Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Overcast Clouds Humidity: 49%
Wind: 3.6 M/S

Web Data Exposure Incidents Rise Sharply in Japan Amid API and Metabase Attacks

Web Data Exposure Incidents Rise Sharply in Japan Amid API and Metabase Attacks

Japan's incident response authority, JPCERT/CC, has warned of a growing wave of data exposure incidents in which attackers are abusing mobile application APIs, exploiting publicly known vulnerabilities, and targeting internet-accessible business systems to steal large volumes of personal information.

The October 8 alert, based on incident reports received by the organization and additional intelligence gathered during investigations, highlights a series of breaches affecting Japanese organizations throughout 2026. While JPCERT/CC did not attribute the activity to any specific threat group or identify impacted organizations, it noted that multiple incidents share similar attack patterns involving unauthorized API access and exploitation of vulnerable web applications.

Personal Data Leaks Continue to Increase

According to JPCERT/CC, the incidents differ from typical ransomware attacks and are notable for the large amounts of personal information exposed. Many of the affected systems included not only consumer-facing applications but also internal business intelligence platforms, administrative portals, and employee management systems that were never intended to be publicly accessible.

The agency cautioned that its visibility into the attacks remains incomplete and that not every victim was necessarily compromised using the same techniques. Nevertheless, reports suggest a sustained increase in such breaches since around September 2026.

Supporting that assessment, Japanese cybersecurity firm Macnica reported that 119 web-related personal data breach incidents had been publicly disclosed in Japan between January and October 6, 2026. That figure exceeds the 84 incidents recorded during all of 2025 and the 62 reported in 2024. Notably, 81 of those 119 incidents emerged after July 2026, indicating a sharp acceleration in attack activity.

Macnica emphasized that its figures exclude ransomware incidents and breaches associated with unrelated threat groups, focusing only on attacks believed to resemble the current campaign.

Breaches Impact Diverse Services

The scope of affected systems has expanded significantly beyond traditional e-commerce targets.

Recent incidents have reportedly affected:

  • Online retail platforms
  • Membership and loyalty services
  • Internal business applications
  • Customer support systems
  • Library catalog platforms
  • Transportation reservation services

Several high-profile disclosures demonstrate the scale of the problem.

Car-sharing service Times Car, operated by Park24, reported that attackers gained access to data associated with approximately 6.6 million accounts. The company later disclosed that identity verification documents, including driver's license images, belonging to roughly 1.6 million users had also been exposed.

Meanwhile, Monogatari Corporation, operator of the Yakiniku King restaurant chain, disclosed a breach affecting more than 10.7 million records within its membership application infrastructure.

International Activity Suggests a Broader Campaign

Macnica observed similar incidents beyond Japan, identifying 99 comparable cases across 13 countries and regions.

Among the affected countries were:

  • South Korea (30 cases)
  • France (11 cases)
  • Poland (8 cases)

Researchers noted that differences in disclosure requirements and reporting practices make it difficult to determine whether Japan is being specifically targeted or simply reporting incidents more transparently than other regions.

Three Major Attack Patterns

JPCERT/CC identified three recurring attack methods appearing throughout the incidents.

1. Abuse of Mobile Application APIs

The most commonly observed technique involves direct interaction with backend APIs supporting mobile applications.

Investigators reported multiple methods used to obtain unauthorized access:

Reverse Engineering Mobile Apps

Attackers analyze publicly available smartphone applications to identify:

  • API endpoints
  • Authentication mechanisms
  • Embedded API keys
  • Backend service structures

Once discovered, these interfaces are accessed directly rather than through the application's normal user interface.

Targeting Hidden Internal APIs

Several incidents involved APIs that were never exposed through the application's visible functionality.

Reported abuse included:

  • Unauthorized privilege escalation
  • Creation of rogue accounts
  • Manipulation of authorization mechanisms
  • Enumeration of account information
  • Blind NoSQL injection attacks

Attackers were also observed comparing server behavior when requests contained modified headers, malformed tokens, or unexpected authentication parameters.

Reuse of Stolen API Keys

In some cases, threat actors leveraged API credentials stolen from previously compromised systems.

Macnica's investigation found examples where attackers extracted API keys from mobile applications and subsequently accessed backend services in ways that appeared indistinguishable from legitimate user activity.

Exploiting Application Logic Weaknesses

Researchers found that attackers systematically searched web applications and APIs for weaknesses that exposed data, including:

  • Overly permissive APIs
  • Excessive data exposure
  • Broken access controls
  • Anonymous access to member-only functions
  • Business logic flaws
  • Session management weaknesses

Several incidents also involved attacks against poorly protected administrative interfaces and the exploitation of known software vulnerabilities.

