Japan's Personal Data Breaches Already Top Last Year's Total: “AI Can Breach Security in Hours”
- Input
- 2026-10-07 07:24:49
- Updated
- 2026-10-07 07:24:49

【Financial News, Tokyo = Correspondent Seo Hye-jin】Damage from information leaks caused by cyberattacks in Japan has surged, with the number of incidents this year already exceeding last year's annual total. Analysts say attacks that use artificial intelligence (AI) to identify security vulnerabilities specific to each company are spreading. Secondary damage has also occurred, with members' points being siphoned off using leaked information.
A tally on the 7th by Japanese cybersecurity firm Trend Micro and the Yomiuri Shimbun of announcements by Japanese companies and organizations found at least 506 information-leak incidents through the 5th of this month. That exceeds last year's annual total of 473 and the 503 recorded in 2024.
The range of targets is also expanding. In the past, attackers broke in sequentially along corporate supply chains or exploited vulnerabilities common to multiple systems. Recently, however, they have increasingly targeted companies holding personal information regardless of their size.
Yutaka Sejiyama, an assistant to the head of the Security Research Center at Japanese cybersecurity firm Macnica, said, “A task that takes a person two to three weeks to find weaknesses in a system can be done by AI in just a few hours,” and said AI was likely being used in wide-ranging attacks.
According to Katsunari Yoshioka, a professor at Yokohama National University, the time between a vulnerability being disclosed and an actual attack being confirmed also fell from 141 days in 2024 to 35 days as of the end of August this year.
Large-scale leaks have also continued. Information was leaked from about 6.6 million accounts belonging to current and former members of the car-sharing service Times Car. About 1.6 million of those accounts also included images of identity documents, such as driver's licenses.
Discount retailer operator MrMax Holdings announced that information on up to 1.73 million members had been leaked. Asahi Kasei Therapeutics, a subsidiary of Asahi Kasei, also said its website for medical professionals had been attacked and that the personal information of about 558,000 people, including healthcare workers and employees, may have been leaked.
The information leaks also led to financial losses. GMO Research & AI announced that information on up to 948,498 members had been leaked and that, in 611 cases, members' points were fraudulently exchanged for Amazon gift codes worth a total of 2,869,500 yen. The company plans to compensate for the full amount of the losses.
Experts said companies should promptly delete the information of former members and people whose contracts have ended, and review security measures, including those of their contractors.
Digital Minister Toshiharu Furukawa urged people the day before to avoid reusing passwords and to enable multi-factor authentication. He also stressed the need to guard against phishing using leaked information by checking suspicious emails through official websites or apps rather than following their links.
[email protected] Seo Hye-jin Reporter