LegalAgent AI Legal Lab
Data Breach & Cyberattack News
Data breaches, unauthorized access and service outages announced by companies and organizations in Japan, listed from their official announcements. Explore incident counts, reported exposure figures and a monthly chart.As of October 11, 2026
Listed incidents in numbers
Data as of 2026.10.11- Listed incidents
- 115 incidents
- Incidents with confirmed leaks
- 49 incidents
- Possible leaks / investigations
- 59 incidents
- Incidents with service / business outages
- 32 incidents
Gross counts of exposed information
Reference sums excluding image metadata · 62 incidents
- Information confirmed exposed
- Approx. 111,837,182 reported items
- Information potentially exposed
- Approx. 44,545,476 reported items
Including image metadata
- Information confirmed exposed
- Approx. 778,237,182 reported items
- Information potentially exposed
- Approx. 44,545,476 reported items
Listed incidents by month
Choose a filter to update both the chart and the list. Select a monthly bar to jump to its incidents.
2026
Listed incidents by monthOctober 2026
-
Fourth report
IDC Frontier
A ransomware attack stopped virtual servers. The company said recovery of data in four affected zones would be difficult.
Official announcement: IDC Frontier (Open external link)Under investigationRansomwareVirtual servers stopped
495 customer companies and public bodies
Timeline and sources (3) · Related announcements (9)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Third reportOfficial announcement (Open external link)
- Fourth reportOfficial announcement (Open external link)
Related announcements (customers and principals)
- Viewcard (Open external link) · Possible leakAbout 4.03 million email addresses
- East Japan Railway (Open external link) · Possible leakEkinet: up to about 1.67 million; Otona no Kyujitsu Club: up to about 390,000 records
- Kyushu Railway (Open external link) · Possible leakUp to about 1.3 million records
- Nissui Logistics (Open external link) · Leak not confirmedSome inbound/outbound operations resumed; no personal or customer data on the affected server
- Cyber University (Open external link) · Leak not confirmedCourse registration and payment procedures disrupted
- Future Shop (Open external link) · Under investigationEmail services resumed in an alternative environment; leak investigation ongoing
- Nihon Shurui Hanbai / Tokyo Shusui (Open external link) · Possible leakNumber not disclosed; newsletter delivery suspended
- Japan Telecom Users Association (Open external link) · Leak not confirmedSender email address changed; learning service unaffected
- Fibergate (Open external link) · Leak not confirmedCloud servers supporting services suspended
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
BOOKOFF Group Holdings
Unauthorized access to a membership system caused a data leak. The maximum affected figure is not a count of unique people.
Official announcement: BOOKOFF Group Holdings (Open external link)Leak confirmedUnauthorized access
Up to about 6.43 million membership-number recordsCount of membership numbers, not unique people.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
dip
Some email addresses for Baitoru and Baitoru NEXT leaked. The maximum figure is the potentially affected scope.
Official announcement: dip (Open external link)Leak confirmedUnauthorized access
Up to 3,885,771 recordsLeakage of every record in the maximum figure has not been confirmed.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Adventureskyticket: servers
The company disclosed data leakage from unauthorized access to skyticket servers. It said passport numbers had not leaked.
Official announcement: Adventure (Open external link)Leak confirmedUnauthorized access
About 14.64 million recordsIncludes about 4.13 million hashed-password records. Not added to the other two events.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Commune
Member-data leakage was confirmed. After suspending all communities, the company began reopening participating communities on October 8.
Official announcement: Commune (Open external link)Leak confirmedUnauthorized accessCommunities reopening in stages
About 307,000 members (estimated)Includes about 126,000 with email addresses and about 42,000 employee and demo accounts.
Timeline and sources · Related announcements (5)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- WingArc1st (Open external link) · Possible leakAbout 1,200 people (estimated)
- Suzuki (Open external link) · Possible leakAbout 3,000 people
- LIXIL (Open external link) · Possible leakNumber not disclosed
- CHITOSE (Open external link) · Possible leakUp to 843 people
- VALX (Open external link) · Possible leak2,950 people potentially affected
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
REXT / REXT Holdings
Ransomware stopped POS, accounting and other systems. The disclosure separates publicly exposed data from potentially leaked data. All stores reopened.
Official announcement: REXT / REXT Holdings (Open external link)Part confirmed / part possibleRansomwareAll stores reopened
310 files publicly exposed; 1,044,906 records potentially affected27 applicants and employees were notified. These figures use different units and scopes and are not added.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Second report
Uzabase / NewsPicks
Customer data may have leaked from a business-management tool. Full card numbers and security codes were not held, and service continued.
Official announcement: Uzabase / NewsPicks (Open external link)Possible leakUnauthorized access
Up to 323,000 email records; 362,000 partial card-data recordsMaximum figures for separate data fields, not a combined count of people.
Timeline and sources (2)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Second reportOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Fourth report
Sagawa Express
The company disclosed possible leakage after unauthorized access to its cargo system. It was reviewing affected senders, recipients and shipping-contract customers.
Official announcement: Sagawa Express (Open external link)Possible leakUnauthorized accessSome web services remain suspended; collection, transport and delivery continue
Number under investigation
Timeline and sources (4)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Second reportOfficial announcement (Open external link)
- Third reportOfficial announcement (Open external link)
- Fourth reportOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
coconala
Unauthorized access exposed recruitment documents. Credit card information and passwords were outside the affected scope.
Official announcement: coconala (Open external link)Leak confirmedUnauthorized access
449 resumes; 1,845 employment-history documents
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Resorttrust
The company disclosed leakage of member and reservation information. Figures for the two categories are kept separate.
Official announcement: Resorttrust (Open external link)Leak confirmedUnauthorized access
About 26,000 member records; about 36,000 reservation records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Lashinbang
The company disclosed possible leakage of purchase-related data. An update excluded identity-document images, card data and passwords.
Official announcement: Lashinbang (Open external link)Possible leakUnauthorized access
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Adventureskyticket: business systems
The company disclosed leakage or possible leakage from skyticket business-management systems, including refund bank-account data.
Official announcement: Adventure (Open external link)Leak / possible leakUnauthorized access
17,780 records, including duplicatesOther affected information is still being counted. Not added to the other two events.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Adventureskyticket: bus reservations
A third party systematically viewed bus-booking confirmation pages that required no login. The issue was fixed on October 1.
Official announcement: Adventure (Open external link)Viewed / possibly viewedMisconfiguration
About 12,000 reservationsNot a count of people including companions. Not added to the other two events.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Daiichikosho
The company disclosed possible leakage of customer and employee information. Actual leakage has not been confirmed.
Official announcement: Daiichikosho (Open external link)Possible leakUnauthorized access
About 8,724,000 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
LAWSONLAWSON ID
Unauthorized access to LAWSON ID exposed names, email addresses and other information.
Official announcement: LAWSON (Open external link)Leak confirmedUnauthorized access
2,155,345 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
LAWSONApp reservations
Unauthorized access exposed app-reservation data, including partial card numbers. The reservation function was suspended.
