Tech Blog · Cybersecurity
Noah's Ark
Designing to limit data leaks: 21 cases involving Japan
Identity-document exposure, contractor ransomware, insider misuse and cloud access settings: 21 cases involving Japanese companies and organizations, followed by practical considerations for data sharing, retention, permissions and audit logs. Confirmed leaks, possible exposure and a comparison case with no confirmed leakage are distinguished throughout.
Read the full analysis in Japanese →- Published
- Updated
- Information as of
Methodology and scope
The same 21 cases appear in both languages. Most concern incidents from 2023 onward, with earlier examples covering malicious email, credential stuffing, backup VPN equipment and USB transport. The scope includes Japanese organizations affected through overseas operations. This is a selected technical discussion, not a national incident census or frequency estimate.
Each account identifies the disclosure supporting its scope and certainty. People, records, accounts and contracts remain separate units. Overlapping fields and subsets are not added, and multiple clients' reports of one upstream incident count once. Company findings are presented separately from our design considerations below.
Company disclosures
01 · Times Car (2026): identity documents
The September 29, 2026 third report confirmed that identity documents had leaked for about 1.6 million accounts. Documents included driving licence images, proof of address, and documents used for student and family plans. This is an account count, not necessarily a count of people.[1]
The report was updated on October 1. Individual notifications had begun, with further investigation into the details.[1]
Company disclosures
02 · Kama-Asa and an external POS app (2026)
On January 27, 2026, Kama-Asa reported unauthorized acquisition of membership data through an external app connected to Smaregi. Confirmed fields were names for 5,375 people and telephone numbers for 1,825. These field-specific counts must not be added together as a victim total.[2]
The notice concerns in-store or telephone registrations, excluding customers who used only the online store. It distinguishes the external app from Smaregi's main system and official apps. Exposure of email addresses, addresses and card data was not confirmed.[2]
Company disclosures
03 · IIJ Secure MX (2025): scope changed during investigation
Company disclosures
04 · Kaikatsu Club and FiT24 (2025): possible exposure
After detecting unauthorized access on January 18, 2025, Kaikatsu Frontier reported possible exposure of 7,290,087 membership records. Its March 17 report had not confirmed an actual leak or secondary harm. The number describes possible scope.[5]
The reported scope included names, addresses and telephone numbers, while excluding card data, email addresses and app passwords. The report also described program changes and stronger monitoring. Those measures do not establish that each potentially affected record was stolen.[5]
Company disclosures
05 · Tully's online store (2024): payment application tampering
Tully's October 3, 2024 report described intrusion through a system vulnerability and tampering with a payment application. Possible exposure involved 92,685 personal-information records, including 52,958 card-information records. The card count is a subset.[6]
The card scope covered purchases from July 20, 2021 to May 20, 2024; membership records used a different period. The notice excluded the Rakuten store, app, digital gifts and Tully's Card registration data.[6]
Company disclosures
06 · KADOKAWA (2024): confirmed personal-information leak
For the attack detected on June 8, 2024, KADOKAWA's August 5 report confirmed external leakage of personal information for 254,241 people. Groups included business partners, former employees, job applicants, and N/S school students and guardians. Leakage of Niconico login credentials was not confirmed.[7]
The company presumed that employee account information had been stolen through phishing or a similar method, but had not established the route or method. The confirmed affected count and the presumed initial access mechanism carry different certainty.[7]
Company disclosures
07 · Iseto and Kumon (2024): outsourced printing and mailing
Kumon reported that ransomware at its printing and mailing contractor Iseto caused a leak. Its August 20, 2024 third report identified 739,714 members in the newly established scope after removing overlap within that scope. An earlier notice concerned 4,678 people with contact or authentication-code information; the categories must not be simply added.[8]
The exposed membership data included learning materials, classroom details, school year and test information. Kumon described minimizing data supplied to contractors and confirming deletion after work.[8]
Company disclosures
08 · Tokyo Gas Engineering Solutions (2024)
Company disclosures
09 · Fujitsu (2024): files on employee computers
Fujitsu's July 9, 2024 investigation followed its March 15 disclosure. Forty-nine computers in its domestic internal network were affected, with possible unauthorized copying and external removal of files containing personal and business information. Forty-nine is a computer count, not a victim count.[11]
The report found no evidence of impact on customer cloud services and distinguished the malware from ransomware.[11]
