Skip to content
>_ITDITDWeb Security Platform

Security Guides

Asahi Kasei Therapeutics healthcare-professional site breach (about 514,000 people): what may have leaked and what doctors, pharmacists and nurses should do

Unauthorized access to Pharma DIGITAL, Asahi Kasei Therapeutics' information site for healthcare professionals, may have exposed names, facilities and specialties of about 514,000 people. What may have leaked, what did not, and what to do today.

Published 2026-10-06 Updated 2026-10-06 Last verified 2026-10-06 9 min read

For: doctors, pharmacists, nurses and other healthcare professionals registered on drug companies' information sites, and people who handle IT or security at hospitals and pharmacies. This article is based on the official notice from Asahi Kasei Therapeutics Co. Ltd. and does not cover attack techniques.

What doctors, pharmacists and nurses should do today

1

Never log in to medical information sites from email links

The data that may have leaked includes names, facility names, facility addresses, job types and specialties. Together, these let someone write a convincing fake email with your correct name, workplace and specialty.

The company asks people not to open URLs in suspicious emails, and not to open attachments or enter personal data. Even if an email talks about "re-registering your membership", "our apology" or "the site has reopened", do not click; go in from your usual bookmark (how to spot fakes: What is phishing?).

2

Check seminar, society and survey invitations on the organizer's official site

Healthcare professionals routinely receive invitations to drug-company seminars and webinars, academic society events and paid surveys. With this data, a fake can be tailored to your own specialty.

If an invitation asks for an ID, password or medical license number to register or watch, do not use the email link. Open the official website of the company or society yourself and check that the same event is listed there.

3

If you reused the password, change it elsewhere

The notice does not list passwords among the data that may have leaked, but it does not say they were unaffected either. Each drug company runs its own site for healthcare professionals, so these are exactly the kind of sites where people reuse one password.

If you used your Pharma DIGITAL password on other medical sites, hospital systems or your email, change it there to a separate one (how to manage them: How to choose a password manager; how to check: How to check if your password has leaked).

4

Turn on two-step verification where it is available

On a site that only asks for a password, typing it into a fake site is enough for someone to get in. If the medical sites and email you use often have a two-step verification option (an extra check at sign-in, such as an app on your phone), turn it on.

Not every site offers it. For which method to choose, see Choosing MFA the right way.

5

Use the contact points listed in the company's notice

The company has set up a dedicated contact point. Its phone number changes from October 8, so use the number in the company's notice (Japanese), not one written in an email you received.

What happened (from Asahi Kasei Therapeutics' notice)

On October 6, 2026, Asahi Kasei Therapeutics Co. Ltd. published a notice on unauthorized access to Pharma DIGITAL, its information website for healthcare professionals, and the possible leak of personal data. Everything below is based on that notice.

  1. October 2, 2026

    The company was notified by the site's contractor that unauthorized access to the site had occurred. It shut the site down immediately.
  2. October 6

    The company went public. It said the access route had been fixed, that it was reporting to the relevant authorities, and that it was continuing the investigation with outside specialists.
~514,000
Healthcare professionals (name, facility name and address, job type, specialty, etc.)
~44,000
Email address and more, in addition to the above
~700
Company employees (name, email address, photo)
None found
Misuse or harm (as of October 6)
Data that may have leaked (from Asahi Kasei Therapeutics' notice)
Where
The member database of Pharma DIGITAL, the company's information site for healthcare professionals
Healthcare professionals
Name, facility name, facility address, job type, specialty and more: about 514,000 people
Email addresses
In addition to the above, email address and more: about 44,000 people
Company employees
Name, email address, photo: about 700 people
Not stored
Credit card data, sensitive personal data
How it was found
On October 2, the site's contractor reported the unauthorized access to the company
Company response
Site shut down immediately, access route fixed, reports to authorities, investigation with outside specialists
Cause
Not disclosed

The company's notice gives no total. Kyodo News added the groups together and reported up to about 558,700 people.

What the leaked data could be used for

What stands out here is that, alongside names and contact details, the data includes workplace, job type and specialty. That tells a scammer whom to target and which topic will get an email opened.

