Skip to content
>_ITDITDWeb Security Platform

Security Guides

Data breaches and cyberattacks of 2026 (Japan and worldwide) — what 56 incidents say about the way in, and what to do today

A list of 56 major data breaches and cyberattacks disclosed in 2026 in Japan and worldwide, with dates, scale, causes and sources. How the way in differs between Japan and elsewhere, and what users and site operators can do today.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 9 min read

For: anyone wondering whether breaches are becoming more common, anyone looking for an incident at a service they use, and anyone deciding where to start with their own organization's or site's defenses. This page is a list based on each organization's official notices and does not cover attack techniques.

56
Major incidents disclosed Jan–Sep 2026 (30 Japan, 26 elsewhere)
23
No cause disclosed at the time of the notice
7
Ransomware cases in Japan (of 30)
9
'Tricking employees' or 'developer infrastructure' cases elsewhere (of 26)

How to read this list: major incidents, not all of them; only numbers the organizations stated

This is not every breach disclosed. It is a selection of incidents with large user impact, widely used services, or new techniques. Selection is biased, so a rise in monthly counts does not mean incidents increased. Scale shows only figures the victim organization itself stated, never attacker claims. The same goes for causes: if the organization has not said, it says "not disclosed". New incidents are added every week.

Incidents of 2026

Filter by Japan / outside Japan and by type. Newest month first.

56 incidents

September(10)

  1. JPIntrusion

    Japan Post (Post Office app)

    Outside unauthorized access to the Post Office app led to customer data, including address books and shipping labels, being obtained.

    Scale
    69 records of 19 people
    Cause
    Not disclosed
    Source
    日本郵便ITmedia
  2. JPRansomware

    Keio Corporation

    Group servers were hit by ransomware, disrupting some group companies' business systems; train operations were unaffected and no leak was confirmed.

    Scale
    —
    Cause
    Not disclosed
    Source
    京王電鉄
  3. JPIntrusion

    Times Mobility (Times Car)

    Unauthorized access leaked member data, including former members, and identity-document images such as driver's licenses.

    Scale
    about 6.6M accounts (1.6M with ID-document images)
    Cause
    Not disclosed
    Source
    タイムズカー 第2報第3報
    → Related article on this site
  4. JPRansomware

    Saga University

    Found suspected ransomware encryption on a NAS used by administrative departments; no impact on education, research or clinical systems was found.

    Scale
    —
    Cause
    Not disclosed
    Source
    佐賀大学ITmedia
  5. AUAI agent

    Australian Government (Medicare statistics portal)

    The Prime Minister disclosed that an AI agent under evaluation by an AI company had reached a government Medicare statistics portal; the Australian Cyber Security Centre issued an advisory.

    Scale
    —
    Cause
    Not disclosed
    Source
    pm.gov.aucyber.gov.au
    → Related article on this site
  6. JPExploited vulnerability

    Helpfeel (Gyazo)

    Unauthorized access to the Gyazo image service leaked user data and image metadata such as OCR text and location.

    Scale
    about 23.6M user records, 490M image metadata records
    Cause
    Command execution via an image-upload server vulnerability
    Source
    Helpfeel
    → Related article on this site
  7. JPMisconfiguration

    istyle (@cosme)

    A sharing-setting error on an external file transfer service briefly left a file with member data open to anyone with the URL.

    Scale
    10,997 members
    Cause
    Sharing-setting error on a file transfer service
    Source
    アイスタイル
    → Related article on this site
  8. USIntrusion

    CenterPoint Energy

    Told the SEC that a third party obtained some customers' personal data through an external-facing system; energy services were not affected.

    Scale
    —
    Cause
    Obtained through an external-facing system
    Source
    SEC 8-K
  9. GBOther

    Revolut

    Handed some customers' ID copies and statements to an impostor posing as a government agency; systems and funds were not compromised.

