Security Guides
Japan data breach statistics: 17,139 leak reports to the Personal Information Protection Commission in FY2025, and about 80% of those filed directly were human error
Data breach reports filed with Japan's Personal Information Protection Commission (PPC), by fiscal year: 17,139 from businesses in FY2025 (19,056 in FY2024) and 6,101 in total for Q1 FY2026. Causes, why counts jumped after 2022, listed-company figures, and what to do.
Who this is for: anyone checking in numbers whether data breaches in Japan are increasing, people who want to cite the counts in reports or training, and organizations deciding what to fix first. This page is based on the annual reports and quarterly releases of Japan's Personal Information Protection Commission (the PPC, or "the commission" below) and on public data from other regulators.
Leak reports by fiscal year
These are the counts of personal-data leak reports in the commission's annual reports. Businesses (personal information handling business operators) and public bodies (national government bodies and local governments) are counted separately. Japan's fiscal year runs from April to the following March.
Orange = before mandatory reporting (to FY2021) / green = after / blue = April to June 2026 only
| Fiscal year | Reports from businesses | Reports from public bodies | How counted |
|---|---|---|---|
| FY2020 | 4,141 | — | Before mandatory reporting. Reports received, including 1,992 via accredited organizations |
| FY2021 | 5,846 | — | Before mandatory reporting. Reports received, including 2,418 via accredited organizations |
| FY2022 | 7,685 | 114 | First year of mandatory reporting. Reports filed |
| FY2023 | 12,120 | 1,159 (national 162, local 997) | Reports processed |
| FY2024 | 19,056 | 1,951 (national 221, local 1,730) | Reports processed. Includes 2,745 reports from a single incident at one contractor |
| FY2025 | 17,139 | 2,278 (national 248, local 2,030) | Reports processed |
| FY2026 Q1 | 5,451 | 650 (national 66, local 584) | Reports processed (April to June, preliminary) |
Local governments came under the Act's reporting rules in April 2023, which is why public-body counts jump from FY2023.
The Q1 FY2026 total of 6,101 combines the 5,451 business reports with the public-body reports. Comparing businesses only, that is about 9% more than the same quarter a year earlier (5,007). The commission notes that quarterly figures are as of publication and may be revised in the annual report.
What must be reported, and why the count rose from FY2022
The amended Act on the Protection of Personal Information took effect on April 1, 2022. Since then, a leak (or possible leak) that meets any of the following must be reported to the commission and notified to the people affected.
| Reporting is required when the leak | Examples | Business reports in Q1 FY2026 |
|---|---|---|
| Involves sensitive personal information | Medical history, treatment records, prescriptions | 3,196 (58.6%) |
| Could cause financial harm if misused | Credit card numbers, login IDs and passwords for services that can send money or pay | 1,093 (20.1%) |
| May have been caused with wrongful intent | Unauthorized access, data taken out by an employee | 1,450 (26.6%) |
| Affects more than 1,000 people | A large customer list | 246 (4.5%) |
One case can meet several conditions, so the shares add up to more than 100%. A preliminary report is due within roughly 3 to 5 days of discovery and a final report within 30 days (60 days where wrongful intent is suspected).
Sensitive personal information must be reported even for one person. That is why hospitals and pharmacies handing another patient's documents (such as itemized medical bills) to the wrong person make up a large part of the reports. The commission itself attributes the FY2022 increase to mandatory reporting and growing awareness of it. Comparing counts before and after 2022 and concluding that "breaches doubled" is a misreading.
Causes: wrong-recipient mistakes dominate, and unauthorized access swings from year to year
The annual reports' appendix tables give causes for reports filed directly with the commission (excluding those routed through other ministries). This site combined the rows for where the leak occurred (the reporting company, a contractor, or unknown) to calculate the shares below.
| Cause | FY2023 (7,075) | FY2024 (14,198) | FY2025 (13,345) |
|---|---|---|---|
| Handed to the wrong person | 62.7% | 40.0% | 48.3% |
| Sent to the wrong recipient | 18.0% | 20.8% | 26.0% |
| Loss | 5.1% | 4.0% | 5.7% |
| Unauthorized access | 6.3% | 27.3% | 9.4% |
| Wrongful disposal, theft, insider misconduct | 1.6% | 1.3% | 1.8% |
| Other | 6.4% | 6.6% | 8.8% |
Unauthorized access jumped to 27.3% in FY2024 most likely because a company running a social-insurance and HR administration system was hit by ransomware, and many of its client companies filed reports. According to the commission, 2,745 reports about that single incident are included in the FY2024 count.
Without them, FY2024 would be about 16,300, and FY2025's 17,139 is higher than that. The drop in FY2025 largely reflects the absence of a similar single large incident; it does not show that everyday leaks have declined.
