This page collects 23 cases in which organizations were affected through an external service they use, a contractor, or a software component. 19 are data leak and unauthorized-access cases disclosed in Japan, and 4 are related to AI development. Damage has been confirmed in 14 cases; every row shows its sources and certainty.
Matching cases: 23Last updated:
Data breach scale rank
Incidents are grouped into seven levels by the order of magnitude of publicly disclosed counts. This is not a rating of companies or services.
Counts mix people, records and accounts, so comparisons are not exact. Dashed borders indicate incidents where a leak has not been confirmed.
ShopServe Intrusion Spread to Stores That Use the Cart System
8
KDDI Mail Platform Vulnerability Spread Across Several ISPs
6
Vercel Internal Access Traced to a Compromised Third-Party AI Tool
1
Malicious Nx npm Packages Reportedly Abused AI Coding Agents
1
Malicious Wiping Command Allegedly Found in Amazon Q Release
1
Hallucinated Package Names Reportedly Downloaded by Developers
1
By category
Group
Cases
Data leaks & unauthorized access
19
AI development
4
Featured cases
ShopServe Intrusion Spread to Stores That Use the Cart System
Aug 3, 2026 – Sep 26, 2026
ConfirmedUnder investigation
Stores that use the e-commerce cart system ShopServe, operated by Estore Co., Ltd., have published notices saying the system suffered unauthorized access from outside. This entry covers 8 stores.
The notices of PRGR and Waiefushii "ADVAN" say that between May 21 and August 1, 2026 a third party gained unauthorized access to Estore's servers and customer information was sent externally. The items named as leaked include names, addresses, email addresses, member IDs and encrypted passwords. On card data, Designphil lists part of the card number (the first 6 and last 4 digits), while Remedikomu says card data was kept on a separate server and was not affected.
The stage of confirmation differs by store. Enoguya Sankichi says that on September 25, 2026 it was informed by Estore that its customers' information was also confirmed as affected. JA Raifu Kurieito Fukushima "E-gyu Shop" says it is still confirming whether its customers are included, and Amtrans says it cannot confirm whether its own customers are affected, so those two are at the investigation stage.
KDDI Mail Platform Vulnerability Spread Across Several ISPs
Jun 23, 2026 – Aug 24, 2026
Confirmed
A vulnerability in third-party software that KDDI had installed in its mail platform for ISPs was exploited, and email addresses and related data of the operators that use the platform leaked. The notices of 6 companies, including BIGLOBE, JCOM and KDDI Web Communications (CPI), are covered here.
The scope differs by company. BIGLOBE says the email addresses and BIGLOBE IDs of 5,016,432 persons leaked, and that 4,631,775 of them also had passwords leaked. STNet says the unauthorized access to its data took place from June 14 to 17. JCOM says that, in addition to the email address leak, passwords also leaked for 1,257 of the affected persons, and that it has finished resetting the passwords of those affected.
Several of the notices say KDDI confirmed the unauthorized access on June 17, 2026 and modified the system the same day. For the Business Standard and KWC Mail plans, CPI attaches a note stating that passwords were managed in hashed form and the passwords themselves were not leaked.
Vercel Internal Access Traced to a Compromised Third-Party AI Tool
Apr 2026
Confirmed
In its security bulletin (April 24, 2026), Vercel said it had identified unauthorized access to certain internal systems. According to Vercel, the incident originated with a compromise of Context.ai, a third-party AI tool used by one of its employees. The attacker used that access to take over the employee's Google Workspace account and then gained access to the employee's Vercel account.
Vercel says the attacker then moved through its systems and enumerated and decrypted environment variables that were not marked as sensitive. It first identified a limited subset of customers whose non-sensitive environment variables that decrypt to plaintext were compromised and contacted them, and says a continued investigation found a small number of additional compromised accounts, whose owners it notified.
Vercel says that, together with GitHub, Microsoft, npm and Socket, it confirmed that no npm packages published by Vercel were compromised. It also published an indicator of compromise (IOC) for the Context.ai Google Workspace OAuth app, saying that the app was the subject of a broader compromise.
Are production secrets inaccessible to users who don't need them?
