Security Guides
Asahi Kasei Therapeutics healthcare-professional site breach (about 514,000 people): what may have leaked and what doctors, pharmacists and nurses should do
Unauthorized access to Pharma DIGITAL, Asahi Kasei Therapeutics' information site for healthcare professionals, may have exposed names, facilities and specialties of about 514,000 people. What may have leaked, what did not, and what to do today.
For: doctors, pharmacists, nurses and other healthcare professionals registered on drug companies' information sites, and people who handle IT or security at hospitals and pharmacies. This article is based on the official notice from Asahi Kasei Therapeutics Co. Ltd. and does not cover attack techniques.
What doctors, pharmacists and nurses should do today
Never log in to medical information sites from email links
The data that may have leaked includes names, facility names, facility addresses, job types and specialties. Together, these let someone write a convincing fake email with your correct name, workplace and specialty.
The company asks people not to open URLs in suspicious emails, and not to open attachments or enter personal data. Even if an email talks about "re-registering your membership", "our apology" or "the site has reopened", do not click; go in from your usual bookmark (how to spot fakes: What is phishing?).
Check seminar, society and survey invitations on the organizer's official site
Healthcare professionals routinely receive invitations to drug-company seminars and webinars, academic society events and paid surveys. With this data, a fake can be tailored to your own specialty.
If an invitation asks for an ID, password or medical license number to register or watch, do not use the email link. Open the official website of the company or society yourself and check that the same event is listed there.
If you reused the password, change it elsewhere
The notice does not list passwords among the data that may have leaked, but it does not say they were unaffected either. Each drug company runs its own site for healthcare professionals, so these are exactly the kind of sites where people reuse one password.
If you used your Pharma DIGITAL password on other medical sites, hospital systems or your email, change it there to a separate one (how to manage them: How to choose a password manager; how to check: How to check if your password has leaked).
Turn on two-step verification where it is available
On a site that only asks for a password, typing it into a fake site is enough for someone to get in. If the medical sites and email you use often have a two-step verification option (an extra check at sign-in, such as an app on your phone), turn it on.
Not every site offers it. For which method to choose, see Choosing MFA the right way.
Use the contact points listed in the company's notice
The company has set up a dedicated contact point. Its phone number changes from October 8, so use the number in the company's notice (Japanese), not one written in an email you received.
What happened (from Asahi Kasei Therapeutics' notice)
On October 6, 2026, Asahi Kasei Therapeutics Co. Ltd. published a notice on unauthorized access to Pharma DIGITAL, its information website for healthcare professionals, and the possible leak of personal data. Everything below is based on that notice.
October 2, 2026
The company was notified by the site's contractor that unauthorized access to the site had occurred. It shut the site down immediately.October 6
The company went public. It said the access route had been fixed, that it was reporting to the relevant authorities, and that it was continuing the investigation with outside specialists.
- Where
- The member database of Pharma DIGITAL, the company's information site for healthcare professionals
- Healthcare professionals
- Name, facility name, facility address, job type, specialty and more: about 514,000 people
- Email addresses
- In addition to the above, email address and more: about 44,000 people
- Company employees
- Name, email address, photo: about 700 people
- Not stored
- Credit card data, sensitive personal data
- How it was found
- On October 2, the site's contractor reported the unauthorized access to the company
- Company response
- Site shut down immediately, access route fixed, reports to authorities, investigation with outside specialists
- Cause
- Not disclosed
The company's notice gives no total. Kyodo News added the groups together and reported up to about 558,700 people.
What the leaked data could be used for
What stands out here is that, alongside names and contact details, the data includes workplace, job type and specialty. That tells a scammer whom to target and which topic will get an email opened.
Name + email address + specialty
↓→
Fake seminar, society or survey invitations matched to your field
→ Check on the organizer's official site / never log in from links
Name + facility name + facility address
↓→
Messages claiming to be from a drug company, sent to the hospital's main address or by post
→ Confirm with your usual representative or the official contact point
Not stored or not found, per the notice
- Credit card data (not stored)
- Sensitive personal data (not stored)
- Misuse or harm (as of October 6)
May have leaked
- Name, job type, specialty
- Facility name and address
- Email address (about 44,000 people)
- Company employees' names, email addresses and photos
A note on reading the numbers: email addresses for 44,000 does not mean the rest are safe
The notice says about 44,000 people's email addresses are involved, but names and workplaces for about 514,000 are included. Messages naming you could also arrive at your hospital's main email address, by post or by phone.