This site's view: counting reports and counting people point to different priorities
By number of reports, cases affecting 1,000 people or fewer make up 93.6% (FY2025), and the main causes are paper documents handed or sent to the wrong person. By number of people affected in incidents companies announced, unauthorized access dominates (in Tokyo Shoko Research's count below, incidents caused by malware or unauthorized access averaged about 560,000 people each).
So organizations that handle personal data at counters or by post can cut most of their reports with recipient checks. Organizations that hold large customer databases in their systems should put unauthorized-access defenses first, even if such incidents are fewer. Decide your first step by which of the two you resemble.
Of the 1,256 unauthorized-access reports in FY2025, 328 (about 26%) occurred at a contractor and 395 had an unknown source. Protecting your own systems is not enough; contractors that hold your personal data are part of the scope.
Incidents disclosed by listed companies (Tokyo Shoko Research)
The credit research firm Tokyo Shoko Research counts personal-data leak and loss incidents disclosed by listed companies and their subsidiaries by calendar year. In 2025 there were 180 (at 158 companies), second only to the record 189 in 2024. About 30.6 million people's data was leaked or lost, nearly double the year before.
Malware infections and unauthorized access accounted for 116 of the incidents, over 60%. This count differs from reports to the commission in scope (only incidents listed companies announced) and in method (calendar year, per incident), so the two numbers should not be added together or compared directly.
Other countries (for reference)
Reporting conditions and counting methods differ by country. The figures below cannot be compared directly with Japan's.
UK: breach reports to the ICO
- The UK data protection regulator (ICO) publishes data on the personal data breach reports it receives each quarter
- Counting the published data (through Q4 2025), this site finds about 13,500 reports in 2025
- About three quarters were non-cyber, and the most common type was "data emailed to incorrect recipient" (about 2,500)
US: healthcare breaches (HHS)
- The HHS Office for Civil Rights posts each health-data breach affecting 500 or more people
- A private tally (HIPAA Journal) counts 710 such breaches reported in 2025
- On the list of cases under investigation as of October 11, 2026, 365 of the 386 breaches reported in 2026 are "Hacking/IT Incident"
In the UK, too, email sent to the wrong recipient is the most common type, so human error makes up much of the reporting, as in Japan. The US healthcare list shows only breaches of 500 or more people, so small misdirected mail does not appear and unauthorized access stands out.
What the numbers mean for you
Organizations: add recipient checks when handing over or sending documents
Handing to the wrong person and sending to the wrong recipient together make up about three quarters of reports filed directly with the commission. At counters, confirm identity with two items such as name and date of birth before handing over documents, and have a second person check the address against the contents when packing mail. For email, use a setting that holds external messages for a few minutes so they can be reviewed, and use a mailing system rather than To or CC fields when writing to many outside people at once.
Organizations: encrypt laptops and storage that leave the office
Loss runs at around 5% every year. Encrypted laptops and USB drives are much harder to read if lost (laptop security when travelling).
Organizations: patch internet-facing devices and add multi-factor authentication
The commission lists the causes it saw in unauthorized-access cases: VPN appliances and other software left unpatched after fixes were released, easily guessed IDs and passwords, and misconfiguration (FY2024 annual report). Keep a list of internet-facing devices with a named owner for updates (why VPN devices become entry points and how to defend them), and require multi-factor authentication for remote access and admin screens (choosing multi-factor authentication).
Organizations: list the contractors that hold your personal data
Write down which contractors hold what personal data and for how many people, and set in the contract how quickly they must tell you about an incident. Even when the leak happens at a contractor, the company that entrusted the data also has a duty to report. Overall priorities are in the security baseline for organizations.
Organizations: set up a reporting flow that meets the 3-to-5-day deadline
Decide in advance who the person who notices a leak should tell, and in what order. The commission has also given guidance to companies whose reports were significantly delayed.
Individuals: check the official site before acting on an apology notice
Do not log in from links in breach notices or "apology" emails; open the official site yourself to check. If a password may have leaked, change it on every service where you used it (how to check whether your password has leaked).
How to read these numbers
Report counts are not incident counts
One incident can produce several reports. When personal data handling is outsourced, both the company that entrusted the data and the contractor generally have to report, so one incident at a contractor can bring reports from many client companies (the 2,745 in FY2024 are an example). Reports may also go to more than one ministry.
Do not mix fiscal and calendar years. The commission counts April to March; Tokyo Shoko Research counts January to December. The commission also counts a report once it has finished processing it, which can differ from when the incident happened.
Reporting was not mandatory up to FY2021, so the basis changed in FY2022. The annual reports also word it differently: "reports filed" for FY2022 and "reports processed" from FY2023.
