Supply Chain Attacks and Third-Party Incidents

This page collects 23 cases in which organizations were affected through an external service they use, a contractor, or a software component. 19 are data leak and unauthorized-access cases disclosed in Japan, and 4 are related to AI development. Damage has been confirmed in 14 cases; every row shows its sources and certainty.

Matching cases: 23Last updated:

Data breach scale rank

Incidents are grouped into seven levels by the order of magnitude of publicly disclosed counts. This is not a rating of companies or services.

Counts mix people, records and accounts, so comparisons are not exact. Dashed borders indicate incidents where a leak has not been confirmed.

Go to the list and filters

D100 or more

E10 or more

FFewer than 10

Count not disclosed (10 cases)

AI development impact rank

Incidents are grouped into seven levels by the scope of impact described in reports and news coverage. This is not a rating of products or companies.

These levels do not precisely compare the severity of damage. Dashed borders indicate unconfirmed incidents, including unverified reports.

Go to the list and filters

AWhole machine or drive

BWhole project

CMultiple files

DSingle file

EHistory only

FNo confirmed damage

No rank (3 cases)

Breakdown

By featured case
GroupCases
ShopServe Intrusion Spread to Stores That Use the Cart System8
KDDI Mail Platform Vulnerability Spread Across Several ISPs6
Vercel Internal Access Traced to a Compromised Third-Party AI Tool1
Malicious Nx npm Packages Reportedly Abused AI Coding Agents1
Malicious Wiping Command Allegedly Found in Amazon Q Release1
Hallucinated Package Names Reportedly Downloaded by Developers1
By category
GroupCases
Data leaks & unauthorized access19
AI development4

All matching cases

Filter incidents

Showing 23 of 23 incidents

Supply Chain Attacks and Third-Party Incidents
DateTargetSummaryClassificationSource links
LEAK-111Daiwa SecuritiesA About 220,000 recordsThe server of Scala Communications, the provider of an external service used for inquiry management, was accessed without authorization from October 2 to 3, 2026, and about 220,000 records, including names and account numbers of about 110,000 customers, may have leaked.
Supply chainPossibleOfficial statement
LEAK-019Enoguya SankichiThrough unauthorized access to the e-commerce system "ShopServe" of Estore Co., Ltd., which the shop uses, it was found on September 25, 2026 that the shop's customers' information was also subject to the leak. This includes names, addresses, email addresses, encrypted passwords and part of the card information.
Supply chainConfirmedOfficial statement
LEAK-096LEGOLAND Japan (LEGOLAND Japan Hotel)C 1,557 recordsUnauthorized access occurred on the external booking platform (Amadeus IT Group) used by the hotel's official reservation site, and names, email addresses and phone numbers in 1,557 reservations may have been affected.
Supply chainPossibleOfficial statement
LEAK-070Tsuburaya Productions "ULTRA MART"The digital ticket system (mogily) used for lottery sales at Tsuburaya Productions' "ULTRA MART" was accessed without authorization by a third party, causing inconsistencies in lottery result data and changing some winners to a losing display. No leak of personal information has been confirmed.
Supply chainConfirmedOfficial statement
LEAK-126CoronaB Up to 35,000 peopleA third party accessed an external cloud service used to manage construction information, and names, addresses and construction-related documents of up to 35,000 customers may have been leaked. It came to light on August 24, 2026, through information from a third party.
Supply chainPossibleOfficial statement
LEAK-014KDDI Web Communications 'CPI'S 1,250,543 recordsUnauthorized access to the KDDI mail system leaked 1,250,543 mail account records of the CPI rental server service. For the Business Standard and KWC Mail plans, passwords were also affected.
Supply chainConfirmedOfficial statement
LEAK-090Japan Association for the 2025 World Exposition (subcontractor of outsourced work)At a subcontractor of outsourced work, phishing led to unauthorized access to Microsoft 365, and emails containing personal information of people involved and event performers may have been affected. It occurred on May 13, 2026.
Supply chainPossibleOfficial statement
LEAK-029Waiefushii "ADVAN"Estore Co., Ltd., the system provider of the company's online shop, was accessed without authorization, and customer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs, encrypted passwords and part of the card information.
Supply chainConfirmedOfficial statement
LEAK-030JA Raifu Kurieito Fukushima "E-gyu Shop"Estore Co., Ltd. announced that buyer and member information leaked from "ShopServe", which the shop uses. Whether the shop's customers are included is under confirmation, and members are advised to change their passwords.
Supply chainUnder investigationOfficial statement
LEAK-031AmtransEstore Co., Ltd. announced that buyer information leaked through unauthorized access to the mail-order system "ShopServe", which the company uses. The company cannot confirm whether its own customers are affected and advises members to change their passwords.
Supply chainUnder investigationOfficial statement
LEAK-016DesignphilThe Shop Serve cart system used by Midori Online Store and others suffered unauthorized access, leaking names, addresses, email addresses, encrypted passwords and partial card data. The scope of those affected is under investigation.
Supply chainConfirmedOfficial statement
LEAK-017RemedikomuThe shopping cart system Shop Serve used by the store suffered unauthorized access, leaking purchaser information of the store, including names, addresses, email addresses, member IDs and encrypted passwords. Card data was kept on a separate server and was not affected.
Supply chainConfirmedOfficial statement
LEAK-028PRGR"ShopServe" of Estore Co., Ltd., used by the company's online shop, was accessed without authorization, and buyer information was sent externally between May 21 and August 1, 2026. It includes names, addresses, email addresses, purchase histories, member IDs and encrypted passwords.
Supply chainConfirmedOfficial statement
LEAK-010Nifty '@nifty Mail'S 2,248,708 peopleA vulnerability in third-party software in the KDDI-provided mail platform was exploited, leaking email addresses of 2,248,708 persons, of whom 1,862,462 also had mail passwords leaked.
Supply chainConfirmedOfficial statement
LEAK-011Chubu Telecommunications (ctc)A 727,176 peopleThe KDDI mail system underlying the Commufa Hikari and Business Commufa mail services suffered unauthorized access, leaking email addresses of 727,176 persons, of whom 724,344 also had mail passwords leaked.
Supply chainConfirmedOfficial statement
LEAK-012STNet 'Pikara'A 456,159 recordsA vulnerability in the KDDI mail system used by mail services such as Pikara Hikari was exploited, leaking 456,159 email address and password sets of 397,152 customers. Access to STNet's data took place from June 14 to 17.
Supply chainConfirmedOfficial statement
LEAK-013JCOMS 2,473,191 peopleA vulnerability in the KDDI mail system was exploited, leaking email addresses of 2,473,191 J:COM NET users and 118,752 users of mail services for partner cable operators. Password leaks were confirmed for 1,257 of the latter.
Supply chainConfirmedOfficial statement
LEAK-009BIGLOBE 'BIGLOBE Mail'S 5,016,432 peopleA vulnerability in third-party software in the KDDI-developed mail platform was exploited, leaking BIGLOBE email addresses and BIGLOBE IDs of 5,016,432 persons, of whom 4,631,775 also had passwords leaked.
Supply chainConfirmedOfficial statement
AI-002Vercel / Context.aiS ProductionStarting from the compromise of Context.ai, a third-party AI tool used by an employee, the employee's Google Workspace and Vercel accounts were taken over, and environment variables not marked as sensitive were enumerated and decrypted. Vercel notified the affected customers and says its published npm packages were not compromised.
Supply chainConfirmedOfficial statement
AI-025Nx npm packagesMalicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration
Supply chainPossibleAIID
AI-027Amazon QAlleged Malicious Wiping Command Found in Amazon Q AI Assistant
Supply chainPossibleAIID
AI-031AI-hallucinated software packagesPurportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers
Supply chainPossibleAIID
UnknownLEAK-018Dorii Myujikku Paburisshingu "Otopuri"The "ShopServe" platform operated by Estore Co., Ltd., which the shop uses, was accessed without authorization, and the shop's customer information was confirmed to have been leaked externally. The notice states that member IDs, passwords and email addresses were also leaked.
Supply chainConfirmedOfficial statement

