← Back to AI Legal Lab
Insight
Legal Outsourcing

Personal Data Breaches from Unauthorized Access: Initial Response and Data Retention Lessons from the September 2026 Incidents

Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.

At 9:07 a.m. on September 25, 2026, Times Mobility, which operates the car-sharing service "Times Car," detected unauthorized access to its web system. On the same day, the company and its parent, Park24, announced the possibility of a personal data leak in their first report (Japanese), and in their second report (Japanese) on September 28 they disclosed that member information for approximately 6.6 million accounts had been obtained by a third party. The affected individuals include not only current members but also former members who had cancelled their membership and people who never completed the sign-up process. The third report (Japanese) on the following day, the 29th, confirmed that images of identity verification documents, such as driver's licenses and proof-of-address documents, had leaked for approximately 1.6 million accounts.

Announcements have also continued in the logistics sector. On September 25, Japan Post suspended its online request service for international mail inquiries, citing possible unauthorized access to the service's server. Japan Post Holdings and Japan Post also separately announced that customer information for 19 individuals had been illicitly obtained through unauthorized access to the post office app. Yamato Transport confirmed unauthorized access to its "Kuroneko Deferred Payment Service" on September 28 and suspended the service that night. Sagawa Express announced unauthorized access to its package inquiry service on September 30, and in its second report (Japanese) on October 1 disclosed that the names, addresses, telephone numbers and other details of senders and recipients of packages for approximately 100 days going back from September 30 may have been leaked.

September saw a series of other large-scale announcements as well. On September 11, the Digital Agency announced that a vulnerability in VPN equipment used by the Government Solution Service (GSS) had been exploited and that personal information of approximately 246,000 people may have been leaked. On September 15, Murauchi.com announced that it had confirmed the exfiltration of 7,716,811 customer records, and on September 16, Helpfeel announced a leak of data relating to approximately 23.62 million users of its image-sharing service "Gyazo." On September 26, servers of the Keio Group were hit by a ransomware attack, and on the 29th, Seicomart announced a possible leak of information for approximately 570,000 app member accounts. In August, E-Store, which operates the e-commerce site building service "Shop Serve," announced that purchaser information and other data covering 8,853,839 records had been affected by unauthorized access between May 21 and August 1, and online retailers that used the service have continued to issue announcements to their own customers.

The facts in this article are based on the companies' announcements as of October 1, 2026. Many of these incidents are still under investigation, and the numbers and causes may change. If you put these incidents in your own company's shoes, there are three issues a legal team should examine. First, once unauthorized access is detected, when and what must be reported to the Personal Information Protection Commission, and when must individuals be notified? Second, was the response to the vulnerability or configuration that allowed the intrusion sufficient as a security control measure? And third, why was the company holding personal data it no longer used, such as data on former members or data that had supposedly been deleted? I explained the required contents of the preliminary and final reports and how to count the deadlines in Initial Response to Personal Data Breaches: Reporting Deadlines and a Timeline of What to Do.

Breaches from Unauthorized Access Keep Getting Larger

The September incidents are an extension of a trend that has continued since 2025. According to Tokyo Shoko Research, listed companies and their subsidiaries announced 180 incidents of personal information leaks or losses in 2025, involving personal information of 30,636,910 people. The number of people rose 93.1% from the previous year, and by cause, "virus infection or unauthorized access" accounted for 116 incidents (64.4%). Incidents involving more than one million people also rose from two in the previous year to six.

According to the Personal Information Protection Commission's Annual Report for FY2025 (Japanese), the Commission processed 17,139 breach reports from private businesses in fiscal 2025, and incidents caused by unauthorized access and similar acts (Article 7, item 3 of the Enforcement Rules) accounted for 22.3%. In the same report, the Commission identified three main deficiencies behind unauthorized access: leaving vulnerabilities in VPN equipment or e-commerce applications unaddressed even after fixes had been published, IDs and passwords that are easy to guess, and inadequate database access controls due to misconfiguration. The Commission gives guidance on these as deficiencies in security control measures, and the entry point in the GSS incident in September was also a VPN equipment vulnerability.