2. Broad Vulnerability Scanning Campaigns

A second possibility raised by JPCERT/CC is that attackers are not relying on a single universal vulnerability.

Instead, they may be conducting large-scale reconnaissance campaigns, scanning each organization individually for:

  • Known vulnerabilities
  • Misconfigured systems
  • Exposed backup files
  • Leaked configuration files
  • Weak administrative controls

This approach would allow attackers to compromise diverse targets regardless of their technology stack.

3. Exploitation of Critical Metabase Vulnerability

The third major attack pattern involves active exploitation of CVE-2026-72898, a critical SQL injection vulnerability affecting Metabase, the widely used open-source business intelligence platform.

Why the Vulnerability Is Dangerous

The flaw carries a maximum CVSS severity score of 10.0 and was reportedly exploited as a zero-day against Metabase's own cloud service before becoming publicly known.

The vulnerability allows unauthenticated attackers to inject SQL commands into Metabase's internal application database.

Successful exploitation can lead to:

  • Administrator-level access
  • Theft of database credentials
  • Access to connected data sources
  • Unauthorized exports of sensitive information

Because Metabase is commonly connected directly to corporate databases, a compromise can provide attackers with immediate access to valuable business and customer data.

Continued Exploitation After Patches

Despite the availability of fixes, attacks continued after disclosure.

Presentation platform AhaSlides later confirmed that attackers exploited the vulnerability within its Metabase environment and maintained access for nearly a month before detection.

JPCERT/CC's latest advisory includes three IP addresses and two User-Agent signatures linked to exploitation attempts observed between August and September 2026.

Indicators of Possible Compromise

According to Metabase, systems should be investigated immediately if logs show:

  1. A POST request to:

returning HTTP 400

followed by:

  1. A GET request to:

returning HTTP 200

This sequence may indicate successful exploitation of CVE-2026-72898.

Recommended Remediation for Metabase Users

Organizations operating internet-accessible Metabase instances are advised to:

  • Upgrade to the latest supported releases immediately
  • Revoke all existing user sessions
  • Audit and remove unknown API keys
  • Review administrator accounts for unauthorized changes
  • Rotate credentials for all connected databases
  • Examine database access logs
  • Review Metabase query history for suspicious activity

For organizations unable to patch immediately, blocking access to the /api/session/reset_password endpoint may provide temporary mitigation.

Attribution Remains Unclear

Neither JPCERT/CC nor Macnica has attributed the activity to a specific threat group.

Researchers believe the attackers are largely opportunistic and focus on any internet-accessible system containing personal data, regardless of industry or organization type.

The investigation has not uncovered evidence that attackers are using AI-discovered zero-day vulnerabilities. Instead, observed attacks rely on:

  • Weak access controls
  • Misconfigurations
  • Authentication failures
  • Poor API security
  • Publicly known software flaws

However, Macnica noted that the volume of systems being tested makes it difficult to completely rule out some level of automation or AI-assisted reconnaissance.

Defensive Recommendations

JPCERT/CC advises organizations to strengthen API security through several key controls:

API Security Measures

  • Apply access controls to every API endpoint, including internal ones.
  • Enforce least-privilege permissions for users and API tokens.
  • Implement rate limiting to prevent automated abuse.
  • Apply stricter limits to high-risk functions such as login, password reset, SMS delivery, and search.
  • Configure token expiration policies.
  • Maintain the ability to rapidly revoke compromised credentials.

Application Security Improvements

Organizations should also:

  • Remove hard-coded API keys and database credentials from mobile applications and browser code.
  • Include administrative functionality in vulnerability assessments.
  • Restrict access to services by geographic region where appropriate.
  • Disable unnecessary internet-facing administrative interfaces.
  • Delete data that exceeds retention requirements.

Log Analysis Recommendations

Defenders should review approximately one month of logs and investigate:

  • Abnormally high API request volumes
  • Spikes in HTTP 403, 404, or 503 errors
  • Requests for non-existent files or endpoints
  • Large increases in successful requests from individual IP addresses
  • Unauthorized use of administrative functions
  • Unusual administrative access locations
  • Increases in database workload
  • Unexpected growth in login attempts

Privacy Regulator Issues Separate Warning

Japan's Personal Information Protection Commission (PPC) issued its own advisory on October 7, warning organizations about recent incidents involving large-scale exposures of personal information.

The regulator highlighted cases where attackers modified request parameters within smartphone applications and web services to obtain data belonging to other users, a technique closely aligned with the API abuse patterns documented by JPCERT/CC.

Officials urged organizations to review their data holdings, verify continued business need for stored personal information, and strengthen controls around API access and user authorization mechanisms.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.