Company disclosures
10 · Okayama Psychiatric Medical Center (2024): clinical documents
A system failure occurred on May 19, 2024, followed by confirmation of ransomware the next day. The February 13, 2025 investigation report states that police confirmed information leakage on June 7. Shared-folder documents included names, addresses and diagnoses, with a scope estimated at up to 40,000 people.[12]
Shared clinical documents are distinct from the electronic medical record system itself. Leakage was confirmed, while the affected population remained an estimate. Missing logs prevented establishment of the initial intrusion route; the report does not justify naming a specific vulnerable device as the cause.[12]
Company disclosures
11 · Tokio Marine & Nichido (2024): agency and secondee disclosures
The August 30, 2024 report on an issue discovered in April described leakage of about 860,000 records concerning the company's policyholders and others to other insurers at 384 multi-insurer agencies. Separately, the company received about 100,000 records about other insurers through secondees at 35 agencies, including about 80,000 individual and 20,000 corporate records. Different directions and units cannot become '960,000 people'.[13][14]
Company disclosures
12 · LY Corporation (2023): shared authentication infrastructure
The November 27, 2023 disclosure, updated February 14, 2024, describes malware on a contractor's employee computer and intrusion through infrastructure shared with NAVER. Updated figures were 302,980 user, 86,211 business-partner and 130,315 employee-related records, including possible exposure. Estimates and overlap prevent a unique-person total.[15]
The updated notice also revised the initial intrusion date. It excluded LINE chat contents, bank-account and card information from the affected scope. Shared authentication infrastructure does not mean every category of LINE data leaked.[15]
Company disclosures
13 · NTT West (2023): insider activity at a contractor
NTT West's October 17, 2023 notice confirmed unauthorized removal and third-party leakage of about 1.2 million customer records used in its telemarketing work by a former dispatched employee. Fields included names, addresses and telephone numbers, and some dates of birth.[16]
The count concerns NTT West's commissioned work, not every client or the entire group. Bank-account, card and password information was excluded. This is an insider misuse case involving authorized work access, distinct from internet-based intrusion.[16]
Company disclosures
14 · Plala and Hikari TV (2023): personal external storage
NTT Docomo's July 21, 2023 update reported that a former dispatched worker at NTT Nexia had improperly moved sales-support files to personally contracted external storage. Investigation expanded the initial maximum of about 5.29 million records to about 5.96 million, including former customers.[17]
The breakdown was about 1.65 million Plala and 4.31 million Hikari TV records, with overlap handling explained. Unauthorized removal was confirmed; third-party viewing, saving or misuse was not. The notice excluded payment information and passwords.[17]
Company disclosures
15 · Toyota (2023): cloud access settings
Toyota's May 31, 2023 additional report described externally accessible vehicle-ID and map-update information relating to about 260,000 domestic customers because of cloud settings. That domestic scope differs from the names and addresses discussed for overseas customers in the same report.[18]
The domestic data alone could not identify specific individuals. Evidence of third-party copying or misuse, and secondary harm, had not been confirmed. External accessibility is distinct from observed acquisition, and this additional scope must not be combined with other notices as if it were one count.[18]
Company disclosures
16 · MKSystem (2023): ransomware affecting HR services
The Personal Information Protection Commission's March 25, 2024 action concerned MKSystem's June 2023 ransomware incident. Encryption created a risk of leakage or other loss of personal data. Up to about 22.42 million people describes the managed population, not confirmed leak victims.[19]
The document also reports 3,067 submitted reports and an aggregate reported population of 7,496,080, excluding unknown counts and potentially containing overlap. Reports, managed populations and confirmed exposure are different measures. Multiple clients reporting the same platform incident do not create separate attacks.[19]
Company disclosures
17 · JAXA (2023): stolen accounts used against cloud services
JAXA's July 5, 2024 report concerns intrusion recognized in October 2023. It describes targeting VPN equipment, spreading into servers, stealing account information and impersonating legitimate users in Microsoft 365. Leakage of some cloud-held business and personal information was confirmed.[20]
Possible leakage from endpoints and servers was treated separately, without a published affected-person count. The compromised systems did not handle sensitive rocket or satellite operations information. The report separately states that other intrusions detected in 2024 had not caused confirmed leakage.[20]
Company disclosures
18 · Amagasaki (2022): lost USB, no confirmed leak
