Security Guides
Data breaches and cyberattacks of 2026 (Japan and worldwide) — what 56 incidents say about the way in, and what to do today
A list of 56 major data breaches and cyberattacks disclosed in 2026 in Japan and worldwide, with dates, scale, causes and sources. How the way in differs between Japan and elsewhere, and what users and site operators can do today.
For: anyone wondering whether breaches are becoming more common, anyone looking for an incident at a service they use, and anyone deciding where to start with their own organization's or site's defenses. This page is a list based on each organization's official notices and does not cover attack techniques.
How to read this list: major incidents, not all of them; only numbers the organizations stated
This is not every breach disclosed. It is a selection of incidents with large user impact, widely used services, or new techniques. Selection is biased, so a rise in monthly counts does not mean incidents increased. Scale shows only figures the victim organization itself stated, never attacker claims. The same goes for causes: if the organization has not said, it says "not disclosed". New incidents are added every week.
Incidents of 2026
Filter by Japan / outside Japan and by type. Newest month first.
September(10)
- JPIntrusion
Japan Post (Post Office app)
Outside unauthorized access to the Post Office app led to customer data, including address books and shipping labels, being obtained.
- JPRansomware
Keio Corporation
Group servers were hit by ransomware, disrupting some group companies' business systems; train operations were unaffected and no leak was confirmed.
- Scale
- —
- Cause
- Not disclosed
- Source
- 京王電鉄
- JPIntrusion
Times Mobility (Times Car)
Unauthorized access leaked member data, including former members, and identity-document images such as driver's licenses.
- Scale
- about 6.6M accounts (1.6M with ID-document images)
- Cause
- Not disclosed
- Source
- タイムズカー 第2報第3報
- JPRansomware
Saga University
Found suspected ransomware encryption on a NAS used by administrative departments; no impact on education, research or clinical systems was found.
- AUAI agent
Australian Government (Medicare statistics portal)
The Prime Minister disclosed that an AI agent under evaluation by an AI company had reached a government Medicare statistics portal; the Australian Cyber Security Centre issued an advisory.
- Scale
- —
- Cause
- Not disclosed
- Source
- pm.gov.aucyber.gov.au
- JPExploited vulnerability
Helpfeel (Gyazo)
Unauthorized access to the Gyazo image service leaked user data and image metadata such as OCR text and location.
- Scale
- about 23.6M user records, 490M image metadata records
- Cause
- Command execution via an image-upload server vulnerability
- Source
- Helpfeel
- JPMisconfiguration
istyle (@cosme)
A sharing-setting error on an external file transfer service briefly left a file with member data open to anyone with the URL.
- Scale
- 10,997 members
- Cause
- Sharing-setting error on a file transfer service
- Source
- アイスタイル
- USIntrusion
CenterPoint Energy
Told the SEC that a third party obtained some customers' personal data through an external-facing system; energy services were not affected.
- Scale
- —
- Cause
- Obtained through an external-facing system
- Source
- SEC 8-K
- GBOther
Revolut
Handed some customers' ID copies and statements to an impostor posing as a government agency; systems and funds were not compromised.
- Scale
- a 'very limited' number of customers
- Cause
- Fraudulent data requests posing as a government agency
- Source
- Malwarebytes
- JPExploited vulnerability
Digital Agency (Japan)
Unauthorized access to its Government Solution Service may have leaked personal data of government staff and others.
- Scale
- about 246,000 records
- Cause
- Intrusion via a VPN device vulnerability
- Source
- デジタル庁
August(13)
- USSupply chain / vendor
McKesson
Told the SEC that data was taken from certain third-party applications, affecting a subset of customers; distribution was not affected.
- Scale
- —
- Cause
- Access to and exfiltration from third-party applications
- Source
- SEC 8-K
- GBIntrusion
Manchester Airports Group (MAG)
An unauthorized party accessed sign-up data for parking, lounges and Wi-Fi at three airports; operations were not affected.
- Scale
- about 8.7 million customers
- Cause
- Not disclosed
- Source
- Security Affairs
- USIntrusion
Boston Scientific
Told the SEC that a cyber incident caused a global network outage affecting manufacturing, ordering and shipping.
- Scale
- —
- Cause
- Not disclosed
- Source
- SEC 8-K
- JPIntrusion
Rakuten Books Network
Some company PCs were accessed without authorization; they held customer records and other data.
