Nearly 600 Cases of Unauthorized Access Reported

Most of 10.8 Million Registered Records Leaked

Names, Email Addresses, and Phone Numbers Among Exposed Data

Cyberattacks and personal information leaks targeting restaurant apps, ride-sharing services, securities firms, and media outlets are continually occurring in Japan. As damages persist—including leaked images of driver's licenses and unauthorized conversions of accumulated points into gift certificates—there are also warnings that the misuse of artificial intelligence (AI) could lower the barriers to launching such attacks.

Cyberattacks and personal information leaks targeting restaurant apps, ride-sharing services, securities firms, and media companies are occurring in Japan. Photo is unrelated to specific content of the article. Pixabay

Cyberattacks and personal information leaks targeting restaurant apps, ride-sharing services, securities firms, and media companies are occurring in Japan. Photo is unrelated to specific content of the article. Pixabay

View original image

On October 6th, Kyodo News reported on the findings of cybersecurity company Trend Micro, which compiled publicly disclosed data from Japanese companies and local governments. According to the report, there were 600 cases of incidents such as unauthorized access disclosed between January and the end of September this year. This figure surpassed last year's total of 593 cases within just nine months.


The total annual number of incidents when this method of aggregation began in 2024 was 644. This year, the pace of disclosures is exceeding even that. For instance, in the ride-sharing service Times Car, approximately 6.6 million accounts had information leaked. Among these, about 1.6 million cases included identification documents such as images of driver's licenses. The operator stated that not only current members but also former users and those whose membership applications were not completed were affected by the breach.


A large-scale leak was also confirmed in the official app of the restaurant chain Yakiniku King. The operator, Monogatari Corporation, announced on October 5th that out of 10,808,784 registered member records, 10,788,963 were leaked. The compromised information included membership numbers, names, email addresses, and phone numbers, but did not include passwords, dates of birth, or records of store usage.


There have also been incidents of actual financial losses. The survey site 'infoQ', operated by GMO Research&AI, announced that up to 948,498 cases of member information were potentially affected by the breach. In addition to names, addresses, phone numbers, and email addresses, encrypted passwords were also included among the leaked data. It was also confirmed that member points on this site were converted into Amazon gift codes without the consent of the account holders. The damage affected 611 cases, totaling 2,869,500 yen. The company stated that the attack exploited vulnerabilities in the software they were using and pledged to restore all points that were fraudulently converted.

Cyberattacks and personal information leaks targeting restaurant apps, ride-sharing services, securities firms, and media outlets have been occurring repeatedly in Japan. Damages include the leakage of driver's license images and unauthorized conversion of reward points into gift certificates. The photo is unrelated to the specific content of the article. Pixabay

Cyberattacks and personal information leaks targeting restaurant apps, ride-sharing services, securities firms, and media outlets have been occurring repeatedly in Japan. Damages include the leakage of driver's license images and unauthorized conversion of reward points into gift certificates. The photo is unrelated to the specific content of the article. Pixabay

View original image

There was also a case where a security incident at an external contractor impacted several client companies. On October 5th, Daiwa Securities announced that the server of Scala Communications, which provides inquiry management services, had been attacked, potentially resulting in the leakage of information such as the names, email addresses, and account numbers of about 110,000 customers. When including inquiry records without personally identifiable information, the number of affected records amounts to roughly 220,000.

Media outlet accounts have also been targeted. Nikkei Inc. revealed on October 4th that a cyberattack on a staff member's Microsoft 365 account resulted in roughly 9,000 spoofed emails being sent. On September 30th, emails containing malicious links were sent to sources and internal contacts, leading to the exposure of email addresses, names, and some email content. Separately, Nikkei Inc. also disclosed that unauthorized logins to Google Workspace accounts may have resulted in personal information leaks affecting 1,646 staff and business contacts.



Government agencies have not been immune to these incidents. The Digital Agency of Japan announced on September 11th that its government work system "Government Solution Service (GSS)" had been compromised, potentially leaking personal data belonging to approximately 246,000 employees and work-related contacts. It was found that the attacker gained access by exploiting vulnerabilities in virtual private network (VPN) equipment. The Digital Agency stated that no personal data of ordinary citizens was included in the leak. With these incidents occurring in rapid succession, concerns about the misuse of AI are growing. According to a Japanese investigator interviewed by Kyodo News, while hacking previously required specialized knowledge, the emergence of AI has lowered the barriers for those wishing to attempt such attacks.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing