolen, and unauthorized access to the administration screen of the website HALMEK up was confirmed on September 9, 2026. The current investigation has found no log evidence of access to customer management information, and details are still being investigated.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-070Tsuburaya Productions "ULTRA MART"The digital ticket system (mogily) used for lottery sales at Tsuburaya Productions' "ULTRA MART" was accessed without authorization by a third party, causing inconsistencies in lottery result data and changing some winners to a losing display. No leak of personal information has been confirmed.
Supply chainConfirmedOfficial statement
LEAK-076mogily digital ticket systemD 133 peopleThe mogily management system was accessed without authorization from outside on September 9-10, and lottery results for 133 customers of one client, who had actually won, were rewritten to a losing status. No leak of personal information was confirmed, and the statuses are stated to have been restored.
Tampering & unauthorized operationConfirmedOfficial statement
LEAK-050REVISIO Inc.Malware infection of one business PC used by an officer or employee was confirmed on March 20. No remote connection from outside or unauthorized server access was found, but a leak of personal information from business cards stored on the PC cannot be ruled out.
Unauthorized access & data leakPossibleOfficial statement
LEAK-066Fuso DentsuB 26,489 recordsA shared folder in cloud storage was accessed without authorization through a third party's misuse of credentials, and 26,489 items of personal information, including names, addresses and phone numbers of business partners, may have been leaked. No payment-related information was included, and no secondary harm has been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-063ApplyNow "Interview Cloud" "ApplyNow" "ApplyNow Sign"A vulnerability in a data analysis tool used by the company was exploited, and traces of unauthorized access to part of the recruitment-management services' database were found. Applicant and corporate user information, and for the electronic employment contract service, contractor information including individual numbers and bank account details, may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-065Enshu Yumesaki Agricultural Cooperative (JA Enshu Yumesaki)On August 24, 2026, the website's program was tampered with through unauthorized access and could no longer be updated, so the site was temporarily closed. Because no personal information is stored on the server, no leak of personal information has been confirmed.
Tampering & unauthorized operationConfirmedOfficial statement
LEAK-062Kyoto Purple Sanga (Kyoto Sanga F.C.)B 15,612 peopleOn September 2, 2026, a file containing names, addresses, contact details and other data of 15,612 fan club members was attached by mistake to an email sent to a business partner. Two of the 11 recipients opened it, and it has been deleted on the partner's side. No payment information was included, and no secondary leak has been confirmed.
Misdelivery & accidental exposureConfirmedOfficial statement
LEAK-052Institute of Science TokyoThe university's information infrastructure was accessed without authorization, and the names, addresses and email addresses of people enrolled at the time of the merger of the two former universities, among others, may have been leaked. The scope is under investigation, and no leak of hospital patient information has been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-051East Nippon Expressway Company Limited (Tokyo Gaikan Project website)Suspected unauthorized access by a third party was identified on the Tokyo Gaikan Project website; its publication has been suspended and the cause is under investigation. No leak of personal information has been confirmed.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-059Seibu Railway "Seibu Tabisuru Resutoran 52-seki no Shifuku"D About 500 peopleDue to a configuration error when a staff information-sharing feature was added to the reservation site, encoded information including personal data was viewable from outside from January 9, 2025 to August 27, 2026. Names, contact details and other data of about 500 people were affected, including special-needs information for about 30.
Misdelivery & accidental exposureConfirmedOfficial statement
LEAK-049Mitsui Fudosan Co., Ltd.B Up to 36,000 recordsUnauthorized access was confirmed on August 28, and information in some systems may have been viewed using misused credentials. Up to 19,000 records of officers and employees (names, email addresses and so on) and up to 36,000 records of outside parties (email addresses and display names) are covered. No leak of business information or passwords has been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-060Chiba Prefecture "Inochi no Nigiwai Chosadan" (Biodiversity Center website)C 1,963 peopleOn the Biodiversity Center website, the page managing names, addresses, phone numbers and other data of 1,963 survey-team members was accessed without authorization, and a page not normally linked was inserted in the early hours of August 27. The site is offline, no leak has been confirmed so far, and an investigation will be carried out.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-127TRUNK Co., Ltd.D 424 recordsAn employee's email account was accessed without authorization, and 424 records including names, addresses, email addresses and workplaces were leaked externally. The third party also used the account to send suspicious emails impersonating the company and its employee.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-094Mandarake Inc.Unauthorized access to the company's servers was confirmed on August 27, 2026, and names, addresses, phone numbers and email addresses of mail-order customers who ordered by 6 a.m. on August 28 may have leaked. Mail-order and auction services were suspended.
Unauthorized access & data leakPossibleOfficial statement
LEAK-005kindalA 136,464 peopleA staff account on the EC platform was accessed without authorization after its credentials were stolen by phishing, and customer information was bulk-exported twice on August 23, 2026. Data of 136,464 customers, including names, addresses and email addresses, may have been leaked.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-056Co-op Yamaguchi "Co-op Yamaguchi LINE Mini App"On August 27, 2026, a third party gained unauthorized access to the database of the LINE mini app, which is operated by an outsourced vendor, and all data was deleted. Service was restored from backup the same day, and the cooperative says it cannot rule out leakage of names, addresses, phone numbers and email addresses.
Unauthorized access & data leakPossibleOfficial statement
LEAK-058Shizugin TM SecuritiesUnauthorized access to customers' securities accounts and unauthorized trades, believed to stem from phishing and similar methods, were confirmed. For losses where third parties traded securities using customers' assets, the firm plans to examine each case and provide certain compensation according to individual circumstances.
Tampering & unauthorized operationConfirmedOfficial statement
LEAK-093Treasure Factory Co., Ltd. (subsidiary Kaindoru)A 136,464 peopleA staff account on the e-commerce platform used by the subsidiary Kaindoru's online store was accessed without authorization on August 22, 2026, and customer data was bulk-exported. 136,464 customers are affected.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-126CoronaB Up to 35,000 peopleA third party accessed an external cloud service used to manage construction information, and names, addresses and construction-related documents of up to 35,000 customers may have been leaked. It came to light on August 24, 2026, through information from a third party.
Supply chainPossibleOfficial statement
LEAK-055CINRA, Inc. "CINRA JOB"On August 18, 2026, credentials for the cloud environment were obtained by a third party, who accessed the member database and its backups. Because no records exist to confirm whether data was viewed or taken, the company says the personal information of members, including former members, may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-057TsunaguD 157 recordsOn the corporate website, an administrator account was created illicitly and a backdoor and other malicious programs were installed, and leakage of 157 contact form submissions (names, email addresses, addresses, phone numbers, etc.) cannot be ruled out. The initial intrusion route has not been identified.
Unauthorized access & data leakPossibleOfficial statement
LEAK-092Zurich Insurance Company LtdC Up to 1,668 peopleA vulnerability was found in Z-Dash, a system for uploading dashcam data, and it had been accessed without authorization on April 1 and 6, 2026. Case numbers, names and email addresses of up to 1,668 customers may have leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-12501BankOn August 17, 2026, unauthorized third-party access to its systems was detected, and it was confirmed that customer identifiers used by the system and email addresses were stolen and leaked. The leak covers up to 100 companies, and the affected customers have not been identified.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-046Tokai University Yamanakako Seminar HouseD 274 peopleTampering with the reservation website was confirmed on April 22, and unauthorized access from outside is highly likely. A leak of the accommodation reservation information of 274 people stored on the server cannot be ruled out. No misuse has been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-014KDDI Web Communications 'CPI'S 1,250,543 recordsUnauthorized access to the KDDI mail system leaked 1,250,543 mail account records of the CPI rental server service. For the Business Standard and KWC Mail plans, passwords were also affected.
Supply chainConfirmedOfficial statement
LEAK-053Nihon Business Data Processing CenterUnauthorized access to the company's systems was confirmed at 11:53 on August 20, 2026, and the internal network was cut off. The cause and scope are being investigated with an external specialist, and the notice does not state whether any information was leaked.
Unauthorized access & data leakUnder investigationOfficial statement
LEAK-091All Nippon Airways Trading Co., Ltd. (Eraberu e-GIFT)The management system of the corporate digital gift service Eraberu e-GIFT was accessed without authorization on August 11-12, 2026, and part of contract company contacts' names and email addresses may have leaked. Unauthorized gift exchanges were also confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-047Kankyo Kiki Co., Ltd. "Mushitaiji.com"E 15 peopleA vulnerability was exploited to obtain administrator privileges, and a malicious program placed on the payment page ran from August 11 to 18. Information on 15 people may have been leaked, 6 of whom may have had card data taken. Whether it was actually sent out cannot be confirmed from the records.
Unauthorized access & data leakPossibleOfficial statement