Following the temporary loss of a USB drive on June 21, 2022, Amagasaki's November 28 report stated that forensic checks of the recovered drive and related computers and servers found no confirmed personal-information leakage. This is a comparison case about loss and evidence, not a confirmed breach.[21][22]
Company disclosures
19 · Capcom (2020): a legacy VPN device
Capcom's April 13, 2021 investigation covered the disruption detected in November 2020. Initial access occurred in October through an old backup VPN device at its North American subsidiary, with impact in Japan and the US. Confirmed personal-information leakage concerned 15,649 people.[23]
That count is not limited to Japan and is separate from possible exposure. Lost logs constrained parts of the investigation; a maximum possible population must not be presented as confirmed. The reported initial entry point was backup equipment rather than an actively used primary device.[23]
Company disclosures
20 · Uniqlo and GU (2019): credential stuffing
Fast Retailing's May 13, 2019 notice confirmed unauthorized login to 461,091 Uniqlo/GU online-store accounts between April 23 and May 10. Names, addresses and contact details may have been viewed. Confirmed login is distinct from confirmation that every field was exported.[24]
The company presumed credential stuffing using credentials possibly leaked from other services. Only part of card numbers was displayed, and security codes were neither displayed nor stored. Affected passwords were invalidated. Reused passwords can connect otherwise separate services' security incidents.[24]
Company disclosures
21 · Japan Pension Service (2015): malicious email
The ministry's June 12, 2015 account states that unauthorized access through malicious email led to personal-information leakage discovered on May 28 and announced June 1. At that stage, about 1.25 million records were thought to have leaked. We preserve the source's unit: records, not people.[25]
The ministry also announced an investigation committee and warned about impersonation calls exploiting the incident. This is a historical example, not an event that occurred in 2026.[25]
Our analysis
Follow data beyond the recipient
The Kumon, TGES and external POS-app cases show why reviewing only a company's own systems cannot describe data held by contractors and integrations. For your own environment, record the fields transferred, purpose, storage location, subcontractors, deletion date and responsible owner together. This gives incident responders a concrete route for determining affected data.
Check whether unnecessary authentication fields accompany mailing files or identity-document images remain after their purpose ends. Supply only necessary fields and verify deletion through the actual process and records. These are checks for your environment, rather than assertions about undisclosed weaknesses at the organizations described.
Our analysis
Separate authentication from data export
A valid login does not justify unlimited data retrieval. Separate everyday work accounts, contractor maintenance access and personally contracted storage. Limit bulk exports and identity-document viewing to the scope required for the job. MFA, time-limited permissions and destination restrictions constrain different operations.
Using actual permission settings, establish what one compromised identity can reach across shared folders, customer data, cloud systems and backups. Monitor normal human viewing separately from machine-driven bulk retrieval, and preserve evidence of unusual volumes or destinations even when the underlying operation is authorized.
Our analysis
Logs that support a conclusion
External accessibility, account misuse, file exfiltration, public disclosure and secondary harm are different facts. Correlate authentication, viewing, export and transmission histories. Short retention or logs that a compromised administrator can delete may leave responders unable to determine whether exposure occurred.
Protect logs under separate administration and detect collection failures. Record confirmed findings and uncertainty alongside the affected scope at that time. Prepare notification counts that preserve units, overlapping records and field-specific subsets.
Implications for mitigation
Six checks for your own operations
Remove unnecessary fields and authentication information from data sent to contractors and integrations.
Assign retention periods and deletion owners, including for former customers.
Identify subcontractors, external apps, backup devices, storage locations and external access points.
Constrain bulk export, external transmission and backup deletion after one identity is compromised.
Keep viewing, export and transmission logs under separate permissions and detect collection failures.
Separate confirmed leakage from possible exposure and reconcile notification counts without mixing units.
Disclaimer
We did not conduct the named organizations' forensic investigations or assessments. Factual accounts draw on the cited company and public-authority reports and contain no original investigation or vulnerability discovery. Unpublished circumstances cannot be established, and later findings may revise the accounts. The design considerations are proposals, not reports of implementation or validated protection at these organizations.