- Scale
- 33,333 customer records
- Cause
- Not disclosed
- Source
- 楽天ブックスネットワーク
- JPIntrusion
SAKURA internet
Disclosed unauthorized access to its rental-server environment and sales system; access to the sales system had continued for about three years.
- Scale
- up to about 1.36 million accounts
- Cause
- Not disclosed
- Source
- さくらインターネット
- FRStolen credentials
French tax administration (DGFiP)
Usurped credentials of an agent and an authorized third party were used to take tax data; the tax website and user accounts were not compromised.
- Scale
- about 678,000 individuals and businesses (as reported)
- Cause
- Usurped credentials of staff and a third party
- Source
- impots.gouv.fr
- LVIntrusion
Road Traffic Safety Directorate (CSDD), Latvia
Historical payment-receipt data going back to 2008 was taken; the directorate's board later resigned.
- Scale
- about 1.2 million people (plus companies)
- Cause
- Not disclosed
- Source
- LV portālsLSM
- JPIntrusion
RIZAP (APORITO online store)
A malicious script on its online store may have exposed personal and card data of customers between May 1 and August 5.
- Scale
- —
- Cause
- A malicious script planted on the site
- Source
- RIZAP
- JPIntrusion
Japan Science and Technology Agency
Emails in some staff mailboxes may have leaked through unauthorized access.
- Scale
- about 18,000 emails of 12 staff
- Cause
- Not disclosed
- Source
- JST
- JPStolen credentials
Chubu Electric Power
Credentials for some systems were misused, possibly exposing staff emails and contact data.
- Scale
- about 2,400 emails and contact data
- Cause
- Misused system credentials
- Source
- 中部電力
- JPStolen credentials
Innovation Inc. (IT Trend)
Unauthorized access to its development GitHub leaked personal data stored in repositories.
- Scale
- 62,691 people
- Cause
- Credentials in a config file, and personal data stored in repositories
- Source
- イノベーション
- JPMisconfiguration
Kyoto Prefecture
Names and related data of members of an outsourced learning site were publicly viewable.
- Scale
- up to 1,338 people
- Cause
- A system flaw left data public
- Source
- 京都府
- GBIntrusion
Police National Legal Database (PNLD)
Confirmed that contact details of police officers, staff and criminal-justice professionals were taken and published on the dark web.
- Scale
- —
- Cause
- Not disclosed
- Source
- PNLD
July(8)
- JPMisconfiguration
The Life Insurance Association of Japan
Personal data of users of its contract inquiry system could be viewed from outside through certain operations.
- Scale
- about 37,000 records
- Cause
- Viewable from outside through certain operations
- Source
- 生命保険協会
- AUIntrusion
Origin Energy
Told the ASX that customer data was accessed and disclosed without authorization, including partial card and bank numbers.
- Scale
- about 900,000 current and former customers
- Cause
- Not disclosed
- Source
- ASX releaseCyber Daily
- USStolen credentials
DentaQuest
An employee was tricked into handing over credentials and an MFA code; health and identity data were taken.
- Scale
- over 23 million people (per filings, as reported)
- Cause
- Social engineering for credentials and an MFA code
- Source
- Security Affairs
- USAI agent
Hugging Face
Disclosed an intrusion carried out end to end by an autonomous AI agent; no tampering with public models or datasets was found.
- Scale
- —
- Cause
- Two code-execution vulnerabilities in the dataset pipeline, then lateral movement
- Source
- Hugging Face
- USStolen credentials
Abbott (cancer diagnostics)
A voice-phishing attack led to access to some legacy systems; some affected files held personal and health information.
- Scale
- —
- Cause
- Voice phishing (vishing)
- Source
- Abbott
- JPIntrusion
Nichirei
A cyberattack disrupted cold storage and frozen-food shipments; in August some employee data of domestic group companies was said to be at risk.
- JPRansomware
Meitetsu Kyosho (Cariteco)
Disclosed a ransomware outage and in August said data of current and former Cariteco car-sharing members, including driver's license information, may have leaked.
- Scale
- —
- Cause
- Unauthorized access to servers
- Source
- カリテコScanNetSecurity
- JPExploited vulnerability
Kaga Solnet
Unauthorized access to its e-commerce site for university students and staff sent customer data externally.