LEAK-044Central Consultant Inc.A possible unauthorized access to its corporate website was identified, and the database storing the company names, names, contact details and inquiry contents submitted through the contact form during the period may have been viewed or obtained. No leak itself has been confirmed and the investigation continues.
Unauthorized access & data leakPossibleOfficial statement
LEAK-090Japan Association for the 2025 World Exposition (subcontractor of outsourced work)At a subcontractor of outsourced work, phishing led to unauthorized access to Microsoft 365, and emails containing personal information of people involved and event performers may have been affected. It occurred on May 13, 2026.
Supply chainPossibleOfficial statement
LEAK-008KDDIS 12,231,954 peopleThe Personal Information Protection Commission issued guidance to KDDI over a leak of IDs and passwords from an ISP mail system through a vulnerability exploit. The number of affected persons is 12,231,954, of whom 7,616,173 had passwords stored in plain text.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-082SAKURA internet Inc.S 1,360,563 accountsWhile investigating unauthorized access to its rental server service, the company found that its sales management system, which holds contract information, may also have been accessed, and member information of up to 1,360,563 accounts may have been viewed or obtained. For 30 of them, hashed passwords may also have been accessed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-124GEX CorporationB 77,619 recordsIn February 2026, a server managing personal information was accessed by ransomware attackers, leaving 77,619 records with names, addresses and other data, plus 1,360 name-only records, viewable by the intruder. No external leak or misuse has been confirmed.
RansomwarePossibleOfficial statement
LEAK-089VOISING Inc.A Up to about 170,000 peopleAn external party gained unauthorized access to the BI tool the company uses from August 10, 2026, and data was downloaded on August 16. Names, purchase history and other data leaked; up to about 170,000 people may be affected (provisional).
Unauthorized access & data leakConfirmedOfficial statement
LEAK-026GODAI KAIHATSU Corporation "Isabo Net"The server of "Isabo Net" managed by the company was subjected to unauthorized access and attack on January 26, 2026, and members' names, email addresses, passwords, company names, addresses and phone numbers may have been viewed or obtained.
Unauthorized access & data leakPossibleOfficial statement
LEAK-043Innovation Inc.B 62,691 peopleA third party misused GitHub credentials written directly in a configuration file, and the leak of customer information on 62,691 people stored in repositories was confirmed. No breach of the production database and no misuse has been confirmed.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-087Digital AgencyD 150 peopleWhen a login history file from the national qualification information system was sent to another ministry, ambiguous procedure wording led to the inclusion of names and other data of 150 staff of other qualification bodies. It came to light on July 6, 2026.
Misdelivery & accidental exposureConfirmedOfficial statement
LEAK-088Japan Science and Technology AgencyB About 18,000 recordsUnauthorized access by a third party may have leaked about 18,000 items of email information stored in the mailboxes of 12 officers and staff. It was found on July 28, 2026, through information from an outside organization.
Unauthorized access & data leakPossibleOfficial statement
LEAK-036Shin FA ComA third party stole account credentials and intruded into the network, and files containing some business partners' employees' names, employers, departments and transaction-related information may have been viewed or obtained. No secondary damage has been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-029Waiefushii "ADVAN"Estore Co., Ltd., the system provider of the company's online shop, was accessed without authorization, and customer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs, encrypted passwords and part of the card information.
Supply chainConfirmedOfficial statement
LEAK-030JA Raifu Kurieito Fukushima "E-gyu Shop"Estore Co., Ltd. announced that buyer and member information leaked from "ShopServe", which the shop uses. Whether the shop's customers are included is under confirmation, and members are advised to change their passwords.
Supply chainUnder investigationOfficial statement
LEAK-031AmtransEstore Co., Ltd. announced that buyer information leaked through unauthorized access to the mail-order system "ShopServe", which the company uses. The company cannot confirm whether its own customers are affected and advises members to change their passwords.
Supply chainUnder investigationOfficial statement
LEAK-016DesignphilThe Shop Serve cart system used by Midori Online Store and others suffered unauthorized access, leaking names, addresses, email addresses, encrypted passwords and partial card data. The scope of those affected is under investigation.
Supply chainConfirmedOfficial statement
LEAK-017RemedikomuThe shopping cart system Shop Serve used by the store suffered unauthorized access, leaking purchaser information of the store, including names, addresses, email addresses, member IDs and encrypted passwords. Card data was kept on a separate server and was not affected.
Supply chainConfirmedOfficial statement
LEAK-028PRGR"ShopServe" of Estore Co., Ltd., used by the company's online shop, was accessed without authorization, and buyer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs and encrypted passwords.
Supply chainConfirmedOfficial statement
LEAK-015Estore 'Shoppu Sabu'S 8,853,839 recordsFrom May 21 to August 1, 2026, a third party ran a malicious program on Shop Serve servers and sent purchaser information outside. The announced count is 8,853,839 records, including member IDs, encrypted passwords and partial card data.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-042Sen Corporation "Hai Cheese! Photo"In unauthorized access from the evening of June 4 to the morning of June 5, the names, addresses, phone numbers and organization names of purchasers and recipients tied to some orders were confirmed leaked. The count was reported to the Personal Information Protection Commission but is withheld from publication.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-045EPARK Relax & Este "PeakManager"S About 33,000,000 recordsUnauthorized access to a database of its reservation and customer management service, and deletion of customer information, were confirmed on July 27; about 33 million records including names, birth dates, addresses, contact details and encrypted passwords may have been leaked. The number of people affected is under investigation.
Unauthorized access & data leakPossibleOfficial statement
LEAK-037ASKUL CorporationA About 600,000 recordsContinuing its investigation of the ransomware attack of October 19, 2025, the company newly identified about 600,000 personal data records that cannot be ruled out as having been leaked externally. The data are names, addresses, phone numbers and email addresses; no actual leak or misuse has been confirmed.
RansomwarePossibleOfficial statement
LEAK-038TV Asahi Mediaplex Inc.C 2,786 recordsIn an unauthorized access to its server confirmed on April 28, personal data of 1,343 employees (including former), 2,786 job applicants and 414 individual business partners has been or may have been leaked, in some cases including My Number and bank account numbers.
Unauthorized access & data leakPossibleOfficial statement
LEAK-039C Connect Co., Ltd. "Ink Kakumei"B 24,166 peopleThe payment application was tampered with, and card details and personal information entered by 24,166 customers from April 8 to December 10, 2025 may have been leaked. Possible fraudulent use of some cards was also identified.
Unauthorized access & data leakPossibleOfficial statement
LEAK-040Meitetsu Kyosho (customer information of Chuden Fudosan)C About 4,000 recordsTraces of unauthorized access by ransomware were found on a server of Meitetsu Kyosho, a parking management contractor, and information on about 4,000 monthly parking contract holders from July 2018 to October 2024 may have been leaked. No specific leak has been confirmed.
RansomwarePossibleOfficial statement
LEAK-080Murauchi.comS 7,716,811 recordsStarting from a vulnerability in one of its web systems, multiple systems were accessed without authorization, and customer names, addresses, phone numbers, email addresses, dates of birth and genders, 7,716,811 records in total, were taken outside the company. Credit card information and passwords are not included.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-033media4u Inc. SMS sending systemB 95,412 recordsThe SMS sending system was accessed without authorization on June 24, 2026, and the account management list of the management console (95,412 records) was leaked. 280 unauthorized SMS messages sent by a third party were also confirmed.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-034First Co., Ltd. member pageThrough unauthorized access exploiting a vulnerability or similar flaw in the system managing the member page, members' names, addresses, contact details, workplaces, debt status, bank account information and login credentials may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-035Sakata Seed Corporation (Brazilian subsidiary Sakata Seed Sudamerica LTDA.)Unauthorized access to a server of its Brazilian consolidated subsidiary was detected on June 27, and an investigation concluded that some information was accessed and may have been leaked. No damage causing business suspension and no impact on other group companies has been confirmed.
Unauthorized access & data leakPossibleOfficial statement
LEAK-010Nifty '@nifty Mail'S 2,248,708 peopleA vulnerability in third-party software in the KDDI-provided mail platform was exploited, leaking email addresses of 2,248,708 persons, of whom 1,862,462 also had mail passwords leaked.
Supply chainConfirmedOfficial statement
LEAK-011Chubu Telecommunications (ctc)A 727,176 peopleThe KDDI mail system underlying the Commufa Hikari and Business Commufa mail services suffered unauthorized access, leaking email addresses of 727,176 persons, of whom 724,344 also had mail passwords leaked.
Supply chainConfirmedOfficial statement
LEAK-012STNet 'Pikara'A 456,159 recordsA vulnerability in the KDDI mail system used by mail services such as Pikara Hikari was exploited, leaking 456,159 email address and password sets of 397,152 customers. Access to STNet's data took place from June 14 to 17.
Supply chainConfirmedOfficial statement
LEAK-013JCOMS 2,473,191 peopleA vulnerability in the KDDI mail system was exploited, leaking email addresses of 2,473,191 J:COM NET users and 118,752 users of mail services for partner cable operators. Password leaks were confirmed for 1,257 of the latter.
Supply chainConfirmedOfficial statement
LEAK-025Kaga Solution Network "Akademiko Navi"A Up to about 170,000 recordsUnauthorized access to the sales site operated by the company was confirmed on June 22, 2026, and up to about 170,000 records registered between October 2021 and April 2026, including names, addresses, email addresses and encrypted passwords, may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-032Aflac Life Insurance Japan Ltd.S About 4,400,000 peopleSystems including the policyholder-only site were accessed without authorization, leaking policyholder names, addresses and policy numbers of about 4.4 million people and information on about 40,000 agencies. About 220,000 of them include premium transfer account information, and the company is coordinating with financial institutions.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-123Nihon Gotochi Character KyokaiA data-storage NAS was infected with ransomware and its data was encrypted. It holds contact data of character-related parties who took part in past events; no external leak has been confirmed so far.
RansomwareConfirmedOfficial statement
LEAK-009BIGLOBE 'BIGLOBE Mail'S 5,016,432 peopleA vulnerability in third-party software in the KDDI-developed mail platform was exploited, leaking BIGLOBE email addresses and BIGLOBE IDs of 5,016,432 persons, of whom 4,631,775 also had passwords leaked.
Supply chainConfirmedOfficial statement
LEAK-021ACT1000On May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained.
RansomwarePossibleOfficial statement
LEAK-022Daitsu ShisutemuOn May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained.
RansomwarePossibleOfficial statement
LEAK-023Superioru AdobantekkuOn May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained.
RansomwarePossibleOfficial statement
LEAK-024Ofisu InteguraruOn May 1, 2026, the server of a work management system was accessed without authorization, and encryption damage believed to be caused by ransomware occurred. Employee names, email addresses, passwords, dates of birth and other data managed in the system may have been viewed or obtained.
RansomwarePossibleOfficial statement
LEAK-122Kyushu UniversityOn May 25, 2026, a terminal managed by a research laboratory was attacked and appears to have been infected with ransomware. Names and surgery video data of 43 Kyushu University Hospital patients stored on it may have been leaked.
RansomwarePossibleOfficial statement
LEAK-121Fujita Health University HospitalC 1,365 recordsA nurse's personal laptop, on which patient data had been stored against hospital rules, fell victim to a tech-support scam and was remotely controlled. Names, diagnoses, test data and other information of 1,365 kidney-disease-related patients may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-119Anabuki Housing ServiceA 207,773 recordsRansomware damage was confirmed on February 3, 2026. Many files were taken from file servers, and the investigation fixed the number of personal data records that may have leaked at 207,773. The cause was a vulnerability in a group company's network device.
RansomwareConfirmedOfficial statement
LEAK-001Nirinkan Yellow Hat 'Nirinkan App'S 3,179,454 peopleThe final report states that unauthorized access abusing the app's API to the members-only server obtained data on 3,179,454 point, mobile and app members, including names, addresses, email addresses and app passwords.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-086Mynavi CorporationB 74,224 recordsUnauthorized access to a cloud service the company uses may have exposed personal information: 74,224 general users, 21,609 corporate contacts and 15,672 employees. An anomaly was detected in December 2025.
Unauthorized access & data leakPossibleOfficial statement
LEAK-120zetton Inc.B 18,553 recordsMalware on a PC at the Gifu store 'forty three' led to theft of credentials for two old mail accounts, followed by unauthorized logins from overseas. Personal information of 18,553 reservation customers, business partners and others may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-117Fujikura CompositesE 64 peopleUnauthorized access to specific addresses on the mail server was found on August 25, 2025, and the investigation showed two employee accounts were affected. Personal information of 64 employees and business partners' email addresses may have leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-118NS Bio JapanE 40 recordsThe online shop's administrator account ID and password were stolen through phishing and used for unauthorized access, and information on 40 records of new customers, including names, addresses, phone numbers and email addresses, was leaked. Payment information was not included.
Unauthorized access & data leakConfirmedOfficial statement
LEAK-020Yamamoto Kami Hososha "Package Shop JP"C 3,973 peopleThrough a vulnerability in its e-commerce site, the payment application was tampered with, and email addresses and other data of 3,973 customers who paid between June 2021 and January 2025, including card information of 1,395 of them, may have been leaked.
Unauthorized access & data leakPossibleOfficial statement
LEAK-007cocoloniUnauthorized access from outside occurred between November 27 and December 13, 2025, and email addresses and encrypted passwords were leaked. No trace of attempted unauthorized logins has been confirmed.
Unauthorized access & data leakConfirmedOfficial statement
UnknownLEAK-018Dorii Myujikku Paburisshingu "Otopuri"The "ShopServe" platform operated by Estore Co., Ltd., which the shop uses, was accessed without authorization, and the shop's customer information was confirmed to have been leaked externally. The notice states that member IDs, passwords and email addresses were also leaked.
Supply chainConfirmedOfficial statement

Showing 20 of 128 cases

Frequently asked questions

What types of data breaches were disclosed in Japan in 2026?

The 128 cases on this list break down as follows: unauthorized access or data leaks, 90; supply chain (through contractors or external services), 19; ransomware, 10; tampering or unauthorized operations, 5; accidental disclosure, 4.

Was a leak confirmed in every case?

No. Damage has been confirmed in 53 cases. 64 cases were disclosed as a possible leak or similar, and 11 are under investigation. The certainty is shown on every row.

What are the criteria for listing a case?

A case is listed only if it was disclosed in Japan in 2026 and its content could be confirmed in a statement from the organization involved or from a government body. Cases found only in news reports, without a confirmed statement, are not listed.

How many ransomware cases are there?

There are 10. Choose ransomware under incident type in the list to filter them.

How to read this database

  1. Each entry is based on the public statements, news articles or reports linked as evidence. Our service has not independently established these facts.
  2. Certainty reflects the wording of the source. Confirmed: the affected party or authorities have confirmed harm. Possible: a potential leak or harm has been disclosed or reported, or the case involves allegations. Under investigation: whether harm occurred or its extent is being investigated. Unverified report: a report by a user or other involved party without confirmation by a third party or the provider.
  3. Entries marked First-party report are user reports, such as those submitted to a product’s public issues. They do not mean the provider has acknowledged the report as fact.
  4. Dates are the publication or disclosure dates of the sources, and may differ from when the incident occurred. For entries sourced from AIID, the date is the incident date listed in AIID.
  5. Details may change with follow-up reports. Check the source links for the latest information.

Scope of coverage

AI development: Deletion, overwriting or destruction by AI coding agents; authentication or secret-handling flaws in AI-generated code or AI-built apps; supply-chain problems involving AI development tools or packages; attack code created with generative AI; and loss of history or data in AI development services. Deepfakes, general misinformation and autonomous driving are excluded.

Data leaks & unauthorized access: Cases publicly disclosed in Japan in 2026 whose details could be verified in statements by the affected party or a government agency.

Request a correction or removal

If an entry contains an error, or you would like to request a correction or removal, please contact us.

Contact us

Check the risks in your own service

Free diagnosis
Japan Data Breach List 2026: 128 Disclosed Cases | Code Rakuda