Leaks of data containing My Number (Japan's individual number) are counted separately from the figures above (in FY2025 the commission processed 392 reports including cases of possible My Number Act violations, of which 74 were statutory leak reports).
Sources and data use
The figures on this page were checked against the official documents below on October 11, 2026. The page is updated when the commission publishes each quarter (next: Q2 FY2026).
- Personal Information Protection Commission, "Processing of leak reports in Q1 FY2026" (September 2, 2026, Japanese) — ppc.go.jp
- Personal Information Protection Commission, "Annual Report FY2025" (text and appendix tables, Japanese) — HTML / PDF
- Same, FY2024 — HTML / PDF
- Same, FY2023 — HTML / PDF
- Same, FY2022, FY2021 and FY2020 — FY2022 / FY2021 / FY2020
- Personal Information Protection Commission, "Responding to leaks" (when reporting is required, and deadlines, Japanese) — ppc.go.jp
- Tokyo Shoko Research, personal-data leak and loss incidents at listed companies in 2025 (January 30, 2026, Japanese) — tsr-net.co.jp
- ICO, "Data security incident trends" (data: Q1 2019 to Q4 2025) — ico.org.uk
- US HHS Office for Civil Rights, "Breach Portal" — ocrportal.hhs.gov
- HIPAA Journal, "2025 Healthcare Data Breach Report" — hipaajournal.com
Data use and attribution
Source: Personal Information Protection Commission website (https://www.ppc.go.jp/aboutus/report/ and https://www.ppc.go.jp/files/pdf/260902quarter-report_roueihoukoku.pdf), accessed October 11, 2026. The yearly table, chart and cause shares on this page were created by this site by processing the commission's annual reports and its Q1 FY2026 release on leak reports; they were not produced by the commission. The commission's content is used under the Public Data License (Version 1.0) (PDL1.0).
UK figures were counted by this site from ICO published data. Contains public sector information licensed under the Open Government Licence v3.0.
Read next
- Major incidents of 2026: 2026 data breach and cyberattack timeline
- How attackers got in: entry points in Japan's 2026 breaches (cross-case analysis)
- For organizations: the security baseline for organizations / defending VPN devices / choosing multi-factor authentication
- For individuals: check whether your password has leaked / if your driver's license data leaked
- Terms: what is ransomware / what is phishing
FAQ
QHow many data breaches are reported in Japan each year?
According to the annual reports of the Personal Information Protection Commission (PPC), businesses filed 17,139 leak reports (reports processed) in FY2025 (April 2025 to March 2026), down from a record 19,056 in FY2024. Reports from national government bodies and local governments are counted separately: 2,278 in FY2025. These are reports, not incidents; one incident can produce several reports, because both the company that entrusted the data and its contractor may have to report.
QWhy did the number of breach reports in Japan rise from 2022?
The amended Act on the Protection of Personal Information took effect on April 1, 2022, making it mandatory to report leaks that involve sensitive personal information, that could cause financial harm, that may have been caused with wrongful intent, or that affect more than 1,000 people. Leaks of sensitive data such as medical history must be reported even for one person, so many cases of hospitals and pharmacies handing documents to the wrong patient are now reported. The commission itself attributes the FY2022 increase to mandatory reporting and growing awareness of it.
QWhat is the most common cause of data breaches in Japan?
For reports filed directly with the commission in FY2025, handing documents to the wrong person accounted for 48.3% and sending to the wrong recipient 26.0%; including loss and wrongful disposal, human error made up about 80%. Unauthorized access was 9.4% (calculated by this site from the annual report's appendix tables). Large incidents are different: in Tokyo Shoko Research's count of listed companies, 116 of 180 incidents in 2025 were malware infections or unauthorized access.
QHow many data breaches did listed companies in Japan disclose in 2025?
Tokyo Shoko Research counted 180 personal-data leak or loss incidents disclosed by listed companies and their subsidiaries in calendar 2025 (158 companies), second only to the record 189 of the year before. About 30.6 million people's data was leaked or lost, nearly double the previous year. This counts incidents companies announced, which is a different measure from reports to the PPC.
QWhen must a data breach be reported to Japan's PPC?
When a leak, loss or damage of personal data (or the possibility of it) involves sensitive personal information, could cause financial harm if misused (for example card numbers), may have been caused with wrongful intent (for example unauthorized access), or affects more than 1,000 people. A preliminary report is due within roughly 3 to 5 days of discovery, and a final report within 30 days (60 days where wrongful intent is suspected).
QWhat is the latest figure for breach reports in Japan?
For Q1 of FY2026 (April to June 2026), published on September 2, 2026, the commission processed 6,101 reports in total: 5,451 from businesses, 66 from national government bodies and 584 from local governments. That is about 8% more than the 5,652 in the same quarter a year earlier. This page is updated when the commission publishes each quarter.