Name + email address + specialty

↓

Fake seminar, society or survey invitations matched to your field

→ Check on the organizer's official site / never log in from links

Name + facility name + facility address

↓

Messages claiming to be from a drug company, sent to the hospital's main address or by post

→ Confirm with your usual representative or the official contact point

Combinations of data that may have leaked, and the matching action

Not stored or not found, per the notice

  • Credit card data (not stored)
  • Sensitive personal data (not stored)
  • Misuse or harm (as of October 6)

May have leaked

  • Name, job type, specialty
  • Facility name and address
  • Email address (about 44,000 people)
  • Company employees' names, email addresses and photos

A note on reading the numbers: email addresses for 44,000 does not mean the rest are safe

The notice says about 44,000 people's email addresses are involved, but names and workplaces for about 514,000 are included. Messages naming you could also arrive at your hospital's main email address, by post or by phone.

Names and email addresses of about 700 company employees are included too. An email using a real employee's name is not proof that it is genuine. Confirm any message from someone claiming to be your contact through the channel you normally use with them.

For hospital and pharmacy IT staff

The professionals involved work at hospitals, clinics and pharmacies across Japan. Rather than leaving this to individuals, it is a chance to review how your workplace handles incoming mail. The cause has not been disclosed, so this section sticks to what the receiving side can do. For preparing against incidents that stop clinical work, see Hospitals whose care was halted by cyberattacks in 2026.

1

Warn staff and set one place to report suspicious emails

Tell physicians, pharmacy and nursing staff to be careful with emails claiming to be from drug companies, academic societies or seminar organizers. Always include where to forward suspicious emails (for example, one IT department address).

Collected reports show how many people in the hospital got the same fake, and let you block the sender for everyone at once.

2

Tag mail from outside the organization as external

Most mail servers and email services can add an "External" label to the subject or top of messages that come from outside. Even an email using a real drug-company employee's name then shows at a glance that it came from outside.

Also check that mail failing sender-domain authentication (SPF, DKIM, DMARC) is sent to the junk folder.

3

Ask staff to keep work-system passwords separate from outside sites

If the password for the electronic medical records, VPN or hospital email is the same as on a medical information site, a password typed into a fake site becomes a way into the hospital. Ask staff never to use internal-system passwords on outside sites, and set up multi-factor authentication on the VPN and email (choosing a method: Choosing MFA the right way).

Sources (public record)

The facts in this article are based on the public information below. Undisclosed intrusion methods and causes are not speculated on.

  • Asahi Kasei Therapeutics Co. Ltd., notice on unauthorized access to the healthcare-professional information site Pharma DIGITAL and the possible leak of personal data (October 6, 2026, Japanese) — asahi-kasei.co.jp
  • Kyodo News (October 6, 2026, via Chunichi Shimbun, Japanese) — chunichi.co.jp

Update history

2026-10-06: First version, based on Asahi Kasei Therapeutics' notice of October 6. The company says its investigation continues; this article will be updated when new facts are published.

FAQ

QWhat was leaked in the Asahi Kasei Therapeutics breach?
A

According to Asahi Kasei Therapeutics' notice of October 6, 2026, personal data in the member database of Pharma DIGITAL, its site for healthcare professionals, may have been viewed or taken. This covers names, facility names, facility addresses, job types, specialties and more for about 514,000 healthcare professionals; email addresses and more in addition to those items for about 44,000; and names, email addresses and photos of about 700 company employees.

QHow many people are affected in total?
A

The company's notice gives no total, only the figure for each group (about 514,000 healthcare professionals, about 44,000 with email addresses, about 700 employees). Kyodo News added these together and reported up to about 558,700 people.

QWere passwords or credit card details leaked?
A

The company says the site did not store credit card data or sensitive personal data such as medical history. The notice does not list passwords among the data that may have leaked, but it also does not say passwords were unaffected. If you used the same password on other medical information sites or elsewhere, changing it there is a sensible precaution.

QHas the data been misused?
A

The company says that as of October 6, no misuse of personal data or other harm caused by the incident had been found. It shut the site down immediately, says the access route has been fixed, and is continuing its investigation with outside specialists.

QWhat scams should I watch for?
A

The company warns of secondary harm from suspicious emails and impersonation, and asks people not to open URLs or attachments in suspicious emails or enter personal data. An email that correctly names you, your workplace and your specialty is not proof it is genuine. Check any email claiming to be from a drug company, academic society or seminar organizer by opening the organizer's official website yourself.

QWhat caused the breach?
A

As of October 6, 2026, the method and cause had not been disclosed. The company says it was notified by the site's contractor on October 2 and is continuing its investigation with outside specialists.