    Scale
    a 'very limited' number of customers
    Cause
    Fraudulent data requests posing as a government agency
    Source
    Malwarebytes
  10. JPExploited vulnerability

    Digital Agency (Japan)

    Unauthorized access to its Government Solution Service may have leaked personal data of government staff and others.

    Scale
    about 246,000 records
    Cause
    Intrusion via a VPN device vulnerability
    Source
    デジタル庁
    → Related article on this site

August(13)

  1. USSupply chain / vendor

    McKesson

    Told the SEC that data was taken from certain third-party applications, affecting a subset of customers; distribution was not affected.

    Scale
    —
    Cause
    Access to and exfiltration from third-party applications
    Source
    SEC 8-K
  2. GBIntrusion

    Manchester Airports Group (MAG)

    An unauthorized party accessed sign-up data for parking, lounges and Wi-Fi at three airports; operations were not affected.

    Scale
    about 8.7 million customers
    Cause
    Not disclosed
    Source
    Security Affairs
  3. USIntrusion

    Boston Scientific

    Told the SEC that a cyber incident caused a global network outage affecting manufacturing, ordering and shipping.

    Scale
    —
    Cause
    Not disclosed
    Source
    SEC 8-K
  4. JPIntrusion

    Rakuten Books Network

    Some company PCs were accessed without authorization; they held customer records and other data.

    Scale
    33,333 customer records
    Cause
    Not disclosed
    Source
    楽天ブックスネットワーク
  5. JPIntrusion

    SAKURA internet

    Disclosed unauthorized access to its rental-server environment and sales system; access to the sales system had continued for about three years.

    Scale
    up to about 1.36 million accounts
    Cause
    Not disclosed
    Source
    さくらインターネット
    → Related article on this site
  6. FRStolen credentials

    French tax administration (DGFiP)

    Usurped credentials of an agent and an authorized third party were used to take tax data; the tax website and user accounts were not compromised.

    Scale
    about 678,000 individuals and businesses (as reported)
    Cause
    Usurped credentials of staff and a third party
    Source
    impots.gouv.fr
  7. LVIntrusion

    Road Traffic Safety Directorate (CSDD), Latvia

    Historical payment-receipt data going back to 2008 was taken; the directorate's board later resigned.

    Scale
    about 1.2 million people (plus companies)
    Cause
    Not disclosed
    Source
    LV portālsLSM
  8. JPIntrusion

    RIZAP (APORITO online store)

    A malicious script on its online store may have exposed personal and card data of customers between May 1 and August 5.

    Scale
    —
    Cause
    A malicious script planted on the site
    Source
    RIZAP
  9. JPIntrusion

    Japan Science and Technology Agency

    Emails in some staff mailboxes may have leaked through unauthorized access.

    Scale
    about 18,000 emails of 12 staff
    Cause
    Not disclosed
    Source
    JST
  10. JPStolen credentials

    Chubu Electric Power

    Credentials for some systems were misused, possibly exposing staff emails and contact data.

    Scale
    about 2,400 emails and contact data
    Cause
    Misused system credentials
    Source
    中部電力
    → Related article on this site
  11. JPStolen credentials

    Innovation Inc. (IT Trend)

    Unauthorized access to its development GitHub leaked personal data stored in repositories.

    Scale
    62,691 people
    Cause
    Credentials in a config file, and personal data stored in repositories
    Source
    イノベーション
    → Related article on this site
  12. JPMisconfiguration

    Kyoto Prefecture

    Names and related data of members of an outsourced learning site were publicly viewable.

    Scale
    up to 1,338 people
    Cause
    A system flaw left data public
    Source
    京都府
  13. GBIntrusion

    Police National Legal Database (PNLD)

    Confirmed that contact details of police officers, staff and criminal-justice professionals were taken and published on the dark web.

    Scale
    —
    Cause
    Not disclosed
    Source
    PNLD

July(8)

  1. JPMisconfiguration

    The Life Insurance Association of Japan

    Personal data of users of its contract inquiry system could be viewed from outside through certain operations.

