Menu

Security

Data breaches in Japan, September 2026: the 10 cases where the cause was disclosed

September 2026 brought a run of data leak disclosures in Japan, led by about 6.6 million records at Times Car. Of 29 confirmed, I examine the 10 where the cause was disclosed.

Published
Boil time
8 min
Language
English · 日本語

TL;DR

  • I could confirm 29 data leaks and unauthorized-access incidents disclosed in Japan in September 2026. The 13 companies that went viral on X are only some of them
  • The cause was disclosed in 10 cases: six exploited vulnerabilities, one was a configuration flaw, one was a phishing chain, and one each was a human operational error and lost paper records
  • Many of the vulnerabilities were in parts reachable from outside, such as VPN equipment, admin console logins and file upload features
  • The core measures are fixing vulnerabilities in externally reachable parts quickly, deleting personal data you no longer use, and stopping phishing chains with multi-factor authentication
Contents
  1. The 10 cases where the cause was disclosed
  2. A vulnerability in externally reachable equipment: the Digital Agency (GSS)
  3. From a web system vulnerability into multiple systems: Murauchi.com
  4. Holes hidden in a service’s own functions: Gyazo, Smaregi EC, Zaim and PhotoGoods
  5. A configuration flaw let a privileged account be created: Shueisha
  6. Next phishing from a hijacked mailbox: the Toyobo group
  7. Incidents that weren’t attacks: TOPPAN and Resona Bank
  8. Lessons and measures

A post like this went viral on X.

TOPPAN: “Times just screwed up big!!
Release ours now while we can!!”
LEGOLAND: “Me too!”
Japan Post: “Me too!”
Keio Group: “Me too!”
Tokyo Metro: “Me too!“
eplus: “Me too!”
Nippon Rent-A-Car: “Me too!”
Starts Publishing: “Me too!”
Seicomart: “Me too!”
Shueisha: “Me too!”
Kuroneko Yamato: “Me too!”

Resona: “Actually, me too!!!”

A screenshot of the post on X. After TOPPAN's line "Times just screwed up big!! Release ours now while we can!!", LEGOLAND, Japan Post, the Keio Group, Tokyo Metro, eplus and Nippon Rent-A-Car follow with "Me too!". It quotes a 47NEWS flash report on TOPPAN's misdelivery
Source: Post on X (@duetousandyou)

The post is a sarcastic take on how company after company made announcements in the days around the disclosure of the roughly 6.6 million records at Times Car (the car rental and car sharing service run by Park24). In reality, September’s disclosures don’t stop at these 13 companies. By mid-month, there were already disclosures such as about 246,000 records at Japan’s Digital Agency and about 23.62 million at Gyazo. Of the 29 cases whose disclosure dates and contents I could confirm, the cause was disclosed in 10.

The 10 cases where the cause was disclosed

A vulnerability in externally reachable equipment: the Digital Agency (GSS)

This is the case of “Government Solution Service (GSS)”, the shared government work platform. According to the Digital Agency’s announcement, the sequence was as follows.

  1. On June 25, it detected access to a large number of files on a server using a maintenance and operations staff account
  2. On July 9, it became clear that a third party had broken into the system by exploiting a vulnerability in network connection equipment (a VPN)
  3. Personal information that may have leaked totals about 246,000 records: about 189,000 for staff of the agencies that use GSS, and about 57,000 for contractors and others who worked on it

As measures to prevent recurrence, the Digital Agency lists reviewing how it manages vulnerabilities and improving how external connections are made. VPN equipment is equipment that can be reached directly from the internet. The time between a fix being released and its being applied is itself the attackers’ window.

From a web system vulnerability into multiple systems: Murauchi.com

Murauchi.com, a long-established e-commerce site, found traces of unauthorized access after a system failure in the early hours of July 15. In its second report on September 15, it confirmed through a forensic investigation the leak of 7,716,811 records of personal information. According to ITmedia NEWS, the cause was a vulnerability in part of the web system, and attackers broke into multiple systems starting from there. Credit card information and passwords were not included.

Holes hidden in a service’s own functions: Gyazo, Smaregi EC, Zaim and PhotoGoods

Four cases exploited weaknesses in the service’s own functions or processing.

Gyazo (an image-sharing and screenshot service run by Helpfeel) had a vulnerability in its image upload server exploited on September 11, and a third party ran arbitrary commands on the system. According to Helpfeel’s first report, about 23.62 million records of user data and about 490 million image metadata records leaked from the database. The second report found that about 174 million metadata records for deleted images also leaked. About 76% of users are anonymous users who haven’t registered an email address. A measure was also taken to stop viewing of some images, so that the leaked information couldn’t be abused to view images.

Smaregi EC (the online store function of the Smaregi point-of-sale service) had a vulnerability in the login function of customers’ admin consoles exploited (Smaregi’s announcement). The environments of four companies may have been affected, and some customer information, order information, administrator information and WordPress information may have been viewed or obtained. The vulnerability was fixed on September 18.

Zaim (a household budget app) is a case where information was rewritten, not read. According to Kufu Company Holdings’ announcement, a third party exploited a defect in part of the system’s processing. From the night of September 18 to the early hours of the 19th, the nicknames, email addresses and other details of 14 people were rewritten. No effect on household budget data or information leak has been confirmed.

