Threat Intelligence

Japan Warns of Surge in Personal Data Leaks Linked to Mobile App APIs and Unpatched Metabase

The Hacker News · 9 Oct 2026
Key Takeaway Check that every API and internal tool, including ones you assume are private, requires access controls, and update software such as Metabase to the latest safe release.

Japan's national coordination centre, JPCERT/CC, has warned that attackers are behind a string of personal data leaks at Japanese organisations. Its October 8, 2026 alert says they have abused APIs used by mobile apps and targeted known software flaws. The centre described what it knows as "limited and fragmentary" and stressed that the same method was not necessarily used in every incident. The alert names no attacker and no affected organisation.

The systems hit go beyond consumer apps. They include business intelligence tools and employee-facing management systems that operators did not expect the public to reach, and stored data leaked in some cases. The only product named is Metabase, a business intelligence tool with a known flaw that attackers have exploited. Metabase has urged users to upgrade to at least its minimum safe releases, which are newer than the first fix for that flaw. The alert also lists eight source IP addresses, five User-Agent strings and a set of API controls, including access controls on every endpoint, public or not.

Security firm Macnica counted 119 publicly reported web-based personal data leaks in Japan this year through October 6, against 84 in all of 2025 and 62 in 2024. Of this year's total, 81 came in July or later. The count excludes ransomware and cases tied to other groups. Targets have spread from online shops to member services, business systems and customer support, including a library catalogue search and a train seat booking system.

data breach API security Metabase JPCERT/CC patching

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.