    Scale
    about 37,000 records
    Cause
    Viewable from outside through certain operations
    Source
    生命保険協会
    → Related article on this site
  2. AUIntrusion

    Origin Energy

    Told the ASX that customer data was accessed and disclosed without authorization, including partial card and bank numbers.

    Scale
    about 900,000 current and former customers
    Cause
    Not disclosed
    Source
    ASX releaseCyber Daily
  3. USStolen credentials

    DentaQuest

    An employee was tricked into handing over credentials and an MFA code; health and identity data were taken.

    Scale
    over 23 million people (per filings, as reported)
    Cause
    Social engineering for credentials and an MFA code
    Source
    Security Affairs
    → Related article on this site
  4. USAI agent

    Hugging Face

    Disclosed an intrusion carried out end to end by an autonomous AI agent; no tampering with public models or datasets was found.

    Scale
    —
    Cause
    Two code-execution vulnerabilities in the dataset pipeline, then lateral movement
    Source
    Hugging Face
    → Related article on this site
  5. USStolen credentials

    Abbott (cancer diagnostics)

    A voice-phishing attack led to access to some legacy systems; some affected files held personal and health information.

    Scale
    —
    Cause
    Voice phishing (vishing)
    Source
    Abbott
  6. JPIntrusion

    Nichirei

    A cyberattack disrupted cold storage and frozen-food shipments; in August some employee data of domestic group companies was said to be at risk.

    Scale
    —
    Cause
    Not disclosed
    Source
    ニチレイ@IT
  7. JPRansomware

    Meitetsu Kyosho (Cariteco)

    Disclosed a ransomware outage and in August said data of current and former Cariteco car-sharing members, including driver's license information, may have leaked.

    Scale
    —
    Cause
    Unauthorized access to servers
    Source
    カリテコScanNetSecurity
  8. JPExploited vulnerability

    Kaga Solnet

    Unauthorized access to its e-commerce site for university students and staff sent customer data externally.

    Scale
    165,587 people
    Cause
    Exploited system vulnerability
    Source
    加賀ソルネットScanNetSecurity

June(2)

  1. JPIntrusion

    Aflac Life Insurance Japan

    Unauthorized access to its policyholder site leaked data on about 4.4 million customers (220,000 with bank account data) and agencies.

    Scale
    about 4.4M customers, 40,000 agencies
    Cause
    Insufficient access and query controls on its policyholder site
    Source
    アフラック
    → Related article on this site
  2. JPExploited vulnerability

    KDDI

    Its mail platform for six ISPs was accessed without authorization; leaks of email addresses and passwords were confirmed.

    Scale
    about 12.23M email addresses, 7.62M with passwords
    Cause
    Exploited vulnerability in third-party software
    Source
    KDDI
    → Related article on this site

May(5)

  1. USStolen credentials

    Carnival Corporation

    Began notifying people after an employee was deceived by social engineering and personal data, including passport and driver's license numbers, was copied.

    Scale
    about 6 million people (per state filing, as reported)
    Cause
    Social engineering of an employee
    Source
    Help Net Security
  2. USSupply chain / vendor

    GitHub

    An employee device was compromised through a poisoned extension and internal repositories were taken; no impact on customer repositories was found.

    Scale
    about 3,800 internal repositories
    Cause
    Employee device compromised by a poisoned VS Code extension
    Source
    GitHub Blog
    → Related article on this site
  3. USSupply chain / vendor

    Nx (Nx Console extension)

    Credentials stolen in the TanStack compromise were used to publish a malicious extension build, which stayed up for under an hour.

    Scale
    one extension version
    Cause
    Developer credentials stolen in the upstream npm compromise
    Source
    Nx
    → Related article on this site
  4. USSupply chain / vendor

    TanStack (npm packages)

    Chained CI/CD weaknesses let malicious versions be published in a six-minute window; they were deprecated within about an hour.

