Skip to content

Security1 publisherNot yet confirmed elsewhere3 min readPublished

JPCERT/CC links Japan's data-leak run to app APIs and BI tools owners thought were internal

JPCERT/CC says attackers abused mobile-app APIs and exploited a known Metabase flaw in a leak run Macnica puts at 119 Japanese incidents this year. Some leaks came from BI tools and staff systems their owners never expected outsiders to reach, so the alert asks for access control on every endpoint, public or not.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying JPCERT/CC links Japan's data-leak run to app APIs and BI tools owners thought were internal
Generated illustration

What happened

  • Macnica counts 81 of this year's 119 incidents from July onward, against 84 for all of 2025 and 62 for 2024.
  • Park24 said on September 28 that data on about 6.6 million Times Car accounts was obtained, and a day later that ID documents leaked from about 1.6 million.
  • Monogatari's Yakiniku King app lost 10,788,963 records from its member system, INTERNET Watch reported on October 5.
  • Metabase's list of minimum safe releases, last updated August 14, sits above the first fix for the exploited flaw.
  • Macnica found 99 similar cases in 13 other countries and regions, mostly from July to September, 30 of them in South Korea.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Metabase operators who applied only the first fix are still below the vendor's floor and have to check their versions against the August 14 list.
  • exposure Any API key shipped inside a released app is effectively in attackers' hands, and calls made with it can pass for ordinary app traffic in server logs.
  • contradiction Macnica's 119 is a series defined by its own similarity test, while JPCERT/CC says its account does not mean one method was used everywhere, so the rising trend and the attack method rest on different evidence.

The first of three patterns in the alert is unauthorized calls to the APIs that manage an app on the back end [27]. Some of those calls altered stored information [20]. One way in starts with the app itself. JPCERT/CC has multiple reports of attackers analyzing a publicly released smartphone app to find its API endpoints and keys [21]. Macnica, working from incident response and log analysis, found attackers who took API keys from an app and called the API in a way that looked like normal use [24].

Other requests go where the app's screens never do [22]. Attackers hit internal APIs to change a user's privileges, create unauthorized accounts, probe the server's responses by adding or stripping a header or sending a malformed authentication token, and pull account details through blind NoSQL injection [22]. Some arrive with API keys stolen when another system was compromised [23].

They search each site and its APIs for any flaw that hands over data. The list includes APIs that return more data than necessary, APIs with excessive privileges, member functions open to anonymous users, logic errors and session management faults [25]. Weak admin-screen passwords and exploitation of known flaws were confirmed in some cases [26].

The Metabase route is shorter. The flaw is known and attackers have exploited it [8], so anyone who can reach an unpatched server has a way in. The Hacker News report identifies the flaw without a CVE number.

How much of the run these methods explain is less settled. JPCERT/CC called what it knows "limited and fragmentary" [3]. It said its account does not mean the same method was used in every incident [4]. Of the 81 disclosures since July, 65 gave too little detail to tell how the attackers got in [14]. That is about 80 percent [29]. JPCERT/CC did not name an attacker or any affected organization [2]. Its indicators are eight source IP addresses and five User-Agent strings [6].

JPCERT/CC said the attacks stand apart from ransomware and other routine incidents, that they expose personal data in large volumes, and that they may be on the rise [10]. For a count, it relies on Macnica's October 7 analysis [11]. That count covers only incidents Macnica judged similar to the current series, leaving out ransomware and cases it ties to other groups [13]. On that basis Japan had 38 such incidents from January through June [28]. This year's total already runs 35 above all of 2025 [30].

Targets have spread from online shops to member services, business systems and customer support, including a library's catalog search and a tourist train's seat booking system [15]. At Park24, identity documents leaked from about a quarter of the accounts whose data was taken [31]. Park24 and Monogatari both said at the time that the cause was still under investigation [18].

What to watch

  • Park24 and Monogatari closing their investigations, and whether either cause turns out to be app-API abuse or the Metabase flaw.
  • A JPCERT/CC update that names an actor, ties a CVE to the Metabase flaw, or adds indicators beyond the eight IPs and five User-Agent strings.
  • Whether the cases Macnica counted in South Korea, France and Poland show the same API techniques seen in Japan.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    JPCERT/CC said in an October 8, 2026 alert that attackers behind a string of personal data leaks at Japanese organizations abused APIs for mobile apps and targeted known software flaws.

    ReportedSupportedView cited source
  2. [2]

    The JPCERT/CC alert names no attacker and no affected organization.

    ReportedSupportedView cited source
  3. [3]

    JPCERT/CC called what it knows "limited and fragmentary" (translated from Japanese).

    ReportedSupportedSource: JPCERT/CC alert, as translated by The Hacker NewsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 8, 2026

    Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories