Japan faces surge in data leaks linked to mobile API misuse and Metabase flaws

JPCERT/CC said it has observed a significant increase in personal data leaks at Japanese organizations, with attackers abusing mobile app APIs and exploiting known software bugs. The center's October 8, 2026 alert did not name any threat actor or victim organization. It drew on incident reports and other information.
JPCERT/CC reported a notable rise in incidents where personal information held by Japanese organizations was exposed. Its October 8, 2026 notice points to two recurring causes: improper use of interfaces that connect mobile applications to backend services, and exploitation of already-known weaknesses in software, including Metabase. The alert was based on incident reports and other available information, and it did not identify any attacker or affected organization. The notice therefore describes a pattern rather than a single event.
The reported increase could affect individuals whose personal data is handled by Japanese organizations, potentially increasing risks of fraud, phishing, or identity misuse. It may also push affected entities to review mobile API security and patch known software flaws more quickly. Because no victims or attackers were named, the immediate scope remains unclear, and the broader impact may depend on how many organizations confirm similar incidents.