    Scale
    84 malicious versions across 42 packages
    Cause
    CI/CD workflow weaknesses
    Source
    TanStack
    → Related article on this site
  5. USExploited vulnerability

    Instructure (Canvas LMS)

    User data across many institutions using its learning platform was accessed, and a week later user-facing pages were altered.

    Scale
    —
    Cause
    Vulnerabilities in its free-for-teacher product used for initial access
    Source
    Instructure

April(7)

  1. NLIntrusion

    Basic-Fit

    Unauthorized access to its member-visit system exposed member data including bank account details.

    Scale
    about 1 million members in six countries
    Cause
    Not disclosed
    Source
    BleepingComputer
  2. NLIntrusion

    Booking.com

    Unauthorized third parties reached some guests' booking information; reservation PINs were reset and affected users notified.

    Scale
    —
    Cause
    Not disclosed
    Source
    BleepingComputer
  3. JPIntrusion

    NYK Line

    A ship-fuel procurement system used by the group was accessed without authorization and data including employees' and partners' personal information was taken.

    Scale
    —
    Cause
    Not disclosed
    Source
    日本郵船ScanNetSecurity
  4. JPExploited vulnerability

    ielove GROUP

    Unauthorized access to its cloud service for real-estate businesses led to external parties' data being read out.

    Scale
    —
    Cause
    Unauthorized access starting from a system vulnerability
    Source
    いえらぶGROUPScanNetSecurity
  5. JPStolen credentials

    CAMPFIRE

    Disclosed unauthorized access to a GitHub account used for system management, later followed by database access; some bank account data was included.

    Scale
    225,846 people
    Cause
    Compromised GitHub account used for administration
    Source
    CAMPFIREScanNetSecurity
    → Related article on this site
  6. JPIntrusion

    The Awa Bank

    The test environment of an internal office system was accessed without authorization, leaking customer data stored there.

    Scale
    27,745 records
    Cause
    Unauthorized access to a test environment
    Source
    阿波銀行ScanNetSecurity
  7. JPRansomware

    YCC Information Systems

    Its file server was hit by ransomware; leakage of some information held for clients, including municipalities, could not be ruled out.

    Scale
    —
    Cause
    Not disclosed
    Source
    YCC情報システムScanNetSecurity

March(5)

  1. —Supply chain / vendor

    axios (npm package)

    Malicious versions of the widely used HTTP library were published from a compromised maintainer account and removed within hours.

    Scale
    —
    Cause
    Compromised maintainer account (a long-lived npm token is suspected)
    Source
    GitHub issueInfoQ
    → Related article on this site
  2. USIntrusion

    Navia Benefit Solutions

    Began notifying about 2.7 million people that personal data, including Social Security numbers, and benefits-plan data were taken.

    Scale
    about 2.7 million people
    Cause
    Not disclosed
    Source
    California AGSecurityWeek
  3. JPRansomware

    Medica Shuppan

    Disclosed a ransomware-related leak that included authors' bank account numbers and employee HR data.

    Scale
    about 772,000 records (may include duplicates)
    Cause
    Not disclosed
    Source
    メディカ出版ScanNetSecurity
  4. USIntrusion

    Stryker

    Told the SEC that a cyber incident disrupted its Microsoft environment worldwide, affecting ordering, manufacturing and shipping.

    Scale
    —
    Cause
    Not disclosed
    Source
    SEC 8-K
  5. JPIntrusion

    Murata Manufacturing

    Data was taken through unauthorized access to its IT environment; the third report put possibly leaked personal records at about 88,000.

    Scale
    about 88,000 records
    Cause
    Not disclosed
    Source
    村田製作所ScanNetSecurity

February(4)

  1. USIntrusion

    University of Mississippi Medical Center

    A cyberattack took down the network and electronic health records and closed 35 clinics statewide for over a week; hospitals and emergency departments stayed open.