Have you checked for secret values such as API keys and tokens left in environment variables that are not marked as sensitive, and protected them with the sensitive environment variables feature? Vercel Security Bulletin: April 2026 security incident
Malicious Nx npm Packages Reportedly Abused AI Coding Agents
Aug 21, 2025
Possible
Malicious versions of the Nx monorepo tool and its plugins were reportedly published to npm after attackers compromised its CI workflow. The postinstall script is reported to have harvested credentials and exfiltrated data, and to have abused local AI coding agents such as Claude Code, Gemini and Amazon q.
According to the report, by invoking unsafe flags it coerced the tools into scanning developer machines for sensitive files, which the AI Incident Database describes as one of the first known AI-assisted supply chain attacks. Another report says the malicious releases were live for about 5 hours 20 minutes before removal, and that the Nx Console VS Code extension was also affected.
Does a lockfile exist, with dependency versions pinned?
Are CI/CD permissions not overly broad?
Do you use a permission mode in which the AI coding agent asks before editing files, running shell commands or reaching the network? Claude Code Docs: Permission modes
Do you restrict the files and network hosts that shell commands can reach by using a sandbox? Claude Code Docs: Sandboxing
Malicious Wiping Command Allegedly Found in Amazon Q Release
Jul 17, 2025
Possible
A reported compromise of Amazon's AI coding assistant Q allegedly involved the insertion of commands that, if executed, could have wiped local files and potentially affected cloud resources. The altered code is reported to have been incorporated into a public release before it was detected and removed.
The AI Incident Database entry points to the compromised release as version 1.84.0 of the Amazon Q Developer extension. It also lists, among its reports, a security update for that extension published by Amazon Web Services (publication date: July 23, 2025).
Hallucinated Package Names Reportedly Downloaded by Developers
Dec 1, 2023
Possible
Large language models reportedly hallucinated names of software packages that do not exist, some of which were later uploaded to public repositories and incorporated into real codebases.
In one reported case, a package named huggingface-cli, purported to have been originally suggested by an AI model, was downloaded more than 15,000 times. It is also reported that several big businesses published source code that incorporates a package previously hallucinated by generative AI.
The technique in which attackers register hallucinated package names to introduce potential malware into software supply chains is called slopsquatting by security researchers.
A About 220,000 recordsThe server of Scala Communications, the provider of an external service used for inquiry management, was accessed without authorization from October 2 to 3, 2026, and about 220,000 records, including names and account numbers of about 110,000 customers, may have leaked.
Through unauthorized access to the e-commerce system "ShopServe" of Estore Co., Ltd., which the shop uses, it was found on September 25, 2026 that the shop's customers' information was also subject to the leak. This includes names, addresses, email addresses, encrypted passwords and part of the card information.
C 1,557 recordsUnauthorized access occurred on the external booking platform (Amadeus IT Group) used by the hotel's official reservation site, and names, email addresses and phone numbers in 1,557 reservations may have been affected.
The digital ticket system (mogily) used for lottery sales at Tsuburaya Productions' "ULTRA MART" was accessed without authorization by a third party, causing inconsistencies in lottery result data and changing some winners to a losing display. No leak of personal information has been confirmed.
B Up to 35,000 peopleA third party accessed an external cloud service used to manage construction information, and names, addresses and construction-related documents of up to 35,000 customers may have been leaked. It came to light on August 24, 2026, through information from a third party.
S 1,250,543 recordsUnauthorized access to the KDDI mail system leaked 1,250,543 mail account records of the CPI rental server service. For the Business Standard and KWC Mail plans, passwords were also affected.
Japan Association for the 2025 World Exposition (subcontractor of outsourced work)
At a subcontractor of outsourced work, phishing led to unauthorized access to Microsoft 365, and emails containing personal information of people involved and event performers may have been affected. It occurred on May 13, 2026.
Estore Co., Ltd., the system provider of the company's online shop, was accessed without authorization, and customer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs, encrypted passwords and part of the card information.
Estore Co., Ltd. announced that buyer and member information leaked from "ShopServe", which the shop uses. Whether the shop's customers are included is under confirmation, and members are advised to change their passwords.
