The sharp increase in web-related data breaches across Japan highlights a growing cybersecurity challenge as attackers increasingly exploit weaknesses in application programming interfaces (APIs), authentication mechanisms and exposed business systems. According to research cited by JPCERT/CC, 119 incidents involving stolen or leaked personal data through web systems were publicly reported in Japan during 2026 through October 6, compared with 84 during the entire previous year. Particularly concerning is that 81 of these incidents were disclosed since July, indicating a significant acceleration in reported activity.

The attacks demonstrate how vulnerabilities in seemingly routine application functionality can expose enormous volumes of sensitive information. Attackers have reportedly analyzed mobile applications to identify hidden API endpoints, extracted embedded API keys, manipulated authentication requests and exploited insufficient access controls to retrieve information beyond their authorized privileges. The exploitation of CVE-2026-72898, a critical CVSS 10.0 SQL injection vulnerability in Metabase, further illustrates how compromised business intelligence platforms can potentially expose credentials and data from connected enterprise databases.

What makes these incidents particularly concerning is that many attacks do not necessarily require sophisticated malware or previously unknown vulnerabilities. Weak authentication, excessive API privileges, insecure configurations and unpatched software can provide attackers with opportunities to access sensitive information through otherwise legitimate application interfaces.

For organizations, this reinforces the need to move beyond conventional perimeter protection toward comprehensive web application and API security. Strong authentication, endpoint-level authorization, API discovery, behavioral monitoring, rate limiting, vulnerability management and continuous inspection of application traffic must become fundamental components of enterprise security.

Equally important is the ability to identify abnormal data access patterns, unauthorized API enumeration and excessive data extraction, even when requests appear technically valid. Security controls must evaluate not only whether a request is permitted, but whether its behavior and context indicate potential abuse.

The broader lesson extends far beyond Japan. As businesses increasingly expose critical functionality through web applications, mobile platforms and APIs, protecting the application layer is becoming as important as protecting the underlying network infrastructure. An API that functions exactly as designed can still become a serious security vulnerability when authorization and data access controls are inadequate.


Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/

Source: Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks via The Hacker News — published 08 Oct 2026.