Situations Requiring a Report and Notification to Individuals

Article 26, paragraph 1 of the Act on the Protection of Personal Information (APPI) (Japanese) requires a business handling personal information to report to the Commission when a situation specified by Commission rules arises as "a leak, loss or damage of personal data, or any other situation relating to ensuring the security of personal data, that is highly likely to harm the rights and interests of individuals." The duty to notify individuals under paragraph 2 of the same Article covers the same situations.

Article 7 of the Enforcement Rules divides these situations into four categories: a leak or similar incident involving personal data that includes special care-required personal information (item 1); a leak or similar incident involving personal data whose unauthorized use is likely to cause financial harm (item 2); a leak or similar incident involving personal data caused by an act that may have been carried out for a wrongful purpose (item 3); and a leak or similar incident involving more than 1,000 individuals (item 4). Each category includes "situations where it is likely that such an incident has occurred." According to Katsuya Uga, Shin Kojin Joho Hogo Ho no Chikujo Kaisetsu (New Article-by-Article Commentary on the Act on the Protection of Personal Information) (Yuhikaku), p. 239, a leak caused by a hacker's cyberattack falls under item 3, and if a situation falls under any of items 1 to 3, it must be reported regardless of the number of records.

The meaning of "likely" is explained in section 3-5-3-1 of the Commission's Guidelines (General Rules) (Japanese). It refers to cases where, based on the facts known at that time, a leak or similar incident is suspected but there is no certainty that it has occurred. The same section gives, as examples of item 3, leaks caused by unauthorized access and encryption by ransomware. Under Article 8, paragraph 2 of the Enforcement Rules, the deadline for the final report is within 30 days from the date the business became aware of the situation, or within 60 days if it falls under item 3.

The matters to be notified to individuals are set out in Article 10 of the Enforcement Rules: an overview of the situation, the items of personal data that were leaked or otherwise affected, the cause, whether there is any secondary harm or risk of secondary harm and its nature, and other matters for reference, to the extent necessary to protect the rights and interests of individuals.

The Scope of Data Held and the Duty to Endeavor to Delete

Article 22 requires a business handling personal information to endeavor to keep personal data accurate and up to date within the scope necessary to achieve the purpose of use, and to delete personal data without delay when it is no longer needed. Deletion is only a duty to endeavor. However, Uga (cited above, p. 231) states that a business should avoid carelessly continuing to hold personal data that has served its purpose and for which there is no plan to reuse it, merely because storage space is not a problem, since doing so carries a risk of leaks.

Article 23 requires a business to take necessary and appropriate measures to prevent leaks and otherwise to securely manage personal data. Data you do not hold cannot leak. Deleting unnecessary data is both the endeavor duty under Article 22 and a starting point for thinking about what security control measures under Article 23 should involve.

The amending act promulgated on July 17, 2026 (Act No. 56 of 2026) relaxed the duty to notify individuals under Article 26, paragraph 2 in cases where there is little risk of harming the protection of individuals' rights and interests. The overall effective date is to be set by Cabinet Order within two years of promulgation, and as of October 1, 2026, the Commission is still considering the contents of the Cabinet Order and the rules. Until the amendments take effect, decide whether notification to individuals is required under the current standards.

Applying the Rules to the September Incidents

Deadlines from Detection to the Final Report

In the Times Car incident, the company published its first report describing the "possibility" of a leak on the day of detection, confirmed acquisition by a third party three days later, and began sending individual notices by email to affected individuals four days later. The second report also mentions reports to the Commission and the police. Sagawa Express likewise focused on access restrictions in its September 30 announcement and set out the items of information that may have leaked in its second report the next day. Yamato Transport's announcement stated that, as of September 29, it was still investigating whether any data had leaked. Companies are continuing to disclose in stages, within the scope of what they have found, before their investigations are complete.