Estore Co., Ltd. announced that buyer information leaked through unauthorized access to the mail-order system "ShopServe", which the company uses. The company cannot confirm whether its own customers are affected and advises members to change their passwords.
The Shop Serve cart system used by Midori Online Store and others suffered unauthorized access, leaking names, addresses, email addresses, encrypted passwords and partial card data. The scope of those affected is under investigation.
The shopping cart system Shop Serve used by the store suffered unauthorized access, leaking purchaser information of the store, including names, addresses, email addresses, member IDs and encrypted passwords. Card data was kept on a separate server and was not affected.
"ShopServe" of Estore Co., Ltd., used by the company's online shop, was accessed without authorization, and buyer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs and encrypted passwords.
S 2,248,708 peopleA vulnerability in third-party software in the KDDI-provided mail platform was exploited, leaking email addresses of 2,248,708 persons, of whom 1,862,462 also had mail passwords leaked.
A 727,176 peopleThe KDDI mail system underlying the Commufa Hikari and Business Commufa mail services suffered unauthorized access, leaking email addresses of 727,176 persons, of whom 724,344 also had mail passwords leaked.
A 456,159 recordsA vulnerability in the KDDI mail system used by mail services such as Pikara Hikari was exploited, leaking 456,159 email address and password sets of 397,152 customers. Access to STNet's data took place from June 14 to 17.
S 2,473,191 peopleA vulnerability in the KDDI mail system was exploited, leaking email addresses of 2,473,191 J:COM NET users and 118,752 users of mail services for partner cable operators. Password leaks were confirmed for 1,257 of the latter.
S 5,016,432 peopleA vulnerability in third-party software in the KDDI-developed mail platform was exploited, leaking BIGLOBE email addresses and BIGLOBE IDs of 5,016,432 persons, of whom 4,631,775 also had passwords leaked.
S ProductionStarting from the compromise of Context.ai, a third-party AI tool used by an employee, the employee's Google Workspace and Vercel accounts were taken over, and environment variables not marked as sensitive were enumerated and decrypted. Vercel notified the affected customers and says its published npm packages were not compromised.
The "ShopServe" platform operated by Estore Co., Ltd., which the shop uses, was accessed without authorization, and the shop's customer information was confirmed to have been leaked externally. The notice states that member IDs, passwords and email addresses were also leaked.
It means cases in which an organization was affected through an external service it uses, a contractor, or a software component such as an npm package. The row for the provider that was attacked may itself be classified under a different type, such as unauthorized access or data leak.
How many cases are there, and how do they break down?
There are 23. 19 are data leak and unauthorized-access cases disclosed in Japan and 4 are related to AI development. By certainty, 14 are confirmed, 7 are possible and 2 are under investigation.
What are the cases based on?
Cases in Japan are listed only when their content could be confirmed in a statement from the organization involved or from a government body. Cases related to AI development are based on official statements or records in the AI Incident Database (AIID). The sources are linked on each row.
Each entry is based on the public statements, news articles or reports linked as evidence. Our service has not independently established these facts.
Certainty reflects the wording of the source. Confirmed: the affected party or authorities have confirmed harm. Possible: a potential leak or harm has been disclosed or reported, or the case involves allegations. Under investigation: whether harm occurred or its extent is being investigated. Unverified report: a report by a user or other involved party without confirmation by a third party or the provider.
Entries marked First-party report are user reports, such as those submitted to a product’s public issues. They do not mean the provider has acknowledged the report as fact.
Dates are the publication or disclosure dates of the sources, and may differ from when the incident occurred. For entries sourced from AIID, the date is the incident date listed in AIID.
Details may change with follow-up reports. Check the source links for the latest information.
Scope of coverage
AI development: Deletion, overwriting or destruction by AI coding agents; authentication or secret-handling flaws in AI-generated code or AI-built apps; supply-chain problems involving AI development tools or packages; attack code created with generative AI; and loss of history or data in AI development services. Deepfakes, general misinformation and autonomous driving are excluded.
Data leaks & unauthorized access: Cases publicly disclosed in Japan in 2026 whose details could be verified in statements by the affected party or a government agency.
Request a correction or removal
If an entry contains an error, or you would like to request a correction or removal, please contact us.