Showing 20 of 23 cases

Frequently asked questions

What does this page mean by supply chain?

It means cases in which an organization was affected through an external service it uses, a contractor, or a software component such as an npm package. The row for the provider that was attacked may itself be classified under a different type, such as unauthorized access or data leak.

How many cases are there, and how do they break down?

There are 23. 19 are data leak and unauthorized-access cases disclosed in Japan and 4 are related to AI development. By certainty, 14 are confirmed, 7 are possible and 2 are under investigation.

What are the cases based on?

Cases in Japan are listed only when their content could be confirmed in a statement from the organization involved or from a government body. Cases related to AI development are based on official statements or records in the AI Incident Database (AIID). The sources are linked on each row.

How to read this database

  1. Each entry is based on the public statements, news articles or reports linked as evidence. Our service has not independently established these facts.
  2. Certainty reflects the wording of the source. Confirmed: the affected party or authorities have confirmed harm. Possible: a potential leak or harm has been disclosed or reported, or the case involves allegations. Under investigation: whether harm occurred or its extent is being investigated. Unverified report: a report by a user or other involved party without confirmation by a third party or the provider.
  3. Entries marked First-party report are user reports, such as those submitted to a product’s public issues. They do not mean the provider has acknowledged the report as fact.
  4. Dates are the publication or disclosure dates of the sources, and may differ from when the incident occurred. For entries sourced from AIID, the date is the incident date listed in AIID.
  5. Details may change with follow-up reports. Check the source links for the latest information.

Scope of coverage

AI development: Deletion, overwriting or destruction by AI coding agents; authentication or secret-handling flaws in AI-generated code or AI-built apps; supply-chain problems involving AI development tools or packages; attack code created with generative AI; and loss of history or data in AI development services. Deepfakes, general misinformation and autonomous driving are excluded.

Data leaks & unauthorized access: Cases publicly disclosed in Japan in 2026 whose details could be verified in statements by the affected party or a government agency.

Request a correction or removal

If an entry contains an error, or you would like to request a correction or removal, please contact us.

Contact us

Check the risks in your own service

Free diagnosis
Supply Chain Attack Examples: 23 Cases via Vendors, SaaS and Packages | Code Rakuda