An incident caused by unauthorized access falls under item 3, and if more than 1,000 individuals are involved, it also falls under item 4. Because it falls under item 3, the deadline for the final report is 60 days. If, hypothetically, we count September 25, the date of detection in the Times Car incident, as day one, the 60th day is November 23, which is a public holiday, so the deadline is the following day, the 24th. In light of the explanation of "likely," a business may be treated as having become aware of a reportable situation when it grasps the fact of an intrusion, even before acquisition by a third party has been confirmed. So that your company can issue a preliminary report without waiting for investigation results if a similar incident occurs, check the route by which the IT department that detects an intrusion contacts the legal team.

Notifying Individuals When Images of Identity Documents Have Leaked

Images of driver's licenses are not special care-required personal information, nor are they information that can be used directly for payment, like credit card numbers. Even so, an image that combines a name, address, date of birth and facial photo may be used for various applications by someone impersonating the individual. Nikkei (Japanese) has also reported that leaked license images could lead to credit cards being issued without the individual's knowledge.

Under Article 10 of the Enforcement Rules, the notice to individuals must include the risk of secondary harm and its nature. Do not stop at a warning about suspicious emails; specifically describe, as steps individuals can take, the risk that someone may apply for contracts by impersonating them and the self-reporting systems offered by credit bureaus and similar bodies. Where senders' and recipients' names, addresses and telephone numbers have leaked, as in the delivery company incidents, the notice should also include a warning about SMS messages and phone calls that pose as missed-delivery notices from the business.

Data on Former Members and Deleted Data

The Times Car leak also affected information on former members and people who did not complete the sign-up process. The published materials do not state why this information was retained or for how long. For Gyazo, a further leak of approximately 174 million metadata records for images that users had deleted has also been confirmed. In the Sagawa Express incident, the affected data is described as package data for approximately 100 days, so the period for which data was stored in the system became the scope of the leak as it was.

Personal data of former members and people who dropped out partway through an application may be retained only to the extent that a purpose of use remains after they leave, such as billing unpaid charges, investigating fraudulent use, or complying with statutory retention obligations. Continuing to hold data beyond that scope not only runs counter to the endeavor duty under Article 22 but also increases the number of individuals affected and the scope of reporting if a leak occurs. For images of identity documents, consider whether there is a need to keep the images themselves after the review is complete, or whether a record of the facts confirmed and the date is sufficient.

What a legal team can start on the next day is checking whether there are rules setting the retention period and deletion method for each category: members, former members, incomplete applicants, images of identity documents, and delivery and transaction histories. Even if rules exist, confirm with the IT department that the system is not designed so that only a deletion flag is set while the actual data remains. If data shown as "deleted" on the user's screen remains internally, that deleted data will also be subject to reporting and notification in the event of a leak.

Vulnerabilities and Misconfiguration

In the GSS incident, abnormal access was detected on June 25, 2026, an intrusion exploiting a VPN equipment vulnerability was identified on July 9, and the incident was announced on September 11. An account belonging to maintenance and operations personnel was used, and a large number of files on the server were accessed. Breach reporting by administrative organs is governed by Article 68 of the Act, and the reporting criteria differ from those for private businesses, but the entry point overlaps with the causes the Commission has pointed out to private businesses. At Gyazo, a vulnerability in an image upload server was exploited, and Murauchi.com was also attacked through a web vulnerability.

What the Commission targets with its guidance are cases in which a vulnerability was left unaddressed even after a fix had been published. If you set an internal period between the release of a patch and its application and keep records of it, those records will serve as material for explaining to the Commission that you had taken security control measures if an incident occurs. For external accounts, such as those of maintenance vendors, check the procedures for issuing and disabling accounts and whether multi-factor authentication is used.

