Security Guides
Japan's e-Tax showed other people's gift tax returns (79 filers): what was visible and what e-Tax users and developers should do
Japan's National Tax Agency says a defect in an e-Tax MyPage update let other users see 79 people's gift tax returns on Sept 24-25, 2026. Not a cyberattack. What to do.
For: people who filed a gift tax return through e-Tax, people who made the gifts, tax accountants who handled those returns, anyone who uses e-Tax MyPage, and developers who build web services where users log in to see their own data. This article is based on reports of the announcement by Japan's National Tax Agency (NTA) and on official NTA and e-Tax guidance. It does not describe how to reproduce the defect.
Are you affected? A quick table
| Details (from reports of the NTA announcement) | |
|---|---|
| Feature | "Gift tax information" in e-Tax MyPage |
| When other users could see returns | Sept 24, 2026 8:30 to midnight; Sept 25 4:00 to 15:58 |
| Returns that were visible | Gift tax returns and related documents of 79 filers |
| People whose data may have been seen | 203 in total (filers, donors named in returns, tax accountants) |
| Users who may actually have viewed them | 19 |
| Information that may have been seen | Name, address, date of birth, phone number, gift value and gift tax amount, donor's name and date of birth, tax accountant's name, and more |
| Contact with affected people | Regional bureau and tax office staff contacted each one individually to explain and apologize |
| Cause | A defect introduced by the September 24 update (not an attack); fixed |
The people affected are the 79 filers whose gift tax returns were visible, plus the donors and tax accountants named in those returns. Not every e-Tax user was affected.
The reports we checked do not say whether the My Number (Japan's individual number) was among the visible information. This article does not claim either way.
What e-Tax users should do today
If someone calls claiming to be the tax office, hang up and call back
According to reports, regional bureau and tax office staff contacted affected people individually. But an incident in the news also gives fraudsters a ready-made reason to call.
The NTA advises that if a call from someone claiming to be a tax official seems suspicious, do not answer on the spot: ask for their department, name and phone number, hang up, and contact the general affairs section of your nearest tax office or the taxpayer support coordinator at the regional taxation bureau. Use a number you look up on the NTA website's tax office directory, not the one the caller gave you.
Do not open links in texts or emails claiming to be the NTA
The NTA states that it never sends text messages containing URLs, and never sends texts, emails or LINE messages demanding tax payment or about seizure of assets.
If you get a text offering an "apology about your tax return being viewed" or asking you to "confirm your personal details", delete it without opening the link (how to spot these: What is phishing?).
Know what genuine e-Tax emails look like
According to the NTA, e-Tax only sends emails in set formats telling you that a notice has arrived in your message box. They never have attachments and, as a rule, contain no URLs.
Read the notice itself by logging in to e-Tax that you opened yourself from a bookmark or a search, and checking the message box there.
Never operate an ATM, transfer money or give out account details on request
The NTA states that it never asks you to operate an ATM to receive a refund or to pay tax, and never asks you to transfer tax payments to a specified bank account.
Even if a caller says "there is a compensation payment for you" or "you need to complete a refund procedure", do not go to an ATM or give out account numbers or PINs.
User A logs in and opens "my gift tax information" in MyPage
↓
1. Authentication: who is this?
Logged-in user A → passes
2. Authorization: is this document A's?
If this check fails, other people's documents are shown
↓
Correct behavior
Show only A's documents
What happened
Other filers' returns became visible (79 filers)
Fix: log in as A, request B's document, and confirm it is refused — on every change
What happened (from reports of the NTA announcement)
The NTA announced this incident on October 2, 2026. As of October 6, we could not find a notice about it in the announcement lists on the NTA or e-Tax websites. The account below is based on several news reports of the announcement and on official e-Tax notices.
May 27, 2026
e-Tax announces that the "gift tax information" feature in MyPage will be expanded (official notice).Sept 24 (Thu)
Update adds amended-return and assessment notices, the status of the inheritance-time settlement taxation election, and records of paper-filed returns to MyPage's gift tax information. On the same day, the NTA replaced its national tax system.Sept 24, 8:30 to midnight
According to reports, other users could see returns (first period).Sept 25, 4:00 to 15:58
The same state again (second period).Oct 2
The NTA announces that returns of 79 filers could be viewed by other users, says the defect has been fixed, and apologizes.
- Feature
- "Gift tax information" in e-Tax MyPage
- Cause
- A defect introduced by the September 24 system update that expanded this feature. Not an attack from outside
- Information that may have been seen
- Filer's name, address, date of birth and phone number; gift value and gift tax amount; donor's name and date of birth; tax accountant's name, among others (reports list slightly different items)
- Response to affected people
- Regional bureau and tax office staff contacted filers, donors and tax accountants individually to explain and apologize
- Response to viewers
- All 19 asked to keep the information confidential and delete it. No sign of saving or secondary harm found
- Next steps
- The NTA says it will thoroughly implement measures to prevent recurrence
- Relation to KSK2
- According to Nikkei xTECH, unrelated to the new core system (KSK2)
Context: KSK2, the NTA's new core tax system
The NTA officially states that it replaced its national tax system on September 24, 2026. According to Nikkei xTECH, because of issues with the new system (KSK2), the NTA has told staff to use the old system to prepare tax payment certificates and to check their content before issuing them, which is causing delays.
e-Tax also posted notices about issues such as being unable to pay the certificate fee through internet banking, later marked as resolved. The NTA says the gift tax return incident is unrelated to KSK2.