Official announcement: LAWSON (Open external link)Leak confirmedUnauthorized accessApp reservations suspended
26 recordsNot added to the LAWSON ID event.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Hi-Ho
The company disclosed unauthorized acquisition of information through account logins. The figure counts contracts.
Official announcement: Hi-Ho (Open external link)Leak confirmedUnauthorized access
38,509 contractsA customer with multiple contracts may be counted more than once.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
Scala Communications
Unauthorized access to an inquiry-management system may have exposed inquiry information of customer companies.
Official announcement: Scala Communications (Open external link)Possible leakUnauthorized access
Up to 713,126 cumulative inquiry recordsCount of inquiries, not unique people.
Timeline and sources · Related announcements (4)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Daiwa Securities (Open external link) · Possible leakAbout 110,000 people; about 220,000 cumulative inquiry records
- Sompo Japan / SMILING ROAD (Open external link) · Possible leakAbout 60,000 cumulative inquiry records
- Citizen Watch (Open external link) · Possible leakAbout 100,000 people
- The Shikoku Bank (Open external link) · Possible leakNotice referring customers to Daiwa Securities
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
TODA
The company disclosed leakage of business-partner and employee information. Employee data covered 4,778 people.
Official announcement: TODA (Open external link)Leak confirmedUnauthorized access
Up to 7,200 email addresses; up to 6,000 transaction recordsSeparately, data for 4,778 employees. Categories are not added together.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Saitama Prefecture
The prefecture disclosed unauthorized viewing of a list and detailed information for some listed people.
Official announcement: Saitama Prefecture (Open external link)Leak confirmedUnauthorized access
A list of about 2,200 people; details for 3 of them
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
HOTELIER
The company disclosed leakage of accommodation reservation information, including names, contact details and stay dates.
Official announcement: HOTELIER (Open external link)Leak confirmedUnauthorized access
7,919 people across 8 properties
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Daiei Sangyo / Grand Inn Canalside (Open external link) · Possible leakNumber not disclosed
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
MrMax
The company disclosed leakage of member information. It said addresses, birth dates, card data, passwords and purchase histories did not leak.
Official announcement: MrMax (Open external link)Leak confirmedUnauthorized access
Up to 1,735,154 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
FAQ update
Times Mobility
Times Car confirmed leakage of member information and identity-document images. It denied leakage of credit card information.
Official announcement: Times Mobility (Open external link)Leak confirmedUnauthorized access
About 6.6 million accountsOf these, about 1.6 million accounts include identity-document images.
Timeline and sources (4)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Second reportOfficial announcement (Open external link)
- Third reportOfficial announcement (Open external link)
- FAQ updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Daiki Suisan
The company disclosed possible leakage of official-app registration data, including former members.
Official announcement: Daiki Suisan (Open external link)Possible leakUnauthorized access
174,933 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
nimoca
The company disclosed a data leak caused by unauthorized access and suspended the affected service.
Official announcement: nimoca (Open external link)Leak confirmedUnauthorized accessAffected service suspended
521 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Asahi Kasei Therapeutics
The company disclosed possible leakage of information related to a healthcare-professional site and employee information.
Official announcement: Asahi Kasei Therapeutics (Open external link)Possible leakUnauthorized access
About 514,000 healthcare professionals, plus other categoriesAbout 44,000 with email addresses and other data are a subset. Separately, about 700 employees.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Rakuten Symphony / Rakuten Drive
Compromised administrator credentials enabled acquisition or viewing of account names, display names and profile-image URLs.
Official announcement: Rakuten Symphony / Rakuten Drive (Open external link)Leak confirmedUnauthorized access
687 accountsThe three events are not added because overlap is unknown. The date is the information cutoff stated in the notice.
Timeline and sources
Timeline and sources
- Information as of October 6Official announcement (Open external link)
Sources checked: 2026-10-10
-
Rakuten Symphony / Rakuten Drive
The company disclosed acquisition or viewing of account data, passwords transformed to resist recovery, and added strings.
Official announcement: Rakuten Symphony / Rakuten Drive (Open external link)Leak confirmedUnauthorized access
313 accountsThe three events are not added because overlap is unknown. The date is the information cutoff stated in the notice.
Timeline and sources
Timeline and sources
- Information as of October 6Official announcement (Open external link)
Sources checked: 2026-10-10
-
Rakuten Symphony / Rakuten Drive
The company disclosed acquisition or viewing of stored photos, documents and other data between January 29 and September 17.
Official announcement: Rakuten Symphony / Rakuten Drive (Open external link)Leak confirmedUnauthorized access
15,382 accountsThe three events are not added because overlap is unknown. The date is the information cutoff stated in the notice.
Timeline and sources
Timeline and sources
- Information as of October 6Official announcement (Open external link)
Sources checked: 2026-10-10
-
Active
The company found traces of customer and order data being exported from its online store and disclosed possible leakage. It said core business operations continued normally.
Official announcement: Active (Open external link)Possible leakUnauthorized access
Up to 54,916 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
Temairazu
The company disclosed possible viewing or acquisition of reservation data. It said temporarily suspended functions had resumed and the service was operating normally.
Official announcement: Temairazu (Open external link)Possible leakUnauthorized accessNormal operation announced
Number under investigation
Timeline and sources · Related announcements (8)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Chojuso / Hotel Crystal Palace (Open external link) · Possible leakNumber not disclosed or under investigation
- Yumotokan (Open external link) · Possible leakNumber not disclosed or under investigation
- FJ Resort Management / Gyokuhokan (Open external link) · Possible leakNumber not disclosed or under investigation
- Holonic (Open external link) · Possible leakNumber not disclosed or under investigation
- Kur and Hotel (Open external link) · Possible leakNumber not disclosed or under investigation
- Resort Hanayunomori / Hana Hotel (Open external link) · Possible leakNumber not disclosed or under investigation
- Nikken Hotel Management / Feliz Villa Suite (Open external link) · Possible leakNumber not disclosed or under investigation
- Capital-Zenrin / Feriendorf (Open external link) · Possible leakNumber not disclosed; fraudulent-email warning updated
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
The Monogatari Corporation
The company disclosed leakage of Yakiniku King app member data. The leak count differs from the total number of registrations.
Official announcement: The Monogatari Corporation (Open external link)Leak confirmedUnauthorized access
10,788,963 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
White Essence
The company disclosed data leakage after attackers reached core systems through a reservation-site vulnerability. Leakage of customer images was not confirmed.
Official announcement: White Essence (Open external link)Leak confirmedUnauthorized access
About 1.05 million accounts
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
GMO Research & AI
The company disclosed leakage of infoQ member information and unauthorized point exchanges.
Official announcement: GMO Research & AI (Open external link)Leak confirmedUnauthorized access
Up to 948,498 recordsThe 611 unauthorized exchanges are a separate measure from leaked records.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Planned restart of selected services
Nihon Kotsu
Unauthorized access stopped dispatch and other systems; some files were found to have leaked. On October 5 the company announced a planned restart of selected services.