- Scale
- 165,587 people
- Cause
- Exploited system vulnerability
- Source
- 加賀ソルネットScanNetSecurity
June(2)
- JPIntrusion
Aflac Life Insurance Japan
Unauthorized access to its policyholder site leaked data on about 4.4 million customers (220,000 with bank account data) and agencies.
- Scale
- about 4.4M customers, 40,000 agencies
- Cause
- Insufficient access and query controls on its policyholder site
- Source
- アフラック
- JPExploited vulnerability
KDDI
Its mail platform for six ISPs was accessed without authorization; leaks of email addresses and passwords were confirmed.
- Scale
- about 12.23M email addresses, 7.62M with passwords
- Cause
- Exploited vulnerability in third-party software
- Source
- KDDI
May(5)
- USStolen credentials
Carnival Corporation
Began notifying people after an employee was deceived by social engineering and personal data, including passport and driver's license numbers, was copied.
- Scale
- about 6 million people (per state filing, as reported)
- Cause
- Social engineering of an employee
- Source
- Help Net Security
- USSupply chain / vendor
GitHub
An employee device was compromised through a poisoned extension and internal repositories were taken; no impact on customer repositories was found.
- Scale
- about 3,800 internal repositories
- Cause
- Employee device compromised by a poisoned VS Code extension
- Source
- GitHub Blog
- USSupply chain / vendor
Nx (Nx Console extension)
Credentials stolen in the TanStack compromise were used to publish a malicious extension build, which stayed up for under an hour.
- Scale
- one extension version
- Cause
- Developer credentials stolen in the upstream npm compromise
- Source
- Nx
- USSupply chain / vendor
TanStack (npm packages)
Chained CI/CD weaknesses let malicious versions be published in a six-minute window; they were deprecated within about an hour.
- Scale
- 84 malicious versions across 42 packages
- Cause
- CI/CD workflow weaknesses
- Source
- TanStack
- USExploited vulnerability
Instructure (Canvas LMS)
User data across many institutions using its learning platform was accessed, and a week later user-facing pages were altered.
- Scale
- —
- Cause
- Vulnerabilities in its free-for-teacher product used for initial access
- Source
- Instructure
April(7)
- NLIntrusion
Basic-Fit
Unauthorized access to its member-visit system exposed member data including bank account details.
- Scale
- about 1 million members in six countries
- Cause
- Not disclosed
- Source
- BleepingComputer
- NLIntrusion
Booking.com
Unauthorized third parties reached some guests' booking information; reservation PINs were reset and affected users notified.
- Scale
- —
- Cause
- Not disclosed
- Source
- BleepingComputer
- JPIntrusion
NYK Line
A ship-fuel procurement system used by the group was accessed without authorization and data including employees' and partners' personal information was taken.
- Scale
- —
- Cause
- Not disclosed
- Source
- 日本郵船ScanNetSecurity
- JPExploited vulnerability
ielove GROUP
Unauthorized access to its cloud service for real-estate businesses led to external parties' data being read out.
- Scale
- —
- Cause
- Unauthorized access starting from a system vulnerability
- Source
- いえらぶGROUPScanNetSecurity
- JPStolen credentials
CAMPFIRE
Disclosed unauthorized access to a GitHub account used for system management, later followed by database access; some bank account data was included.
- Scale
- 225,846 people
- Cause
- Compromised GitHub account used for administration
- Source
- CAMPFIREScanNetSecurity
- JPIntrusion
The Awa Bank
The test environment of an internal office system was accessed without authorization, leaking customer data stored there.
- Scale
- 27,745 records
- Cause
- Unauthorized access to a test environment
- Source
- 阿波銀行ScanNetSecurity
- JPRansomware
YCC Information Systems
Its file server was hit by ransomware; leakage of some information held for clients, including municipalities, could not be ruled out.
- Scale
- —
- Cause
- Not disclosed
- Source
- YCC情報システムScanNetSecurity
March(5)
- —Supply chain / vendor
axios (npm package)
Malicious versions of the widely used HTTP library were published from a compromised maintainer account and removed within hours.
- Scale
- —
- Cause
- Compromised maintainer account (a long-lived npm token is suspected)
- Source
- GitHub issueInfoQ
- USIntrusion
Navia Benefit Solutions
Began notifying about 2.7 million people that personal data, including Social Security numbers, and benefits-plan data were taken.
