INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Japan Sees Sharp Rise in Web Data Leaks Amid Attacks

| 2026-10-08 15:45 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
In the past few months, Japan has seen a sharp rise in web data leaks amid mobile API abuse and Metabase attacks. The JPCERT Coordination Center reported that attackers have exploited known software flaws to target Japanese organizations' systems, including business intelligence tools and employee-facing management systems. Data stored in these systems leaked in some cases, with an estimated 6.6 million accounts compromised by a third party on September 28, followed by the leak of identity documents from about 1.6 million accounts just one day later. The attacks are separate from ransomware incidents and may be increasing, leaving defenders with limited information to defend against them, including eight source IP addresses, five User-Agent strings, and a list of API controls.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-72898 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

69.10.•••.•••
210.149.•••.•••
221.216.•••.•••
54.95.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-72898CVE-2026-72898
Target & Sectors
PL JP KR FR
Incident Timeline
‎August 6
Metabase's August 6 security update fixed CVE-2026-72898, a zero-day flaw exploited against the company's own cloud service.
vulnerability CVE-2026-72898
infrastructure 0.63.5
infrastructure 0.63.13
infrastructure 0.62.9
infrastructure 0.62.16
infrastructure 0.61.11
infrastructure 0.61.18
infrastructure 0.60.17
infrastructure 0.60.24
infrastructure 0.59.21
infrastructure 0.59.28
infrastructure 0.58.24
infrastructure 0.58.31
general_metric 63 0.63.13
general_metric 61 0.61.11
general_metric 60 0.60.17
general_metric 59 0.59.21 0.59.28
organisation Metabase
‎August 11
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability to its Known Exploited Vulnerabilities catalog on August 11, advising users to upgrade their systems.
organisation Known Exploited
tactic T1588.006 - Vulnerabilities
‎August 14
Threat actors exploited a vulnerability in Metabase, prompting the software to issue an urgent upgrade notice on August 14.
‎September 2026
Threat actors exploited the SQL injection flaw in Metabase, CVE-2026-72898, to target companies and leak large amounts of personal data.
observable 172.86.91.7
observable 210.149.87.120
observable 213.163.202.171
observable 221.216.140.129
observable 221.216.140.49
observable 3.112.252.14
observable 54.95.112.6
observable 69.10.51.162
organisation Macintosh
organisation Intel Mac OS
organisation KHTML
data_breach 2026 early September
data_breach 30 September
organisation SQL
organisation CVSS
organisation JPCERT/CC's
organisation Operators
organisation POST
organisation Rotate
organisation Review Metabase
organisation Indicators and Checks
organisation Limit
organisation Enforce
‎September 28
A third party obtained data on approximately 6.6 million accounts from Park24's Times Car car-sharing service web system on September 28.
general_metric 6.6 accounts
‎October 5
Threat actors exploited vulnerabilities in Monogatari Corporation's mobile app to leak 10,788,963 records from its member system.
organisation Monogatari Corporation
data_breach 10,788,963 records
‎October 6
Between October 6 and this year, Japan experienced a sharp rise in web data leaks resulting from mobile API abuse and Metabase attacks.
target_region Japan
general_metric 119 incidents
‎October 7
The Personal Information Protection Commission of Japan issued its own alert on October 7, citing an analysis by the Security Research Center at Macnica.
target_region Japan
organisation Personal Information Protection Commission
organisation the Security Research Center
‎October 8, 2026
Threat actors exploited a known flaw in Metabase, a Business Intelligence tool, to target Japanese users.
organisation IP
organisation API
organisation BI
‎August 12 to September 7
A third party exploited a flaw in AhaSlides' Metabase, gaining unauthorized access from August 12 to September 7.
organisation AhaSlides
‎2026/10/08
Attackers behind a string of personal data leaks at Japanese organizations abused APIs for mobile apps and targeted known software flaws.
organisation Japan Sees Sharp Rise
organisation the JPCERT Coordination Center
organisation JPCERT/CC
organisation OWASP
Tactical Metrics
Metrics
data_breach
30
September
Metrics
infrastructure
‎0.63.5
Software Version
Metrics
infrastructure
‎0.63.13
Software Version
Metrics
infrastructure
‎0.62.9
Software Version
Metrics
infrastructure
‎0.62.16
Software Version
Metrics
infrastructure
‎0.61.11
Software Version
Metrics
infrastructure
‎0.61.18
Software Version
Metrics
infrastructure
‎0.60.17
Software Version
Metrics
infrastructure
‎0.60.24
Software Version
Metrics
infrastructure
‎0.59.21
Software Version
Metrics
infrastructure
‎0.59.28
Software Version
Metrics
infrastructure
‎0.58.24
Software Version
Metrics
infrastructure
‎0.58.31
Software Version
Metrics
data_breach
2,026
Early September
Metrics
data_breach
10,788,963
Records
Intelligence Sources