Official announcement: Nihon Kotsu (Open external link)Leak confirmedMalware infectionPlanned restart of telephone dispatch and selected services
Leak count not disclosedRestart was planned for 11:00 on October 6; completion is not confirmed by this notice.
Timeline and sources (3)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Fourth reportOfficial announcement (Open external link)
- Planned restart of selected servicesOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
i-plug / OfferBox
A configuration flaw included names and email addresses in network responses accessible to customer companies through developer tools.
Official announcement: i-plug / OfferBox (Open external link)Possible leakMisconfiguration
Theoretical maximum: 314,009 studentsNot the number actually viewed.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Nikkei
Unauthorized logins to a Google Workspace account may have exposed employee and business-contact data.
Official announcement: Nikkei (Open external link)Possible leakUnauthorized access
1,646 peopleReaders and news sources are excluded. Separate from the Microsoft 365 incident.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Nikkei
The company disclosed an attack on a Microsoft 365 account and apparent leakage of contact information and some email contents.
Official announcement: Nikkei (Open external link)Possible leakUnauthorized access
Leak count under investigationAbout 9,000 counts impersonation emails sent, not leaked records.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Recruit
The company disclosed that a third party may have identified 3,687 email addresses as registered with Study Sapuri.
Official announcement: Recruit (Open external link)Possible leakUnauthorized access
3,687 email addresses
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Dai-ichi Life Group / Dai-ichi Life Insurance
The companies disclosed possible leakage of current and former employee data. Unauthorized access to customer data was not confirmed.
Official announcement: Dai-ichi Life Group / Dai-ichi Life Insurance (Open external link)Possible leakUnauthorized access
About 120,000 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
MoonStar
The company disclosed possible leakage of order information and impersonation emails. Card numbers and passwords were outside the affected scope.
Official announcement: MoonStar (Open external link)Possible leakUnauthorized access
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Japan Organization for Metals and Energy Security
Unauthorized access may have exposed email addresses of staff and external contacts.
Official announcement: Japan Organization for Metals and Energy Security (Open external link)Possible leakUnauthorized access
About 1,100 staff and 7,400 external email addressesCounts of email addresses, not unique people.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
ApplyNow (Kichiri Holdings subsidiary)
Unauthorized access to recruitment services may have exposed personal data. The affected scope for the electronic employment-contract service includes individual identification numbers.
Official announcement: ApplyNow (Kichiri Holdings subsidiary) (Open external link)Possible leakIncident at a vendor
Number under investigationImage and PDF files themselves, and interview videos, were outside the unauthorized-access scope.
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Wondertable (Open external link) · Leak confirmedNumber not disclosed
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
September 2026
-
VOISING
The final report confirmed leakage of personal information following unauthorized access.
Official announcement: VOISING (Open external link)Leak confirmedUnauthorized access
About 170,000 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Nabari Kintetsu Gas
The company disclosed possible leakage of customer data after unauthorized access at a vendor. Bank-account and card data were excluded.
Official announcement: Nabari Kintetsu Gas (Open external link)Possible leakIncident at a vendor
About 6,800 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
G-PLAN
The company disclosed possible leakage of member identifiers and related data. Identifier counts are not counts of unique people.
Official announcement: G-PLAN (Open external link)Possible leakUnauthorized access
Up to about 70,000 member identifiers
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Benefit One
The company disclosed that another customer downloaded mixed personal data and confirmed its deletion.
Official announcement: Benefit One (Open external link)Leak confirmedMisconfiguration
13,460 people across 2,322 organizations
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Service resumption notice, updated
Helpfeel
Leakage of user information and image metadata was confirmed. The second report additionally disclosed leaked metadata for deleted images.
Official announcement: Helpfeel (Open external link)Leak confirmedUnauthorized accessResumed September 27; earlier images remain subject to viewing and sharing restrictions
About 23.62 million user records and 666.4 million image-metadata recordsMetadata comprises about 490 million records, 2.4 million separately extracted records and about 174 million deleted-image records. These are not image files or unique people; overseas usage is included.
Timeline and sources (3)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Announcement / updateOfficial announcement (Open external link)
- Service resumption notice, updatedOfficial announcement (Open external link)
Sources checked: 2026-10-11
-
Seicomart
The company disclosed possible third-party viewing of member data and said purchase histories had not leaked.
Official announcement: Seicomart (Open external link)Possible leakUnauthorized access
About 570,000 accounts
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
TOPPAN / Sompo Japan Insurance
Insurance-related personal data were mistakenly sent to another insurer. Complete deletion at the recipient was confirmed.
Official announcement: TOPPAN / Sompo Japan Insurance (Open external link)Leak confirmedMisdelivery
177,426 people, potentially including duplicatesThe figure may include the same person more than once.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
eplus
Unauthorized access exposed refund-processing information. Card numbers were outside the affected scope.
Official announcement: eplus (Open external link)Leak confirmedUnauthorized access
1,463 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Daito Gas
The company disclosed possible leakage of customer information from historical files left on a vendor network.
Official announcement: Daito Gas (Open external link)Possible leakIncident at a vendor
About 124,000 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Ainokaze Toyama Railway
Unauthorized access to a reservation system may have exposed customer information.
Official announcement: Ainokaze Toyama Railway (Open external link)Possible leakUnauthorized access
1,409 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Shueisha
Shueisha disclosed leakage of Hapicomu registration and related data. Figures for different categories are not added together.
Official announcement: Shueisha (Open external link)Leak confirmedUnauthorized access
2,835 blogger records; other categories listed separatelySeparately: 630 project records, 11,237 emails and 10,780 business-contact records.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Tokyo Metro
The company disclosed possible access to Metpo email addresses and said the affected server held no other member information.
Official announcement: Tokyo Metro (Open external link)Possible leakUnauthorized access
About 59,000 email-address records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Nippon Rent-A-Car Service
Unauthorized access to the NR app may have exposed member information. For members who registered it, driver-license data and other information were also affected.
Official announcement: Nippon Rent-A-Car Service (Open external link)Possible leakUnauthorized access
41 peopleCard data is limited to the last four digits and cardholder names. The notice does not state leakage of license images.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Fines
A preliminary notice disclosed unauthorized access to a reservation system and the affected data scope. Detailed investigation continued.
Official announcement: Fines (Open external link)Under investigationUnauthorized access
1,536,322 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
Nichirei
The seventh report confirmed leakage of personal information. Normal warehouse and frozen-food shipping operations resumed at all sites on July 24.
Official announcement: Nichirei (Open external link)Leak confirmedRansomwareNormal operations resumed
3,308 delivery; 6,849 partner; 43,709 employee-related recordsSeparately, 43,709 employee-related records. Categories are not added together.