    Scale
    —
    Cause
    Not disclosed
    Source
    UMMCTechTarget
  2. JPRansomware

    Nippon Medical School Musashi Kosugi Hospital

    A ransomware attack exposed personal data of about 130,000 patients; no leak of medical records was confirmed.

    Scale
    about 130,000 patients, about 1,700 staff
    Cause
    Exploited VPN appliance vulnerability
    Source
    武蔵小杉病院ScanNetSecurity
  3. JPSupply chain / vendor

    Mynavi

    A cloud service the company uses was accessed without authorization, possibly exposing personal data of users and business-partner contacts.

    Scale
    74,224 users (third report)
    Cause
    Unauthorized access to a cloud service it uses
    Source
    マイナビScanNetSecurity
  4. JPRansomware

    Anabuki Housing Service

    Disclosed ransomware on some servers; its sixth report in May fixed the possibly leaked personal records at 207,773.

    Scale
    207,773 records (final count)
    Cause
    A vulnerability in a group company's network device
    Source
    穴吹ハウジングサービスScanNetSecurity

January(2)

  1. USMisconfiguration

    Illinois Department of Human Services

    Internal planning maps containing client data had been publicly viewable for years because of incorrect privacy settings on a mapping website.

    Scale
    about 705,000 people
    Cause
    Incorrect privacy settings on a mapping website
    Source
    IDHS
  2. USStolen credentials

    Betterment

    Social engineering gave an intruder access to third-party marketing and operations platforms; a fake crypto message went to some customers and contact data was exposed. Accounts and passwords were not affected, the company says.

    Scale
    —
    Cause
    Social engineering into third-party platforms
    Source
    BettermentBleepingComputer

Three patterns

Japan: 30

Intrusion (incl. method undisclosed)11
Ransomware7
Exploited vulnerability5
Stolen credentials / tricking staff3
Misconfiguration3
Supply chain / vendor1

Outside Japan: 26

Intrusion (incl. method undisclosed)11
Stolen credentials / tricking staff5
Supply chain / vendor5
AI agent2
Misconfiguration1
Exploited vulnerability1
Other1
Breakdown by type (the 56 incidents selected here). 'Intrusion' includes many cases with no disclosed method, so the real ways in may be more skewed.

Ways in that stood out in Japan

  • Ransomware: Anabuki Housing Service, Nippon Medical School Musashi Kosugi Hospital, Medica Shuppan, Meitetsu Kyosho, Saga University, Keio and others
  • VPN and network-device vulnerabilities: Musashi Kosugi Hospital, Anabuki Housing Service (a group company's device), the Digital Agency
  • Developer GitHub credentials: CAMPFIRE, Innovation

Ways in that stood out elsewhere

  • Tricking employees (phone calls, impersonation, fake data requests): Betterment, Carnival, Abbott, DentaQuest (even an MFA code), Revolut
  • Chains through developer infrastructure: TanStack (npm) → Nx (extension) → GitHub internal repositories; axios
  • AI agents: Hugging Face, an Australian government portal

First, in Japan the way in concentrates on devices exposed to the internet. VPN-device vulnerabilities have also accounted for much of the intrusion routes in ransomware cases in Japan's National Police Agency statistics (Why VPN devices become the way in, and how to defend them). At Anabuki Housing Service the entry point was a group company's device — watching only your own devices would not have stopped it.

Second, elsewhere people were often the way in. At DentaQuest an employee was tricked into handing over not only a password but a multi-factor authentication (MFA) code. MFA that asks you to type a code can be defeated if you are tricked into typing it. What phishing cannot defeat is a method where the device itself tells the real site from a fake, such as passkeys (Choosing multi-factor authentication).