Names and email addresses of about 700 company employees are included too. An email using a real employee's name is not proof that it is genuine. Confirm any message from someone claiming to be your contact through the channel you normally use with them.
For hospital and pharmacy IT staff
The professionals involved work at hospitals, clinics and pharmacies across Japan. Rather than leaving this to individuals, it is a chance to review how your workplace handles incoming mail. The cause has not been disclosed, so this section sticks to what the receiving side can do. For preparing against incidents that stop clinical work, see Hospitals whose care was halted by cyberattacks in 2026.
Warn staff and set one place to report suspicious emails
Tell physicians, pharmacy and nursing staff to be careful with emails claiming to be from drug companies, academic societies or seminar organizers. Always include where to forward suspicious emails (for example, one IT department address).
Collected reports show how many people in the hospital got the same fake, and let you block the sender for everyone at once.
Tag mail from outside the organization as external
Most mail servers and email services can add an "External" label to the subject or top of messages that come from outside. Even an email using a real drug-company employee's name then shows at a glance that it came from outside.
Also check that mail failing sender-domain authentication (SPF, DKIM, DMARC) is sent to the junk folder.
Ask staff to keep work-system passwords separate from outside sites
If the password for the electronic medical records, VPN or hospital email is the same as on a medical information site, a password typed into a fake site becomes a way into the hospital. Ask staff never to use internal-system passwords on outside sites, and set up multi-factor authentication on the VPN and email (choosing a method: Choosing MFA the right way).
Sources (public record)
The facts in this article are based on the public information below. Undisclosed intrusion methods and causes are not speculated on.
- Asahi Kasei Therapeutics Co. Ltd., notice on unauthorized access to the healthcare-professional information site Pharma DIGITAL and the possible leak of personal data (October 6, 2026, Japanese) — asahi-kasei.co.jp
- Kyodo News (October 6, 2026, via Chunichi Shimbun, Japanese) — chunichi.co.jp
Update history
2026-10-06: First version, based on Asahi Kasei Therapeutics' notice of October 6. The company says its investigation continues; this article will be updated when new facts are published.
Read next
- Preparing for follow-on scams: What is phishing?
- Protecting your sign-in: Choosing MFA the right way / How to choose a password manager / How to check if your password has leaked
- Healthcare incidents: Hospitals whose care was halted by cyberattacks in 2026 / The MyDr medical booking breach in Poland
- Other Japanese incidents this month: Daiwa Securities vendor breach
- Other 2026 incidents: Data breaches and cyberattacks of 2026
FAQ
QWhat was leaked in the Asahi Kasei Therapeutics breach?
According to Asahi Kasei Therapeutics' notice of October 6, 2026, personal data in the member database of Pharma DIGITAL, its site for healthcare professionals, may have been viewed or taken. This covers names, facility names, facility addresses, job types, specialties and more for about 514,000 healthcare professionals; email addresses and more in addition to those items for about 44,000; and names, email addresses and photos of about 700 company employees.
QHow many people are affected in total?
The company's notice gives no total, only the figure for each group (about 514,000 healthcare professionals, about 44,000 with email addresses, about 700 employees). Kyodo News added these together and reported up to about 558,700 people.
QWere passwords or credit card details leaked?
The company says the site did not store credit card data or sensitive personal data such as medical history. The notice does not list passwords among the data that may have leaked, but it also does not say passwords were unaffected. If you used the same password on other medical information sites or elsewhere, changing it there is a sensible precaution.
QHas the data been misused?
The company says that as of October 6, no misuse of personal data or other harm caused by the incident had been found. It shut the site down immediately, says the access route has been fixed, and is continuing its investigation with outside specialists.
QWhat scams should I watch for?
The company warns of secondary harm from suspicious emails and impersonation, and asks people not to open URLs or attachments in suspicious emails or enter personal data. An email that correctly names you, your workplace and your specialty is not proof it is genuine. Check any email claiming to be from a drug company, academic society or seminar organizer by opening the organizer's official website yourself.
QWhat caused the breach?
As of October 6, 2026, the method and cause had not been disclosed. The company says it was notified by the site's contractor on October 2 and is continuing its investigation with outside specialists.