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Q'sai (Open external link) · Leak confirmed484 people
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
LEGOLAND Japan
The hotel disclosed the scope of reservations potentially affected by unauthorized access to a booking service.
Official announcement: LEGOLAND Japan (Open external link)Possible leakIncident at a vendor
1,557 reservations
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Second report
EPARK Relax & Esthe
External transfer of the PeakManager database was confirmed. Review revised the scope from about 33 million to about 22.18 million records.
Official announcement: EPARK Relax & Esthe (Open external link)Leak confirmedUnauthorized access
About 22.18 million records after reviewCannot be converted to unique people. Includes health information and five entries resembling card data.
Timeline and sources (2)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Second reportOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Co-op Yamaguchi
The cooperative disclosed possible leakage of member-related database records. Actual leakage was not confirmed.
Official announcement: Co-op Yamaguchi (Open external link)Possible leakUnauthorized access
69,586 / 143,126 / 365 / 4,218 records by categoryCategories are not added together. The 143,126-record category includes Coco Card numbers and PINs.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
RIZAP / APORITO
Malicious scripts on the online store may have exposed card and other information. Investigation continued in the third report.
Official announcement: RIZAP / APORITO (Open external link)Possible leakUnauthorized accessOnline store temporarily closed
Number not disclosedSeparate from the August ransomware incident at REXT.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
JGC Digital
A third party acquired account data for Azas and Sloop. The figures include multiple accounts held by the same person.
Official announcement: JGC Digital (Open external link)Leak confirmedUnauthorized access
About 40,000 Azas and 20,000 Sloop accounts
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Chibagin Shoten
The company disclosed possible leakage of customer data. Evidence of external transmission had not been confirmed.
Official announcement: Chibagin Shoten (Open external link)Possible leakUnauthorized access
About 192 individual and 722 corporate contacts; about 7,670 email-only contactsSeparately, about 7,670 email-only contacts. About 31 with account information are a subset.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
istyle
Information placed on a file-transfer service was accessible. Actual acquisition by an outside party was not confirmed.
Official announcement: istyle (Open external link)Possible leakMisconfiguration
10,997 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Murauchi.com
The second report disclosed leakage of personal information through unauthorized access. Card data and passwords were excluded.
Official announcement: Murauchi.com (Open external link)Leak confirmedUnauthorized access
7,716,811 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
LEAN BODY
The company disclosed leakage of account data. Card data were limited to items such as the last four digits; full numbers and security codes were not held.
Official announcement: LEAN BODY (Open external link)Leak confirmedUnauthorized access
About 440,000 accountsThe company expects the number of unique people to be lower than the account count.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
ROHTO Pharmaceutical
The company disclosed possible leakage of call recordings and associated information. Cause and scope remained under investigation.
Official announcement: ROHTO Pharmaceutical (Open external link)Possible leakUnauthorized access
Number under investigation
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Digital Agency
Possible leakage concerns officials and contractors. The disclosure does not report leakage of the general public's data or My Number identifiers.
Official announcement: Digital Agency (Open external link)Possible leakUnauthorized access
About 246,000 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
SAKURA internet
Unauthorized access affected sales-management and other systems. Viewing or acquisition was possible, but clear evidence of external removal was not confirmed.
Official announcement: SAKURA internet (Open external link)Possible leakUnauthorized access
1,360,563 accountsIncludes 951 rental-server accounts. A link between the two system compromises was not established.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
FUSO DENTSU
The company disclosed possible leakage of information about customers and contacts of business partners. Bank-account and card data were excluded.
Official announcement: FUSO DENTSU (Open external link)Possible leakUnauthorized access
26,489 records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Correction to third report
Charm
A correction to the third report refined the affected figures. The scope for former customers remained under review.
Official announcement: Charm (Open external link)Leak confirmedUnauthorized access
About 370,000 confirmed; about 20,000 possibly affected recordsCorrected on September 2. The 239 unauthorized logins are a separate measure.
Timeline and sources (3)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Second reportOfficial announcement (Open external link)
- Correction to third reportOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Mitsui Fudosan
The company disclosed possible leakage of employee-related and external-contact data. Viewing or acquisition of every record was not confirmed.
Official announcement: Mitsui Fudosan (Open external link)Possible leakUnauthorized access
Up to 19,000 employee-related and 36,000 external-contact records
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
August 2026
-
Yellow Hat
The company disclosed possible leakage of personal information and said it did not hold card, password or vehicle information.
Official announcement: Yellow Hat (Open external link)Possible leakUnauthorized access
Up to 1,801,499 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Kindal
Bulk export of information was confirmed, and the company disclosed the potentially affected personal-data scope.
Official announcement: Kindal (Open external link)Leak confirmedUnauthorized access
136,464 people potentially affectedThe figure describes the potentially affected scope.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Second report
Hands Holdings
Ransomware caused some internal systems to stop. The second report disclosed possible employee-data leakage and possible viewing of My Number data.
Official announcement: Hands Holdings (Open external link)Possible leakRansomwareSome systems stopped in June; recovery status not stated in the second report
Number not disclosed
Timeline and sources (2)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Second reportOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
KDDI
The PPC disclosure on August 19 identified the leak scope. People whose plaintext passwords were involved form a subset.
Official announcement: KDDI (Open external link)Leak confirmedUnauthorized access
12,231,954 peopleThe 7,616,173 people with plaintext passwords are a subset. Related company figures are not added.
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- KDDI Web Communications (CPI) (Open external link) · Leak confirmed1,250,543 email-account records
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
Faith Group
Ransomware encrypted and erased internal systems. Product shipping was suspended, with dispatch arrangements resuming on June 24.
Official announcement: Faith Group (Open external link)Possible leakRansomwareDispatch arrangements resumed
Number not disclosedAs of August 21, full system recovery was expected around the end of October.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Kaneko Agricultural Machinery
Following a ransomware incident, the company announced restoration of a simplified website and part of its systems on August 20.
Official announcement: Kaneko Agricultural Machinery (Open external link)Under investigationRansomwareSome systems restored
Scale not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
COTA
Following unauthorized access, the company rebuilt its environment and announced full internal-system recovery on August 20. It could not rule out leakage.
Official announcement: COTA (Open external link)Possible leakUnauthorized accessAll internal systems restored
See the announcement for category figures
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
CyberAgent / dotmoney
Unauthorized access suspended dotmoney and dotgift. Partner PointTown announced resumption of exchanges to dotmoney on August 20.
Official announcement: CyberAgent / dotmoney (Open external link)Leak not confirmedUnauthorized accessExchanges resumed at a partner
Number of affected users not disclosedThis does not establish full recovery of all functions or dotgift.
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- GMO Media / PointTown (Open external link) · Leak not confirmedExchanges to dotmoney resumed
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
KAGA SOLNET
Leakage of Academico Navi information was confirmed. The scope was refined from an initial maximum of about 170,000 records.