Third, developer infrastructure chains. In May, developer credentials stolen in an npm package compromise were used to tamper with a VS Code extension, and a GitHub employee's device with that extension installed led to internal repositories being taken. In Japan, CAMPFIRE and Innovation also had personal data taken through the GitHub they used for development. Developer keys need the same weight as production keys (Defending against npm supply-chain attacks / Stopping secrets before they are committed).

What users and operators can do today

1

Users: check whether a service you use is on the list

Filter by Japan or outside Japan. If a service you use (or used) appears, check the official notice in the source column for who is affected and what to do. Some incidents include former members (Times Car, for example).

2

Users: stop reusing passwords and switch to passkeys where you can

Most breaches are not something you can prevent. What you can do is keep one leak from spreading. Use a different password for each service (password manager) and switch to passkeys where supported.

3

Users: do not act on 'apology', 'refund' or 're-registration' messages through their links

After breaches that leak addresses or phone numbers, convincing follow-on messages increase. Do not open links in the message; check in the official app or a site you open yourself (What is phishing?).

4

Operators: list everything internet-facing and assign who patches it

VPNs, remote access, admin panels, file sharing. Write down everything reachable from the internet and decide who updates each, and when. Include devices at group companies and contractors (The minimum security baseline for organizations).

5

Operators: inventory developer credentials and remove long-lived tokens

GitHub personal access tokens, npm publish tokens, CI/CD secrets. Give every token an expiry, and put guards in place so personal data and keys never live in repositories.

How the list is built (sources and updates)

This site collects security news from Japan and elsewhere (Japanese outlets and aggregators, BleepingComputer, The Record and others) and public-sector notices every day. For each incident selected, we confirm the victim organization's own notice or a regulator filing (such as US SEC or state attorney-general filings) before listing it. Where no official notice could be confirmed, the source column shows the reporting instead. For trends in Japan, see also Tokyo Shoko Research's count (disclosures by listed companies have hit a record every year since 2021).

Update history

2026-09-30: Published with 30 incidents in Japan and 26 elsewhere from January to September 2026. New incidents are added weekly.

FAQ

QWhat major data breaches happened in 2026?
A

This site's list covers 30 incidents in Japan and 26 elsewhere disclosed from January to September 2026. Large ones include KDDI's mail platform (about 12.23 million email addresses), Times Car (about 6.6 million accounts, 1.6 million with identity-document images), Aflac Life Insurance Japan (about 4.4 million people) and Gyazo (about 23.6 million user records) in Japan, and DentaQuest (over 23 million people) and Manchester Airports Group (about 8.7 million customers) elsewhere.

QAre data breaches increasing?
A

In Japan, Tokyo Shoko Research's count of personal-data leaks disclosed by listed companies and their subsidiaries has hit a record every year since 2021. Japan's 2022 privacy-law amendment also made reporting and notification mandatory for certain leaks, which increased the number disclosed. This site's list is a selection of major incidents and is not a statistic of trends over time.

QDo causes differ between Japan and elsewhere?
A

Among the 56 incidents collected here, Japan showed more ransomware (7 cases) and vulnerabilities in VPNs and other network devices or systems. Elsewhere, tricking employees by phone or impersonation to obtain credentials (5 cases) and supply-chain incidents through developer infrastructure such as GitHub, npm and VS Code extensions (4 cases) stood out. This reflects the selected incidents, not a statistical comparison.

QWhy do so many incidents have no disclosed cause?
A

23 of the 56 incidents had no disclosed cause at the time of the notice. Investigations take time, and many organizations hold back technical details because publishing them could invite the same attack again. That is why it is more practical to close the ways in that every incident shares — reused passwords, unpatched internet-facing devices and leaked developer credentials — than to wait for each cause.

QHow is the list built?
A

This site collects security news and public-sector notices from Japan and elsewhere every day, picks incidents with large user impact, widely used services or new techniques, and confirms the victim organization's own notice (or a regulator filing or reputable reporting) before listing it. Only numbers stated by the organization are shown, never attacker claims. Only victim organizations are named; contractors and attackers are not.