Local Chorus
Local news from local sources, read in your language.
Settled
Verified

JPCERT/CC details three attack methods behind spate of unauthorised access cases

🇯🇵 Japan 06:48 IT & software Tech3 Official updated 2 d ago first reported by マイナビニュース

In short

The JPCERT Coordination Center (JPCERT/CC) issued an alert on October 8 over a series of unauthorised access cases at companies and organisations in Japan since around September 2026, which have led to leaks of personal and other information. It described three attack methods: attempts on known vulnerabilities or management flaws, illicit operation through APIs, and exploitation of the Metabase SQL injection vulnerability CVE-2026-72898.

Read the full story 2 min read

The JPCERT Coordination Center (JPCERT/CC) published an alert on October 8 after a series of unauthorised access cases at companies and organisations in Japan since around September 2026, Mynavi News and ASCII.jp reported. Mynavi News said the cases have led to leaks of personal and other information. NHK reported that an information security specialist body had published three attack methods confirmed so far and was urging companies to be careful. [ 1 , 2 , 3 ]

The three methods are attempts to attack known vulnerabilities or management flaws, illicit operation through APIs, and exploitation of an SQL injection vulnerability in the BI tool Metabase, CVE-2026-72898. ASCII.jp reported that, rather than targeting one common vulnerability, the attackers may be checking each target for vulnerabilities or using management flaws that are not vulnerabilities. Mynavi News reported that JPCERT/CC had issued a separate alert on the Metabase vulnerability on August 14. [ 1 , 2 ]

In the API attacks, publicly available smartphone apps were analysed to identify API keys, and according to ASCII.jp endpoints, and internal APIs were attacked. Mynavi News said these were internal APIs that cannot be run through the normal on-screen operations, and that changes to user privileges, the creation of unauthorised accounts and the misuse of API keys stolen from other systems had been confirmed. ASCII.jp reported that besides apps for the general public, business tools and other systems not intended for access by unspecified numbers of people have been affected. [ 1 , 2 ]

JPCERT/CC said technical information on the recent cases has not been sufficiently shared and what it knows is limited, Mynavi News reported. It published example IP addresses abused between August and September 2026, which it said may be in legitimate use at the time of investigation, and User-Agents seen in suspicious access, including "curl/7.88.1", "python-requests/2.34.2" and "Metabase-GHSA-vwf4/2.0", noting that these User-Agents alone do not show unauthorised access. [ 1 ]

JPCERT/CC recommends applying updates that fix known vulnerabilities, no longer exposing unneeded administrative functions to the internet, and checking employee-facing management systems and BI tools as well as public services, Mynavi News reported. Against API attacks it lists limiting the number of requests, appropriate access control and minimum permissions for API tokens; ASCII.jp added setting suitable expiry periods for API tokens and, where possible, restricting the regions access comes from. Mynavi News said JPCERT/CC also called for reviewing monitoring and initial response, and deleting data whose retention period or purpose has ended to limit damage from leaks. [ 1 , 2 ]

Why it matters

ASCII.jp reported that, besides apps for the general public, business tools and other systems not meant for access by unspecified numbers of people have been hit, and JPCERT/CC urged organisations to check employee-facing management systems and BI tools as well as public services. JPCERT/CC said what it knows about the recent cases is limited, so their full scope is not set out in the reports.

Key facts

  • JPCERT/CC published an alert on October 8 about a series of unauthorised access cases in Japan. [ 1 , 2 ]
  • The cases have occurred since around September 2026; Mynavi News said they have led to leaks of personal and other information at companies and organisations. [ 1 , 2 ]
  • Three attack methods were described: attempts on known vulnerabilities or management flaws, illicit operation through APIs, and exploitation of a Metabase vulnerability. [ 1 , 2 , 3 ]
  • The Metabase flaw is the SQL injection vulnerability CVE-2026-72898; JPCERT/CC issued a separate alert on it on August 14. [ 1 ]
  • In API attacks, publicly available smartphone apps were analysed to identify API keys, internal APIs were attacked, and API keys stolen from other systems were used. [ 1 , 2 ]
  • Changes to user privileges and the creation of unauthorised accounts were confirmed, Mynavi News reported. [ 1 ]
  • Recommended measures include limiting the number of API requests, applying updates for known vulnerabilities and giving API tokens only the minimum permissions needed. [ 1 , 2 ]

Confirmed by several sources

  • JPCERT/CC issued an alert on October 8 over a series of unauthorised access cases in Japan since around September 2026. [ 1 , 2 ]
  • Three attack methods have been made public. [ 1 , 2 , 3 ]
  • Unauthorised access cases have led to leaks of personal information. [ 1 , 3 ]
  • One method exploits the Metabase SQL injection vulnerability CVE-2026-72898. [ 1 , 2 ]
  • API attacks include analysing public smartphone apps to find API keys and using API keys stolen from other systems. [ 1 , 2 ]
  • JPCERT/CC recommends limiting the number of requests to APIs. [ 1 , 2 ]

Still unclear

  • Which companies and organisations were affected and how many cases there have been. None of the reports names victims or gives a number of cases.
  • How much is known about the attacks. Mynavi News reported JPCERT/CC as saying technical information has not been sufficiently shared and what it knows is limited.
  • Whether the cases are linked. ASCII.jp reported that the attackers may be checking each target for vulnerabilities or using management flaws rather than exploiting one common vulnerability; this is single-source and stated as a possibility.
  • Whether the listed IP addresses are still malicious. Mynavi News reported they were abused in August and September 2026 but may be in legitimate use at the time of investigation.

What local media are saying

Technology mediaMynavi News and ASCII.jp set out the three attack methods in detail, including API key extraction from smartphone apps and the Metabase CVE, along with indicators and JPCERT/CC's recommended countermeasures. [ 1 , 2 ]
Official sourcesNHK reported briefly that an information security specialist body had published three attack methods confirmed so far, amid repeated personal information leaks, and was urging companies to be careful. [ 3 ]

Timeline, local time

  1. Mynavi News reports JPCERT/CC's October 8 alert on the unauthorised access cases. [ 1 ]
  2. ASCII.jp reports the three attack methods described by JPCERT/CC. [ 2 ]
  3. NHK reports that an information security specialist body has published three attack methods and urged companies to take care. [ 3 ]