JPCERT/CC published alert JPCERT-AT-2026-0030 on 8 October 2026 and updated it on 9 October. The alert covers a run of personal-data leaks at Japanese organisations since around September, separate from the usual ransomware cases. JPCERT/CC says its technical picture is still limited, and that the same method was not used in every incident.
What happened
Macnica's Security Research Center, cited in the alert, counted 119 public incidents this year through 6 October in which personal data was stolen or leaked through web systems in Japan. That compares with 84 in all of 2025 and 62 in 2024. Eighty-one of this year's cases were disclosed in July or later. Of those 81, 65 did not include enough detail to say how the attackers got in.
JPCERT/CC describes four patterns. Attackers scan each target for known flaws and for exposed config or backup files. They reverse-engineer public smartphone apps, find internal API endpoints, and abuse weak tokens, missing access control, or NoSQL injection. They exploit CVE-2026-72898, an unauthenticated SQL injection in Metabase scored CVSS 10.0 and added to CISA's Known Exploited Vulnerabilities catalog on 11 August. On 9 October JPCERT/CC added a fourth pattern: a web shell dropped as a WAR file on an application server reachable from a public web server.
Who is affected
Japanese organisations running member apps, business-intelligence tools, and staff systems that were never meant to face the public internet. Named public cases in related reporting include large member-data leaks at consumer apps. Any Metabase instance still on a vulnerable build is in the exploited set, not only Japanese ones.
- Mobile apps whose private APIs can be called directly once the app binary is unpacked.
- Metabase deployments that have not installed the fix for CVE-2026-72898.
- Internal BI and employee portals that are reachable from the internet by mistake.
- Java application servers where a dropped WAR or JSP web shell would be served.
What to do now
Put access control on every API endpoint, including ones the app never shows, rate-limit login and lookup calls, and patch Metabase if CVE-2026-72898 is still open. Revoke long-lived API tokens. Take management and BI interfaces off the public internet. Hunt for unexpected WAR or JSP files on app servers that a public web tier can reach.
Source: JPCERT/CC alert JPCERT-AT-2026-0030, updated 9 October 2026, unauthorized access against Japanese organisations.
Also on the blog
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- Citrix NetScaler CVE-2026-107406 scores 9.5 on SAML deployments
- ARTEX AI pentest agent used in South Korean bank data theft
- Cisco NX-OS CVE-2026-76471 and four more flaws score 9.8
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.