Lessons for developers: run authorization tests even for "convenience" updates
This was not an intrusion from outside. It was a case where another user's data appeared on the screen of a properly logged-in user. In security terms, it is a failure of access control (the rules on who may access which data).
A closely related pattern is IDOR (insecure direct object reference): changing a number or identifier in a request is enough to reach someone else's data. The difference between checking who you are (authentication) and checking whether you may access this data (authorization) is explained in Authentication vs. authorization.
The UK Companies House WebFiling flaw in March 2026 was the same kind of case: a defect introduced by a system update let logged-in users see other companies' non-public details. This incident adds two points.
This site's take: updates that add features are where authorization checks get missed
This update increased the kinds of information MyPage displays. Each new piece of data fetched needs its own check that the data belongs to the logged-in person. Updates that make a page more convenient are rarely treated as security changes, so that check is easy to overlook.
- Put authorization tests in the same suite as functional tests, and run them automatically on every change. Set up test users A and B. Logged in as A, request B's lists, details, downloads and every screen and data fetch the update added, and confirm that each is refused or returns only A's data. Functional tests check that what should work does work; these tests check that what must not work does not.
- Log both "document owner" and "who displayed it", and alert on mismatches. Here, the NTA published the number of visible returns (79 filers) separately from the number of people who may have viewed them (19). In general, producing such figures requires a record of who displayed whose documents. If an alert fires whenever the viewer and owner differ, it can help catch a problem right after a release. Exclude legitimate proxy relationships, such as a tax accountant viewing a client's documents, in advance.
Other cases of personal data leaking from government bodies, and what citizens can do, are covered in Four government data breaches of 2026.
Sources (public record)
The facts in this article are based on the public information below. As of October 6, 2026, we could not find the NTA's announcement itself on the NTA or e-Tax websites, so we cite news reports of it. The detailed mechanism of the defect has not been published, and we do not speculate about it.
- Nikkei xTECH, "79 people's returns may have been viewed by others on the NTA's e-Tax; a defect separate from KSK2" (Japanese, October 5, 2026) — xtech.nikkei.com
- Nikkei, "79 gift tax returns may have been displayed; e-Tax update defect" (Japanese, October 2, 2026) — nikkei.com
- TV Asahi (ANN), "Other people's gift tax information temporarily viewable on e-Tax" (Japanese, October 2, 2026) — news.yahoo.co.jp
- Zei no Shirube, "NTA discloses that gift tax return information was viewable by others in e-Tax MyPage" (Japanese, October 2, 2026) — shirube.zaikyo.or.jp
- e-Tax, notice on the expanded "gift tax information" in MyPage (Japanese, May 27, 2026, updated September 24) — e-tax.nta.go.jp
- National Tax Agency, "On the replacement of the national tax system" (Japanese) — nta.go.jp
- e-Tax, "[Resolved] Certificate fees could not be paid by internet banking" (Japanese, September 29, 2026, updated October 5) — e-tax.nta.go.jp
- National Tax Agency, "Beware of suspicious emails and phone calls" (Japanese) — nta.go.jp
Update history
2026-10-06: First version, based on reports of the NTA's October 2 announcement (Nikkei xTECH, Nikkei, TV Asahi, Zei no Shirube) and official NTA and e-Tax guidance. We will update this article if the NTA posts the announcement on its website or officially lists which items were visible.
Read next
- Protecting yourself from fake messages: What is phishing?
- The same type of incident: The Companies House WebFiling flaw (UK)
- Terms and concepts: What is IDOR? / Authentication vs. authorization
- Government incidents: Four government data breaches of 2026
- Other incidents of 2026: Data breaches and cyberattacks of 2026 (Japan and worldwide)
FAQ
QWhat information could other e-Tax users see?
According to reports of the NTA's October 2, 2026 announcement, the information in gift tax returns and related documents: the filer's name, address, date of birth and phone number, the value of the gift and the gift tax amount, the donor's name and date of birth, and the name of the tax accountant, among other items. The reports we checked do not say whether the My Number (Japan's individual number) was included.
QHow many people were affected?
According to reports, returns of 79 filers could be viewed by someone other than the filer. Including the donors and tax accountants named in those returns, personal information of 203 people in total may have been seen. Nineteen users may actually have viewed another person's return.
QHow do I know whether I am affected?
According to reports, NTA regional bureau and tax office staff contacted each affected filer, donor and tax accountant individually to explain and apologize. The reports do not describe any application you need to make. If you are unsure whether a call from a 'tax office' is genuine, hang up and call back on a tax office number you look up on the NTA website.
QWas this a hack or cyberattack?
According to reports, the NTA says the cause was a defect introduced by a system update on September 24 that expanded the gift tax information feature in e-Tax MyPage. This was not unauthorized access from outside; other people's information appeared on the screens of properly logged-in users. The NTA says the defect has been fixed.
QCould the exposed information be misused?
According to reports, the NTA asked all 19 users who may have viewed the information to keep it confidential and delete it, and found no sign that it was saved and no secondary harm. Fake calls and texts claiming to be the tax office are common regardless of this incident, though. The NTA states that it never sends text messages containing URLs, and never sends texts or emails demanding tax payment or about seizure of assets.
QIs this related to the problems with KSK2, the NTA's new core system?
According to Nikkei xTECH, the NTA says this e-Tax defect is unrelated to KSK2. The NTA replaced its national tax system on September 24, 2026, and delays in issuing tax payment certificates have been reported around the same time, but this is a separate defect.