PhotoGoods is a service for ordering cards themed on Calbee’s “Professional Baseball Chips”, run by Daiko Printing. According to Daiko Printing’s announcement, a system vulnerability and the file upload function were exploited to plant a program that steals card information entered on the payment screen. It was in place from August 6 to September 11. Anyone who entered a card number, expiry date and security code on the payment screen during that time could be affected, even without completing the purchase. A rogue administrator account had also been created. It was discovered when someone outside the company reported that a suspicious external program was being loaded.

A configuration flaw let a privileged account be created: Shueisha

According to Shueisha’s announcement (Shueisha is a major publisher), information was taken from “HAPPY PLUS COMMUNITY”, the system for managing fashion magazine bloggers, in the following sequence.

  1. Starting from a configuration flaw in the CMS it uses, it was hit by an attack that targeted API credentials
  2. A privileged user account was illegally created
  3. API requests were run repeatedly, and registration information was obtained

The unauthorized access happened twice on September 9: from 0:45 to 1:25, and from 13:42 to 16:46. During this time, a total of three emails using the system’s template were sent to 100 addresses, and it came to light through a report from a user who received one. What leaked was the names and addresses of 2,835 bloggers, plus information registered on each person’s screen, such as marital status, whether they have children, height and skin type.

Next phishing from a hijacked mailbox: the Toyobo group

According to Toyobo MC’s announcement, on September 24 an employee’s email account at group company Toyobo Senni was hijacked, and about 1,500 suspicious emails were sent inside and outside the company. They were emails that lead to a phishing site. Two employees of Toyobo MC who received the email also fell victim to the phishing, and unauthorized access to their email accounts was confirmed on September 28. Because the emails arrive from legitimate accounts used to communicate with business partners, they are hard for recipients to recognize.

Incidents that weren’t attacks: TOPPAN and Resona Bank

TOPPAN, which started the post, wasn’t attacked. According to TOPPAN’s announcement, in operating the “insurance premium deduction certificate issuing service” it is contracted for by non-life insurers, a staff member made a mistake with a mouse drag and drop. A ZIP file holding the data of 177,426 Sompo Japan policyholders was mixed into the ZIP file for another non-life insurer and sent. The data consisted of three items: names in kana, policy numbers for the premium deduction and business IDs, and it was deleted at the recipient.

A diagram of how TOPPAN misdelivered the data. When TOPPAN manually (by drag and drop) sent data from the insurance premium deduction certificate issuing system, besides the legitimate transmission to Sompo Japan, it misdelivered to another non-life insurer
Source: Misdelivery of data in operating the insurance premium deduction certificate issuing service we are contracted for (TOPPAN)

The operation was done with the ZIP files for several companies in the same folder, and the contents weren’t checked before sending. As measures to prevent recurrence, TOPPAN says it will standardize file attachment on “Select file”, add a checker separate from the operator, and systematize the sending.

Resona Bank announced it had lost about 9,000 people’s records (names, account numbers, closure amounts and so on) for accounts closed from 1992 to 2001 at branches including the one that is now the Fussa branch. According to the Nikkei, they were most likely discarded by mistake, and the possibility of an outside leak is low.

Lessons and measures

  • Fix vulnerabilities in externally reachable parts quickly: the entry points were VPN equipment for the Digital Agency, the admin console login for Smaregi EC, and the upload features for Gyazo and PhotoGoods. Keep an inventory of internet-facing equipment and services, and make applying fixes the top priority
  • Watch upload features and admin accounts: at PhotoGoods a rogue administrator account was created, and at Shueisha a privileged account was created. Set it up so that you get notified whenever a new administrator or privileged account is created
  • Data you don’t hold can’t leak: at Times Car, even identity documents of people who had left or hadn’t finished joining leaked. At Gyazo, the metadata of deleted images also leaked. For documents whose checks are finished and for records of deleted data, set a retention period and delete them
  • Stop phishing chains with multi-factor authentication: in the Toyobo group, an email from a hijacked account led employees at another company to fall victim too. Put multi-factor authentication on email as well, so a stolen password isn’t enough to log in
  • Chase small anomalies: at Seicomart one illegitimate withdrawal request, at Murauchi.com a system failure, and at Shueisha a user’s report was what led to discovery. Have a procedure that turns “just one” anomaly into an investigation
  • Treat contractors and external services as your own scope: LEGOLAND’s external reservation platform, PhotoGoods’ partner Calbee, and TOPPAN’s contractor doing manual work were where information got out. Settle in contracts the contact route when an incident happens at a contractor, and the scope of data they handle
  • Eliminate manual sending: TOPPAN’s measures to prevent recurrence (standardizing on file selection, a checker, systematized sending) can be used as is by any workplace with similar handoffs

What users can do is common to what each company appeals for: don’t open links in emails or SMS that impersonate companies, don’t reuse passwords, and change your password if you are told you are affected.

udon
Microsoft 365, ServiceNow, Copilot and more, tested first-hand and written up as practical notes with real bite.