Security1 publisherNot yet confirmed elsewhere3 min readPublished
JPCERT/CC links Japan's data-leak run to app APIs and BI tools owners thought were internal
JPCERT/CC says attackers abused mobile-app APIs and exploited a known Metabase flaw in a leak run Macnica puts at 119 Japanese incidents this year. Some leaks came from BI tools and staff systems their owners never expected outsiders to reach, so the alert asks for access control on every endpoint, public or not.
The Watch · Security desk

What happened
- Macnica counts 81 of this year's 119 incidents from July onward, against 84 for all of 2025 and 62 for 2024.
- Park24 said on September 28 that data on about 6.6 million Times Car accounts was obtained, and a day later that ID documents leaked from about 1.6 million.
- Monogatari's Yakiniku King app lost 10,788,963 records from its member system, INTERNET Watch reported on October 5.
- Metabase's list of minimum safe releases, last updated August 14, sits above the first fix for the exploited flaw.
- Macnica found 99 similar cases in 13 other countries and regions, mostly from July to September, 30 of them in South Korea.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Metabase operators who applied only the first fix are still below the vendor's floor and have to check their versions against the August 14 list.
- exposure Any API key shipped inside a released app is effectively in attackers' hands, and calls made with it can pass for ordinary app traffic in server logs.
- contradiction Macnica's 119 is a series defined by its own similarity test, while JPCERT/CC says its account does not mean one method was used everywhere, so the rising trend and the attack method rest on different evidence.
The first of three patterns in the alert is unauthorized calls to the APIs that manage an app on the back end [27]. Some of those calls altered stored information [20]. One way in starts with the app itself. JPCERT/CC has multiple reports of attackers analyzing a publicly released smartphone app to find its API endpoints and keys [21]. Macnica, working from incident response and log analysis, found attackers who took API keys from an app and called the API in a way that looked like normal use [24].
Other requests go where the app's screens never do [22]. Attackers hit internal APIs to change a user's privileges, create unauthorized accounts, probe the server's responses by adding or stripping a header or sending a malformed authentication token, and pull account details through blind NoSQL injection [22]. Some arrive with API keys stolen when another system was compromised [23].
They search each site and its APIs for any flaw that hands over data. The list includes APIs that return more data than necessary, APIs with excessive privileges, member functions open to anonymous users, logic errors and session management faults [25]. Weak admin-screen passwords and exploitation of known flaws were confirmed in some cases [26].
The Metabase route is shorter. The flaw is known and attackers have exploited it [8], so anyone who can reach an unpatched server has a way in. The Hacker News report identifies the flaw without a CVE number.
How much of the run these methods explain is less settled. JPCERT/CC called what it knows "limited and fragmentary" [3]. It said its account does not mean the same method was used in every incident [4]. Of the 81 disclosures since July, 65 gave too little detail to tell how the attackers got in [14]. That is about 80 percent [29]. JPCERT/CC did not name an attacker or any affected organization [2]. Its indicators are eight source IP addresses and five User-Agent strings [6].
JPCERT/CC said the attacks stand apart from ransomware and other routine incidents, that they expose personal data in large volumes, and that they may be on the rise [10]. For a count, it relies on Macnica's October 7 analysis [11]. That count covers only incidents Macnica judged similar to the current series, leaving out ransomware and cases it ties to other groups [13]. On that basis Japan had 38 such incidents from January through June [28]. This year's total already runs 35 above all of 2025 [30].
Targets have spread from online shops to member services, business systems and customer support, including a library's catalog search and a tourist train's seat booking system [15]. At Park24, identity documents leaked from about a quarter of the accounts whose data was taken [31]. Park24 and Monogatari both said at the time that the cause was still under investigation [18].
What to watch
- Park24 and Monogatari closing their investigations, and whether either cause turns out to be app-API abuse or the Metabase flaw.
- A JPCERT/CC update that names an actor, ties a CVE to the Metabase flaw, or adds indicators beyond the eight IPs and five User-Agent strings.
- Whether the cases Macnica counted in South Korea, France and Poland show the same API techniques seen in Japan.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
JPCERT/CC said in an October 8, 2026 alert that attackers behind a string of personal data leaks at Japanese organizations abused APIs for mobile apps and targeted known software flaws.
- [2]
The JPCERT/CC alert names no attacker and no affected organization.
- [3]
JPCERT/CC called what it knows "limited and fragmentary" (translated from Japanese).
- [4]
JPCERT/CC said its account does not mean the same method was used in every incident.
- [5]
Besides consumer apps, systems hit include business intelligence tools and employee-facing management systems that their operators did not expect the public to reach; data stored in them leaked in some cases.
- [6]
The alert includes eight source IP addresses and five User-Agent strings.
- [7]
The alert includes a list of API controls, including access controls on every endpoint, public or not.
- [8]
The only product the alert names as a target is Metabase, a BI tool with a known flaw that attackers have exploited.
- [9]
Metabase has urged users to upgrade to at least the minimum safe releases in a list last updated August 14; those releases are newer than the first fix for the flaw.
- [10]
The leaks came one after another around September 2026; JPCERT/CC said the attacks are separate from ransomware and other routine incidents, lead to leaks of large amounts of personal data, and may be increasing.
- [11]
JPCERT/CC gave no count; the alert cites an October 7 analysis by Macnica's Security Research Center.
- [12]
Macnica counted 119 incidents made public this year through October 6 in which personal data was stolen or leaked through web systems run by organizations in Japan, against 84 in all of 2025 and 62 in 2024; 81 of this year's 119 came in July or later.
- [13]
Macnica's count covers only incidents it judged similar to the current series and leaves out ransomware and cases it ties to other attack groups.
- [14]
Of the 81 incidents made public since July, 65 gave too little detail to tell how the attackers got in.
- [15]
Targets have spread from online shops to member services, business systems and customer support; recent cases include a library's catalog search and a tourist train's seat booking system.
- [16]
Park24 said on September 28 that a third party obtained data on about 6.6 million accounts from the web system of its Times Car car-sharing service; a day later it said identity documents such as driver's license images leaked from about 1.6 million accounts.
- [17]
Monogatari Corporation, which runs Yakiniku King, said 10,788,963 records leaked from the member system of its Yakiniku King app, INTERNET Watch reported on October 5.
- [18]
Park24 and Monogatari both said at the time that the cause was still under investigation.
- [19]
Macnica found 99 similar cases in 13 other countries and regions, mostly from July to September, including 30 in South Korea, 11 in France and 8 in Poland; it does not know whether Japan is the only target.
- [20]
The first pattern is unauthorized requests to the management APIs behind an app; in some cases those requests rewrote information.
- [21]
JPCERT/CC has received multiple reports of attackers analyzing a publicly released smartphone app to find its API endpoints and keys.
- [22]
Attackers attack internal APIs that cannot be used through the app's screens; reported actions include changing a user's privileges, creating unauthorized accounts, comparing server responses when a header is added or removed or a malformed authentication token is sent, and finding account details through blind NoSQL injection.
- [23]
Attackers use API keys stolen when another system was compromised.
- [24]
Macnica, from incident response and log analysis, reports the same method; in some cases attackers took API keys from a smartphone app and called the API in a way that looked like normal use.
- [25]
Attackers search each site and its APIs for any flaw that allows them to obtain data, including APIs that return more data than necessary, APIs with excessive privileges, member functions accessible to anonymous users, logic errors and session management faults.
- [26]
Attacks on weak admin-screen passwords and exploitation of known flaws were also confirmed in some cases.
- [28]
Macnica's count implies 38 similar incidents made public in Japan from January through June 2026.
- [29]
About 80 percent of the incidents made public since July gave too little detail to tell how attackers got in.
- [30]
This year's 119 incidents through October 6 exceed the 84 counted for all of 2025 by 35.
- [31]
Identity documents leaked from about a quarter of the Park24 Times Car accounts whose data was obtained.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comJapan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Business intelligence toolsFollow
- Cybersecurity in JapanFollow
- Data BreachesFollow
- API SecurityFollow