- Scale
- about 2.7 million people
- Cause
- Not disclosed
- Source
- California AGSecurityWeek
- JPRansomware
Medica Shuppan
Disclosed a ransomware-related leak that included authors' bank account numbers and employee HR data.
- Scale
- about 772,000 records (may include duplicates)
- Cause
- Not disclosed
- Source
- メディカ出版ScanNetSecurity
- USIntrusion
Stryker
Told the SEC that a cyber incident disrupted its Microsoft environment worldwide, affecting ordering, manufacturing and shipping.
- Scale
- —
- Cause
- Not disclosed
- Source
- SEC 8-K
- JPIntrusion
Murata Manufacturing
Data was taken through unauthorized access to its IT environment; the third report put possibly leaked personal records at about 88,000.
- Scale
- about 88,000 records
- Cause
- Not disclosed
- Source
- 村田製作所ScanNetSecurity
February(4)
- USIntrusion
University of Mississippi Medical Center
A cyberattack took down the network and electronic health records and closed 35 clinics statewide for over a week; hospitals and emergency departments stayed open.
- Scale
- —
- Cause
- Not disclosed
- Source
- UMMCTechTarget
- JPRansomware
Nippon Medical School Musashi Kosugi Hospital
A ransomware attack exposed personal data of about 130,000 patients; no leak of medical records was confirmed.
- Scale
- about 130,000 patients, about 1,700 staff
- Cause
- Exploited VPN appliance vulnerability
- Source
- 武蔵小杉病院ScanNetSecurity
- JPSupply chain / vendor
Mynavi
A cloud service the company uses was accessed without authorization, possibly exposing personal data of users and business-partner contacts.
- Scale
- 74,224 users (third report)
- Cause
- Unauthorized access to a cloud service it uses
- Source
- マイナビScanNetSecurity
- JPRansomware
Anabuki Housing Service
Disclosed ransomware on some servers; its sixth report in May fixed the possibly leaked personal records at 207,773.
- Scale
- 207,773 records (final count)
- Cause
- A vulnerability in a group company's network device
- Source
- 穴吹ハウジングサービスScanNetSecurity
January(2)
- USMisconfiguration
Illinois Department of Human Services
Internal planning maps containing client data had been publicly viewable for years because of incorrect privacy settings on a mapping website.
- Scale
- about 705,000 people
- Cause
- Incorrect privacy settings on a mapping website
- Source
- IDHS
- USStolen credentials
Betterment
Social engineering gave an intruder access to third-party marketing and operations platforms; a fake crypto message went to some customers and contact data was exposed. Accounts and passwords were not affected, the company says.
- Scale
- —
- Cause
- Social engineering into third-party platforms
- Source
- BettermentBleepingComputer
Three patterns
Japan: 30
Outside Japan: 26
Ways in that stood out in Japan
- Ransomware: Anabuki Housing Service, Nippon Medical School Musashi Kosugi Hospital, Medica Shuppan, Meitetsu Kyosho, Saga University, Keio and others
- VPN and network-device vulnerabilities: Musashi Kosugi Hospital, Anabuki Housing Service (a group company's device), the Digital Agency
- Developer GitHub credentials: CAMPFIRE, Innovation
Ways in that stood out elsewhere
- Tricking employees (phone calls, impersonation, fake data requests): Betterment, Carnival, Abbott, DentaQuest (even an MFA code), Revolut
- Chains through developer infrastructure: TanStack (npm) → Nx (extension) → GitHub internal repositories; axios
- AI agents: Hugging Face, an Australian government portal
First, in Japan the way in concentrates on devices exposed to the internet. VPN-device vulnerabilities have also accounted for much of the intrusion routes in ransomware cases in Japan's National Police Agency statistics (Why VPN devices become the way in, and how to defend them). At Anabuki Housing Service the entry point was a group company's device — watching only your own devices would not have stopped it.
Second, elsewhere people were often the way in. At DentaQuest an employee was tricked into handing over not only a password but a multi-factor authentication (MFA) code. MFA that asks you to type a code can be defeated if you are tricked into typing it. What phishing cannot defeat is a method where the device itself tells the real site from a fake, such as passkeys (Choosing multi-factor authentication).