Official announcement: KAGA SOLNET (Open external link)Leak confirmedUnauthorized access
165,587 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
OCS
OCS disclosed leakage of customer and other data for its Family Link Service. New applications and service provision remained suspended in the fourth report.
Official announcement: OCS (Open external link)Leak confirmedUnauthorized accessAffected service still suspended
Number not disclosedThis does not mean all international transport operations stopped.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Tokushima Prefecture
Storage media from resident-register network equipment were unaccounted for and may have been disposed of without erasure.
Official announcement: Tokushima Prefecture (Open external link)Possible leakLoss of media
About 460,000 cumulative recordsAbout 180,000 cumulative records containing My Number identifiers are a subset.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
Estore
The second report confirmed data leakage. The announced figure is a maximum cumulative count including duplicates.
Official announcement: Estore (Open external link)Leak confirmedUnauthorized access
Up to 8,853,839 cumulative recordsCard information was limited to partial digits and related data, not full numbers or security codes.
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Designphil (Open external link) · Leak confirmedNumber not disclosed
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
Toshiba Tec
A specific ShopCraft customer could access another customer's data. Actual viewing was not confirmed.
Official announcement: Toshiba Tec (Open external link)Possible leakMisconfiguration
382,123 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
July 2026
-
Aflac Life Insurance Japan
The investigation disclosed leakage of policyholder and agency data. Policyholders whose account information was involved form a subset.
Official announcement: Aflac Life Insurance Japan (Open external link)Leak confirmedUnauthorized access
About 4.4 million policyholders and 40,000 agenciesAbout 220,000 people with account information are a subset. Policyholders and agencies are not added together.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
LY Corporation
Internal LINE GAME identifiers and related data were sent to an external advertising tool. Names, addresses and card information were not included.
Official announcement: LY Corporation (Open external link)Leak confirmedMisconfiguration
About 5.74 million unique users in JapanDistinct from about 6.66 million Japanese identifiers and about 6.1 million users worldwide.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Solid Advance
A malware incident led to suspension of the affected system. Other operating services continued after safety checks.
Official announcement: Solid Advance (Open external link)Leak not confirmedMalware infectionAffected system suspended
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
ASKUL
An investigation into an earlier attack added potentially affected records. This was not a new attack.
Official announcement: ASKUL (Open external link)Possible leakRansomware
About 600,000 additional recordsExternal leakage or misuse of the newly added information was not confirmed.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
SEIDENSHA ELECTRONICS
Server encryption and external transfer of some data were confirmed. Quoting, orders, production and shipping resumed on a temporary core system.
Official announcement: SEIDENSHA ELECTRONICS (Open external link)Leak confirmedRansomwareOperations resumed on temporary systems
Affected systems; personal-data count not disclosedThe company reported no traces of transfer of information received from customers or partners.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Kankyo Kaihatsu Kogyo
The company disclosed a system disruption caused by unauthorized access. Waste-oil and industrial-waste collection continued normally, while data leakage remained under investigation.
Official announcement: Kankyo Kaihatsu Kogyo (Open external link)Under investigationUnauthorized accessSome systems disrupted; collection operations continued
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Asahi Group Holdings
The group revised the potentially affected server-data scope for an earlier attack. External leakage of that scope was not confirmed.
Official announcement: Asahi Group Holdings (Open external link)Possible leakRansomware
1.525 million customer-inquiry records; 378,000 partner records, and other categoriesSeparately: 117,000 ceremonial contacts, 107,000 employee records and 162,000 family records. The confirmed scope announced on February 18 was not revised.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
FIVE FOXes
After detecting possible ransomware infection, the company stopped servers, internet and email functions. Shops and the separately operated online store remained open.
Official announcement: FIVE FOXes (Open external link)Under investigationCyberattackServers and email stopped; shops and online store remained open
Number under investigation
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Hachioji Gakuen Hachioji Junior and Senior High School
The school disclosed unauthorized server access and ransomware damage. Its main email address became unavailable during the response, while data leakage remained under investigation.
Official announcement: Hachioji Gakuen Hachioji Junior and Senior High School (Open external link)Under investigationRansomwareMain email address unavailable
Number under investigation
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Related update
Nostrum
Ransomware prevented servers from starting and suspended learning-support services. The company reported rebuilding in a new environment.
Official announcement: Nostrum (Open external link)Under investigationRansomwareLearning-support services suspended
Number not disclosed
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Fukuoka University (Open external link) · Possible leakUp to 33,668 people, including up to 800 with names
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
June 2026
-
REQREA
Tabiq identity-document images and related data were accessible. Unauthorized acquisition and secondary harm were not confirmed.
Official announcement: REQREA (Open external link)Possible leakMisconfiguration
1,060,338 peopleThe figure is not limited to residents of Japan.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Marutake
A ransomware incident involved data removal and public exposure. Pharmaceutical supply operated using temporary servers.
Official announcement: Marutake (Open external link)Leak confirmedRansomwareOperating on temporary servers
Number of affected people not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
SOFTSU
The company disclosed possible leakage of call timestamps, transcripts and related information. Actual leakage was not confirmed.
Official announcement: SOFTSU (Open external link)Possible leakUnauthorized access
159,850 telephone numbersCount of telephone numbers, not unique people.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Final report
ICOMSOFT
Unauthorized access led to isolation and rebuilding of web and email servers. The final report assessed leakage as unlikely but could not rule it out.
Official announcement: ICOMSOFT (Open external link)Possible leakUnauthorized accessWeb and email environments rebuilt; full recovery not expressly stated
Number not disclosed
Timeline and sources (2)
Timeline and sources
- Initial noticeOfficial announcement (Open external link)
- Final reportOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
2 Rinkan Yellow Hat
The final report confirmed personal-data leakage, refining the scope from an initial maximum of 3,455,754 people.
Official announcement: 2 Rinkan Yellow Hat (Open external link)Leak confirmedUnauthorized access
3,179,454 people
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Osaka Organic Chemical Industry
Unauthorized access disrupted website availability; the company reported recovery. Core operations, including order processing, were unaffected.
Official announcement: Osaka Organic Chemical Industry (Open external link)Under investigationUnauthorized accessWebsite restored; core operations unaffected
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Komatsu
Registered users could access information about other registered users.
Official announcement: Komatsu (Open external link)Possible leakMisconfiguration
139,302 peopleThe disclosure does not describe unrestricted public access.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Nippon Tele-net
The ransomware investigation disclosed potentially affected information categories. No traces of external transfer were detected.
Official announcement: Nippon Tele-net (Open external link)Possible leakRansomware
602,000 / 404,000 / 33,000 / 2,044 records by categorySeparately, 33,000 sales-contact records and 2,044 employee/family records. No aggregate total.
Timeline and sources · Related announcements (1)
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Related announcements (customers and principals)
- Mobility Platform (Open external link) · Possible leakNumber not disclosed
Figures are those announced by each organization. They arise from the same incident and are not added together.
Sources checked: 2026-10-10
-
Kyushu Electric Power Transmission and Distribution
The company disclosed lost storage media and possible exposure of customer data. Actual leakage was not confirmed.