Leaks happen even without an attack. In July 2026, Sagawa Express announced that, due to a configuration error made while restoring a system malfunction, other customers' information appeared in delivery notification emails, and personal information of approximately 70,000 people may have been leaked. The more urgently a failure is being addressed, the more likely it is that configuration changes will be pushed to the production environment without review, so procedures should specify who reviews the content of changes even in an emergency.

Ransomware Damage Where a Leak Cannot Yet Be Confirmed

In the Keio Group incident, the company announced that, as of September 26, no information leak had been confirmed. Immediately after a ransomware attack, a business must make decisions without being able to confirm whether data was sent outside. An intrusion into a server storing personal data constitutes a likely leak or similar incident caused by an act carried out for a wrongful purpose, and it can be reportable under item 3 even if no trace of data transmission has been found.

If the same data can be restored from backups, the situation does not constitute damage within the meaning of section 3-5-1 of the General Rules Guidelines. However, attackers also use the tactic of exfiltrating data before encrypting it and threatening to publish it, so the ability to restore data alone does not rule out the likelihood of a leak. Even if a ransom is paid and the attacker says that "the data has been deleted," the situation differs from the case the General Rules Guidelines treat as not being a leak, namely "where all the data was recovered before it was viewed." Regardless of whether a ransom is paid, the duties to report and to notify individuals are likely to remain.

For ransomware incidents, an amendment to the Enforcement Rules that took effect on October 1, 2025 made it possible to use the "Common Form for Ransomware Incidents" for breach reports to the Commission. A business can report to the Commission using the same form it uses for reports to the police and the ministry with jurisdiction over its business. When investigating the cause, preserve logs and the state of compromised devices in parallel with disconnecting them from the network. On January 28, 2026, the Commission published "Points to Consider for Making Effective Use of Forensic Investigations When Unauthorized Access Occurs."

Leaks at Contractors and Platforms

In the Shop Serve incident, many online retailers that had entrusted the building and operation of their e-commerce sites to the same service had to check whether their own customers' information was affected and make their own announcements. When a leak or similar incident occurs at a contractor, under the proviso to Article 26, paragraph 1 of the Act and Article 9 of the Enforcement Rules, if the contractor promptly notifies the entrusting party, the contractor is relieved of its duty to report to the Commission, and the entrusting party makes the report and notifies individuals. Section 3-5-3-5 of the General Rules Guidelines states that the entrusting party is normally deemed to have become aware of a reportable situation, at the latest, when it receives notice from the contractor.

In the delivery company incidents, much of the recipient information was provided for delivery by shippers such as online retailers. Where the relationship between a shipper and a delivery company constitutes entrustment of the handling of personal data, the same analysis means the shipper must also consider whether a report and notification are required. Check your shipping records to see whether the recipients of packages your company shipped fall within the affected period that was announced.

A contractor's first report may not state the scope of the entrusting party's customers who were affected. The entrusting party should not wait for the contractor's investigation results; it should identify, from its own records, the items of personal data it entrusted and the number of individuals involved, and include them in its preliminary report. The outsourcing agreement should specify the deadline for notifying the entrusting party after the contractor becomes aware of a suspected incident, the items to be reported in the first notice, provision of logs and cooperation with investigations, and deletion of data after the engagement ends together with proof of deletion. I explain the points to check in these clauses in What Is a Personal Data Clause? Points to Check in Outsourcing and SaaS Agreements.

Keywords
Personal data
Browse all keywords

Related articles

Articles connected to this topic.

Insight / 2026.08.29 Labor Management for Spot Work: The Contractual Relationships around Applications, Cancellations and Wages Insight / 2026.08.29 Legal Issues for TikTok Shop and Live Commerce: Mail-Order Disclosures, Stealth Marketing and Returns Insight / 2026.07.21 Running Esports Tournaments: Prize Money, Sponsors, and Minors

Services connected to this topic

Legal outsourcing Ongoing legal team support for contract review and legal operations.
View AI Legal Lab articles