ATTACKERS in Japan have been chaining personal data leaks by abusing mobile-app APIs and exploiting known flaws in business systems, according to a 8 October 2026 alert from JPCERT/CC. The incidents, described as limited and fragmentary by the CERT, span consumer apps, BI tools, and employee-facing management systems, with data sometimes exposed publicly. The alert lists eight source IP addresses and five User-Agent strings observed in the activity, and highlights Metabase as a known target.
Metabase has urged users to upgrade to minimum safe releases; the vulnerable version was CVE-2026-72898, an SQL injection flaw with a CVSS score of 10.0 that allowed unauthenticated admin access and data exfiltration from connected databases. Attacks continued after fixes were issued, with JPCERT/CC noting that some organisations faced multi‑target exploitation patterns rather than a single flaw.
Macnica’s analysis, cited by the alert, counted 119 publicly disclosed incidents in 2026 (through 6 October) where personal data was stolen or leaked via web systems operated by Japanese organisations, up from 81 such incidents since July 2026. Notable breaches include Park24’s Times Car car‑sharing service (about 6.6 million accounts affected) and identity documents leaked from about 1.6 million accounts; Monogatari Corporation reported 10,788,963 records leaked from its Yakiniku King app member system.
The attackers’ methods include unauthorized requests to applications’ management APIs, abuse of internal APIs, credential compromise, and, in some cases, exploitation of weak admin passwords or other known flaws. The report emphasises comprehensive API‑level controls, reduced data exposure, and prompt upgrades as practical responses, with Metabase advising upgrades and a six‑step post‑upgrade checklist for affected servers. No single group is named as responsible.