Official announcement: Kyushu Electric Power Transmission and Distribution (Open external link)Possible leakLoss of media
Up to 10.9 million supply-contract recordsCount of supply contracts, not unique people.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Matsuzawa Shoten
Ransomware affected ordering and shipping for Gakufu Navi and Chumon-kun. Alternative methods remained in use after major functions resumed.
Official announcement: Matsuzawa Shoten (Open external link)Under investigationRansomwareMajor functions resumed
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Asahi-Seiki Manufacturing
Unauthorized access disrupted website display. The second report said the site was viewable again, with some functions still restricted.
Official announcement: Asahi-Seiki Manufacturing (Open external link)Leak not confirmedUnauthorized accessWebsite viewing restored; some functions restricted
Number not disclosedThe company reported no impact on internal core operations.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
May 2026
-
KDDI Web Communications (CPI)
DDoS attacks disrupted Web and FTP access. Recovery was announced for 10:30 on May 28.
Official announcement: KDDI Web Communications (CPI) (Open external link)Leak not confirmedDDoS attackRestored May 28 at 10:30
Some shared-hosting plansSeparate from the email-information breach.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Anabuki Housing Service
External leakage of files was confirmed. The final investigation refined the potentially affected personal-data scope.
Official announcement: Anabuki Housing Service (Open external link)Leak confirmedRansomware
207,773 possibly affected recordsThe figure does not confirm leakage of all 207,773 records.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Universal Music Japan
An investigation into unauthorized access to online stores in the previous year disclosed leakage of customer information.
Official announcement: Universal Music Japan (Open external link)Leak confirmedUnauthorized access
3,105,585 recordsA figure disclosed by a Japanese business, not necessarily a count of Japanese residents.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Aisan Technology
Unauthorized access and website tampering prompted temporary closure. The company rebuilt the environment and republished the site on May 14.
Official announcement: Aisan Technology (Open external link)Leak not confirmedWebsite defacementWebsite republished on May 14
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Medica Shuppan
The investigation revised the scope of possibly exposed personal data. Conclusive evidence of external removal was not detected.
Official announcement: Medica Shuppan (Open external link)Possible leakRansomware
About 641,000 people, potentially including duplicatesMay include the same person more than once.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Enessance Holdings
The company confirmed public exposure of some data from an earlier-year attack and disclosed the affected scope.
Official announcement: Enessance Holdings (Open external link)Leak confirmedRansomware
About 365,000 potentially affected recordsThe figure does not mean leakage of every record was confirmed.
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
April 2026
-
B&G Foundation
A malware attack disrupted servers. The foundation isolated affected servers and disconnected the network while working on recovery.
Official announcement: B&G Foundation (Open external link)Leak not confirmedMalware infectionAffected servers isolated and network disconnected
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
-
Setsunan University
The university confirmed partial tampering with its economics-faculty website and closed the affected site. Data leakage was not confirmed.
Official announcement: Setsunan University (Open external link)Leak not confirmedWebsite defacementAffected economics-faculty website closed
Number not disclosed
Timeline and sources
Timeline and sources
- Announcement / updateOfficial announcement (Open external link)
Sources checked: 2026-10-10
Methods and coverage
How incidents are counted
- The overview counts each listed incident once. Its figures cover the full list and do not change with the chart filters.
- The leak statuses also include 7 incidents with leakage unconfirmed and 0 reporting no leak. Confirmed incidents include partial confirmations; possible or investigating incidents include cases still being investigated.
- Outage counts include restored services. An incident can have both a leak and an outage, so these categories must not be added together.
How information counts are aggregated
- Reviewed figures from 62 incidents are included; 53 incidents are excluded. Confirmed and possible exposure are shown separately. Both sums include approximate figures, so neither is an exact nationwide total.
- Disclosed counts of people, accounts, records, contracts and other information units are each counted as one reported item per source unit. These are sums of reported scopes, not unique people or a standardized database-record count. Names and addresses within one person's record are not counted as separate items. Some domestic organizations' disclosures include overseas users.
- Certainty is reviewed for each numerical scope. If some leakage is confirmed but its count cannot be separated, the full reported scope is counted only under possible exposure. When separate confirmed and possible figures are disclosed, each is included in its own category. Maxima are not treated as confirmed solely because some leakage occurred.
- The first row excludes image metadata; the row below includes it when separately disclosed from user information. The rows are alternative scopes and must not be added together. Metadata is information attached to images, such as image IDs and source URLs, not the image files themselves or the number of affected people.
- Subsets, superseded figures and related customer disclosures already covered by a parent scope are not added again. Unknown counts or unresolved scopes are excluded, not treated as zero. The lists below preserve source units, calculation decisions and exclusions.
How the monthly chart is counted
- Each incident is counted once, in the month of its latest listed announcement, including related customer disclosures. Follow-ups and related disclosures are not counted as separate incidents. The chart does not show when incidents occurred or how many people were affected.
- Initial coverage includes announcements and follow-ups from April 10, 2026. Coverage criteria differ by month, and the latest month runs only through the data cutoff date. The chart therefore does not represent national incident totals or trends.
Incidents listed
- Only incidents announced by the company, organization or public body itself in Japan. Incidents known only from press reports or from an attacker's claims are not listed.
- Listed are incidents with announced figures of 1,000 or more, cyberattack-related service or business outages, identity documents, card data, My Number or health information, and vendor incidents affecting many customers. Unauthorized-access incidents with follow-up reports while the affected count is under investigation are also included.
- For incidents up to August 2026, only those with an announced figure of 100,000 or more, or with an outage that affected the business, are included.
- This is not a complete list of every incident announced in Japan.
Reading each entry
- Figures retain the units of each announcement, with subsets marked as part of the overall figure.
- “Confirmed”, “possible” and “under investigation” follow the wording of the announcement. When a later report changes the picture, the entry is updated and the earlier reports stay in the timeline.
- An incident at a vendor or cloud platform is listed once, with the announcements of its customers shown as related announcements.
- Each row shows the latest date among the listed sources, including related announcements. The timeline contains the announcements reviewed and the source-check date for that entry.
Corrections
If an entry is wrong, or a new announcement has changed the facts, please let us know through the contact form. We will check and correct it.
Figures included in the sums (62 incidents)
Each entry shows the number used in the sum alongside the original wording, including qualifiers such as “about” and “up to”. Even when some leakage is confirmed, the entire reported scope may not be confirmed leaked. Follow an incident link for its status and timeline.
Information confirmed exposed — 778,237,182 reported items
-
Resorttrust26,000 reported items
Group member information
About 26,000 member records; about 36,000 reservation records
Approximately 26,000 member records, separately disclosed from reservation information.
Official source -
Resorttrust36,000 reported items
Hotel reservation information
About 26,000 member records; about 36,000 reservation records
Approximately 36,000 reservation records; people are not deduplicated.