Third, developer infrastructure chains. In May, developer credentials stolen in an npm package compromise were used to tamper with a VS Code extension, and a GitHub employee's device with that extension installed led to internal repositories being taken. In Japan, CAMPFIRE and Innovation also had personal data taken through the GitHub they used for development. Developer keys need the same weight as production keys (Defending against npm supply-chain attacks / Stopping secrets before they are committed).
What users and operators can do today
Users: check whether a service you use is on the list
Filter by Japan or outside Japan. If a service you use (or used) appears, check the official notice in the source column for who is affected and what to do. Some incidents include former members (Times Car, for example).
Users: stop reusing passwords and switch to passkeys where you can
Most breaches are not something you can prevent. What you can do is keep one leak from spreading. Use a different password for each service (password manager) and switch to passkeys where supported.
Users: do not act on 'apology', 'refund' or 're-registration' messages through their links
After breaches that leak addresses or phone numbers, convincing follow-on messages increase. Do not open links in the message; check in the official app or a site you open yourself (What is phishing?).
Operators: list everything internet-facing and assign who patches it
VPNs, remote access, admin panels, file sharing. Write down everything reachable from the internet and decide who updates each, and when. Include devices at group companies and contractors (The minimum security baseline for organizations).
Operators: inventory developer credentials and remove long-lived tokens
GitHub personal access tokens, npm publish tokens, CI/CD secrets. Give every token an expiry, and put guards in place so personal data and keys never live in repositories.
How the list is built (sources and updates)
This site collects security news from Japan and elsewhere (Japanese outlets and aggregators, BleepingComputer, The Record and others) and public-sector notices every day. For each incident selected, we confirm the victim organization's own notice or a regulator filing (such as US SEC or state attorney-general filings) before listing it. Where no official notice could be confirmed, the source column shows the reporting instead. For trends in Japan, see also Tokyo Shoko Research's count (disclosures by listed companies have hit a record every year since 2021).
Update history
2026-09-30: Published with 30 incidents in Japan and 26 elsewhere from January to September 2026. New incidents are added weekly.
Read next
- Individual incidents: Times Car (driver's license images) / Gyazo / KDDI, Aflac, the Digital Agency and Sakura compared / The Hugging Face intrusion (AI agent)
- Intrusion routes: Japanese incidents of 2026 classified by way in
- Defenses: Defending VPN devices / Choosing MFA / Defending against npm supply-chain attacks
- Older history: Security history (from 1976)
FAQ
QWhat major data breaches happened in 2026?
This site's list covers 30 incidents in Japan and 26 elsewhere disclosed from January to September 2026. Large ones include KDDI's mail platform (about 12.23 million email addresses), Times Car (about 6.6 million accounts, 1.6 million with identity-document images), Aflac Life Insurance Japan (about 4.4 million people) and Gyazo (about 23.6 million user records) in Japan, and DentaQuest (over 23 million people) and Manchester Airports Group (about 8.7 million customers) elsewhere.
QAre data breaches increasing?
In Japan, Tokyo Shoko Research's count of personal-data leaks disclosed by listed companies and their subsidiaries has hit a record every year since 2021. Japan's 2022 privacy-law amendment also made reporting and notification mandatory for certain leaks, which increased the number disclosed. This site's list is a selection of major incidents and is not a statistic of trends over time.
QDo causes differ between Japan and elsewhere?
Among the 56 incidents collected here, Japan showed more ransomware (7 cases) and vulnerabilities in VPNs and other network devices or systems. Elsewhere, tricking employees by phone or impersonation to obtain credentials (5 cases) and supply-chain incidents through developer infrastructure such as GitHub, npm and VS Code extensions (4 cases) stood out. This reflects the selected incidents, not a statistical comparison.
QWhy do so many incidents have no disclosed cause?
23 of the 56 incidents had no disclosed cause at the time of the notice. Investigations take time, and many organizations hold back technical details because publishing them could invite the same attack again. That is why it is more practical to close the ways in that every incident shares — reused passwords, unpatched internet-facing devices and leaked developer credentials — than to wait for each cause.
QHow is the list built?
This site collects security news and public-sector notices from Japan and elsewhere every day, picks incidents with large user impact, widely used services or new techniques, and confirms the victim organization's own notice (or a regulator filing or reputable reporting) before listing it. Only numbers stated by the organization are shown, never attacker claims. Only victim organizations are named; contractors and attackers are not.