Official source -
Saitama Prefecture2,200 people
A list of about 2,200 people; details for 3 of them
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
HOTELIER7,919 people
7,919 people across 8 properties
People only; property counts are not added. Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Times Mobility6,600,000 accounts
About 6.6 million accounts — Of these, about 1.6 million accounts include identity-document images.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
nimoca521 reported items
521 records
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
The Monogatari Corporation10,788,963 reported items
10,788,963 records
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
White Essence1,050,000 accounts
About 1.05 million accounts
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
VOISING170,000 reported items
About 170,000 records
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Benefit One13,460 people
13,460 people across 2,322 organizations
People only; organization counts are not added. Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Helpfeel23,620,000 reported items
User information
About 23.62 million user records and 666.4 million image-metadata records — Metadata comprises about 490 million records, 2.4 million separately extracted records and about 174 million deleted-image records. These are not image files or unique people; overseas usage is included.
Disclosed user-information records, including anonymous and overseas usage, separate from image metadata.
Official source -
Helpfeel490,000,000 records
Image metadata
About 23.62 million user records and 666.4 million image-metadata records — Metadata comprises about 490 million records, 2.4 million separately extracted records and about 174 million deleted-image records. These are not image files or unique people; overseas usage is included.
Approximately 490 million image-metadata records, such as image IDs and source URLs, not image files.
Official source -
Helpfeel2,400,000 records
Separately extracted image metadata
About 23.62 million user records and 666.4 million image-metadata records — Metadata comprises about 490 million records, 2.4 million separately extracted records and about 174 million deleted-image records. These are not image files or unique people; overseas usage is included.
The initial notice describes 2.4 million separately extracted records in addition to the 490 million. The second notice leaves their scope, not the leakage itself, under investigation.
Official source -
Helpfeel174,000,000 records
Deleted-image metadata
About 23.62 million user records and 666.4 million image-metadata records — Metadata comprises about 490 million records, 2.4 million separately extracted records and about 174 million deleted-image records. These are not image files or unique people; overseas usage is included.
Approximately 174 million additional records confirmed in the second notice; deleted image files themselves are excluded.
Official source -
TOPPAN / Sompo Japan Insurance177,426 people
177,426 people, potentially including duplicates — The figure may include the same person more than once.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
eplus1,463 reported items
1,463 records
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
EPARK Relax & Esthe22,180,000 records
Leaked customer data records (EPARK)
About 22.18 million records after review — Cannot be converted to unique people. Includes health information and five entries resembling card data.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Murauchi.com7,716,811 reported items
7,716,811 records
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
LEAN BODY440,000 accounts
About 440,000 accounts — The company expects the number of unique people to be lower than the account count.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Charm370,000 reported items
Confirmed personal-information records
About 370,000 confirmed; about 20,000 possibly affected records — Corrected on September 2. The 239 unauthorized logins are a separate measure.
Uses the corrected figure of about 370,000; excludes the superseded 390,000 and 239 unauthorized logins.
Official source -
KDDI12,231,954 people
12,231,954 people — The 7,616,173 people with plaintext passwords are a subset. Related company figures are not added.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
KAGA SOLNET165,587 people
165,587 people
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Estore8,853,839 reported items
Up to 8,853,839 cumulative records — Card information was limited to partial digits and related data, not full numbers or security codes.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Aflac Life Insurance Japan4,400,000 people
About 4.4 million policyholders and 40,000 agencies — About 220,000 people with account information are a subset. Policyholders and agencies are not added together.
Information for about 4.4 million policyholders; the 220,000 bank-detail subset is not added.
Official source -
Aflac Life Insurance Japan40,000 agencies
Agency-related personal information
About 4.4 million policyholders and 40,000 agencies — About 220,000 people with account information are a subset. Policyholders and agencies are not added together.
Personal information for about 40,000 agencies, disclosed separately; not an outage count.
Official source -
LY Corporation6,660,000 reported items
Internal identifiers of domestic users
About 5.74 million unique users in Japan — Distinct from about 6.66 million Japanese identifiers and about 6.1 million users worldwide.
Uses about 6.66 million domestic identifiers rather than 5.74 million unique people. The 860,000 guest identifiers are not added separately because their relationship to the main count is not resolved here.
Official source -
2 Rinkan Yellow Hat3,179,454 people
3,179,454 people
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source -
Universal Music Japan3,105,585 reported items
3,105,585 records — A figure disclosed by a Japanese business, not necessarily a count of Japanese residents.
Counted as information confirmed leaked, externally transmitted or viewed by a third party in the disclosure.
Official source
Information potentially exposed — 44,545,476 reported items
-
BOOKOFF Group Holdings6,430,000 reported items
Up to about 6.43 million membership-number records — Count of membership numbers, not unique people.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
dip3,885,771 reported items
Up to 3,885,771 records — Leakage of every record in the maximum figure has not been confirmed.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
Daiichikosho8,724,000 reported items
About 8,724,000 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Hi-Ho38,509 contracts
Contracts affected by unauthorized logins (Hi-Ho)
38,509 contracts — A customer with multiple contracts may be counted more than once.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
Scala Communications713,126 reported items
Up to 713,126 cumulative inquiry records — Count of inquiries, not unique people.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
MrMax1,735,154 people
Up to 1,735,154 people
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
Daiki Suisan174,933 people
174,933 people
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Asahi Kasei Therapeutics514,000 people
Medical-professional information
About 514,000 healthcare professionals, plus other categories — About 44,000 with email addresses and other data are a subset. Separately, about 700 employees.
Up to approximately 514,000 people; the 44,000-person email subset is not added.
Official source -
Asahi Kasei Therapeutics700 people
Employee information
About 514,000 healthcare professionals, plus other categories — About 44,000 with email addresses and other data are a subset. Separately, about 700 employees.
Approximately 700 employees, disclosed as a separate information category.
Official source -
Active54,916 reported items
Up to 54,916 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
GMO Research & AI948,498 reported items
Up to 948,498 records — The 611 unauthorized exchanges are a separate measure from leaked records.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
i-plug / OfferBox314,009 people
Theoretical maximum: 314,009 students — Not the number actually viewed.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Nikkei1,646 people
1,646 people — Readers and news sources are excluded. Separate from the Microsoft 365 incident.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Recruit3,687 email addresses
Email addresses whose registration may have been identified (Study Sapuri)
3,687 email addresses
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Dai-ichi Life Group / Dai-ichi Life Insurance120,000 people
About 120,000 people
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Nabari Kintetsu Gas6,800 reported items
About 6,800 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
G-PLAN70,000 reported items
Up to about 70,000 member identifiers
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Seicomart570,000 accounts
About 570,000 accounts
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Daito Gas124,000 reported items
About 124,000 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Ainokaze Toyama Railway1,409 people
1,409 people
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Tokyo Metro59,000 reported items
About 59,000 email-address records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Nippon Rent-A-Car Service41 people
41 people — Card data is limited to the last four digits and cardholder names. The notice does not state leakage of license images.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Fines1,536,322 reported items
1,536,322 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
LEGOLAND Japan1,557 reservations
Hotel reservations potentially affected by unauthorized access (LEGOLAND Japan Hotel)
1,557 reservations
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
istyle10,997 people
10,997 people
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Digital Agency246,000 reported items
About 246,000 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
SAKURA internet1,360,563 accounts
1,360,563 accounts — Includes 951 rental-server accounts. A link between the two system compromises was not established.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
FUSO DENTSU26,489 reported items
26,489 records
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Charm20,000 reported items
Possibly exposed personal-information records
About 370,000 confirmed; about 20,000 possibly affected records — Corrected on September 2. The 239 unauthorized logins are a separate measure.
The approximately 20,000 records are disclosed separately from the 370,000 confirmed records.
Official source -
Yellow Hat1,801,499 people
Up to 1,801,499 people
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Kindal136,464 people
136,464 people potentially affected — The figure describes the potentially affected scope.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
Tokushima Prefecture460,000 reported items
About 460,000 cumulative records — About 180,000 cumulative records containing My Number identifiers are a subset.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Toshiba Tec382,123 people
382,123 people
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
ASKUL600,000 reported items
About 600,000 additional records — External leakage or misuse of the newly added information was not confirmed.
Only the additional scope in this update; earlier figures are not added. Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
REQREA1,060,338 people
1,060,338 people — The figure is not limited to residents of Japan.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
SOFTSU159,850 phone numbers
Phone numbers in potentially exposed call data (Softsu)
159,850 telephone numbers — Count of telephone numbers, not unique people.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Komatsu139,302 people
139,302 people — The disclosure does not describe unrestricted public access.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Kyushu Electric Power Transmission and Distribution10,900,000 supply points
Customer information on missing media, counted in supply points (Kyushu Electric Power Transmission and Distribution)
Up to 10.9 million supply-contract records — Count of supply contracts, not unique people.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Anabuki Housing Service207,773 reported items
207,773 possibly affected records — The figure does not confirm leakage of all 207,773 records.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source -
Medica Shuppan641,000 people
About 641,000 people, potentially including duplicates — May include the same person more than once.
Counted as a disclosed scope of possible exposure, accessibility or continuing investigation.
Official source -
Enessance Holdings365,000 reported items
About 365,000 potentially affected records — The figure does not mean leakage of every record was confirmed.
Some leakage or access was confirmed, but a confirmed count cannot be separated from this scope. The entire figure is counted only under possible exposure.
Official source
Excluded incidents and reasons (53 incidents)
No settled figure: undisclosed, under investigation or not specified (30 incidents)
-
Number under investigation
Official source -
Number not disclosed
Official source -
Number under investigation
Official source -
Leak count not disclosed — Restart was planned for 11:00 on October 6; completion is not confirmed by this notice.
Official source -
Leak count under investigation — About 9,000 counts impersonation emails sent, not leaked records.
Official source -
Number not disclosed
Official source -
Number under investigation — Image and PDF files themselves, and interview videos, were outside the unauthorized-access scope.
Official source -
Number not disclosed — Separate from the August ransomware incident at REXT.
Official source -
Number under investigation
Official source -
Number not disclosed
Official source -
Number not disclosed — As of August 21, full system recovery was expected around the end of October.
Official source -
Scale not disclosed
Official source -
See the announcement for category figures
Official source -
Number of affected users not disclosed — This does not establish full recovery of all functions or dotgift.
Official source -
Number not disclosed — This does not mean all international transport operations stopped.
Official source -
Number not disclosed
Official source -
Affected systems; personal-data count not disclosed — The company reported no traces of transfer of information received from customers or partners.
Official source -
Number not disclosed
Official source -
Number under investigation
Official source -
Number under investigation
Official source -
Number not disclosed
Official source -
Number of affected people not disclosed
Official source -
Number not disclosed
Official source -
Number not disclosed
Official source -
Number not disclosed
Official source -
Number not disclosed — The company reported no impact on internal core operations.
Official source -
Some shared-hosting plans — Separate from the email-information breach.
Official source -
Number not disclosed
Official source -
Number not disclosed
Official source -
Number not disclosed
Official source
Multiple categories or scopes require further reconciliation (14 incidents)
-
About 307,000 members (estimated) — Includes about 126,000 with email addresses and about 42,000 employee and demo accounts.
Official source -
310 files publicly exposed; 1,044,906 records potentially affected — 27 applicants and employees were notified. These figures use different units and scopes and are not added.
Official source -
Up to 323,000 email records; 362,000 partial card-data records — Maximum figures for separate data fields, not a combined count of people.
Official source -
449 resumes; 1,845 employment-history documents
Official source -
Up to 7,200 email addresses; up to 6,000 transaction records — Separately, data for 4,778 employees. Categories are not added together.
Official source -
About 1,100 staff and 7,400 external email addresses — Counts of email addresses, not unique people.
Official source -
2,835 blogger records; other categories listed separately — Separately: 630 project records, 11,237 emails and 10,780 business-contact records.
Official source -
3,308 delivery; 6,849 partner; 43,709 employee-related records — Separately, 43,709 employee-related records. Categories are not added together.
Official source -
69,586 / 143,126 / 365 / 4,218 records by category — Categories are not added together. The 143,126-record category includes Coco Card numbers and PINs.
Official source -
About 40,000 Azas and 20,000 Sloop accounts
Official source -
About 192 individual and 722 corporate contacts; about 7,670 email-only contacts — Separately, about 7,670 email-only contacts. About 31 with account information are a subset.
Official source -
Up to 19,000 employee-related and 36,000 external-contact records
Official source -
1.525 million customer-inquiry records; 378,000 partner records, and other categories — Separately: 117,000 ceremonial contacts, 107,000 employee records and 162,000 family records. The confirmed scope announced on February 18 was not revised.
Official source -
602,000 / 404,000 / 33,000 / 2,044 records by category — Separately, 33,000 sales-contact records and 2,044 employee/family records. No aggregate total.
Official source
Overlap between separate events at the same service is unresolved (8 incidents)
-
About 14.64 million records — Includes about 4.13 million hashed-password records. Not added to the other two events.
Official source -
17,780 records, including duplicates — Other affected information is still being counted. Not added to the other two events.
Official source -
About 12,000 reservations — Not a count of people including companions. Not added to the other two events.
Official source -
2,155,345 records
Official source -
26 records — Not added to the LAWSON ID event.
Official source -
687 accounts — The three events are not added because overlap is unknown. The date is the information cutoff stated in the notice.
Official source -
313 accounts — The three events are not added because overlap is unknown. The date is the information cutoff stated in the notice.
Official source -
15,382 accounts — The three events are not added because overlap is unknown. The date is the information cutoff stated in the notice.
Official source
Organizations affected by an outage, a different measure from leaked data (1 incident)
-
495 customer companies and public bodies
Official source