Primary sources
タイムズモビリティ — タイムズカーWebシステムへの不正アクセスに関する調査結果および今後の対応(第3報、10月1日追記)
Publication date: · Accessed:
https://share.timescar.jp/news/2026/0929/1816.html釜浅商店 — 個人情報漏えいに関するお知らせとお詫び
Publication date: · Accessed:
https://kama-asa.co.jp/en/blogs/news/info-20260127-1インターネットイニシアティブ — IIJセキュアMXサービスへの不正アクセスによる情報漏えいについて
Publication date: · Accessed:
https://www.iij.ad.jp/news/pressrelease/2025/0415.htmlインターネットイニシアティブ — IIJセキュアMXサービスへの不正アクセスに関する追加情報(4月22日)
Publication date: · Accessed:
https://www.iij.ad.jp/news/pressrelease/2025/0422-2.html快活フロンティア — 個人情報漏えいに関するお詫びとお知らせ(3月17日報告)
Publication date: · Accessed:
https://www.kaikatsu.jp/info/detail/ddos.htmlタリーズコーヒージャパン — 弊社が運営するタリーズオンラインストアへの不正アクセスによる個人情報漏洩に関するお詫びとお知らせ
Publication date: · Accessed:
https://www.tullys.co.jp/information/2024/10/post-14.htmlKADOKAWA — ランサムウェア攻撃による情報漏洩に関するお知らせ
Publication date: · Accessed:
https://group.kadokawa.co.jp/information/media-download/1356/d3f77b589c58d083/公文教育研究会 — 業務委託先へのランサムウェア攻撃による個人情報の漏えいについて(第三報)
Publication date: · Accessed:
https://www.kumon.ne.jp/oshirase/2024081.html東京ガス — 不正アクセスによるお客さま等に関する情報流出の可能性についてお詫びとお知らせ
Publication date: · Accessed:
https://www.tokyo-gas.co.jp/news/press/20240717-03.html日本ガス — 業務委託先への不正アクセスによる個人情報流出の可能性(続報・お客さまへの個別通知)
Publication date: · Accessed:
https://www.nihongas.co.jp/news/2024/12/post-390.htmlFujitsu — Notice regarding results of security incident investigation
Publication date: · Accessed:
https://www.fujitsu.com/global/about/resources/news/notices/2024/0709-01.html岡山県精神科医療センター — ランサムウェア感染による情報セキュリティインシデント調査報告書
Publication date: · Accessed:
https://www.okayama-pmc.jp/wp-content/uploads/2025/02/24bb9b94f7eb10eff58b605c01c384ad.pdf東京海上日動火災保険 — 情報漏えい事案にかかる金融庁への報告について(9月2日訂正)
Publication date: · Accessed:
https://www.tokiomarine-nichido.co.jp/company/release/pdf/240830_01.pdf東京海上日動火災保険 — 情報漏えい事案に対する指導について
Publication date: · Accessed:
https://www.tokiomarine-nichido.co.jp/company/release/pdf/250430_01.pdfLINEヤフー — 不正アクセスによる情報漏えいに関するお知らせとお詫び(2024年2月14日更新)
Publication date: · Accessed:
https://www.lycorp.co.jp/ja/news/announcements/007712/NTT西日本 — お客さま情報の不正流出に関するお詫びとお知らせ
Publication date: · Accessed:
https://www.ntt-west.co.jp/news/2310/231017a.htmlNTTドコモ — 個人情報の不正流出に関するお詫びとお知らせ(続報)
Publication date: · Accessed:
https://www.plala.or.jp/support/info/2023/0721/index.htmlToyota Motor Corporation — Additional Report on Potential Data Leakage of Customer Information
Publication date: · Accessed:
https://global.toyota/en/newsroom/corporate/39241625.html個人情報保護委員会 — エムケイシステムに対する行政上の対応について
Publication date: · Accessed:
https://www.ppc.go.jp/files/pdf/240325_houdou.pdf宇宙航空研究開発機構 — JAXAにおいて発生した不正アクセスによる情報漏洩について
Publication date: · Accessed:
https://www.jaxa.jp/press/2024/07/20240705-2_j.html尼崎市 — USBメモリー紛失事案調査委員会調査報告書を受けての市の対応
Publication date: · Accessed:
https://www.city.amagasaki.hyogo.jp/_res/projects/default_project/_page_/001/030/947/221128.pdf尼崎市 — 個人情報を含むUSBメモリーの紛失事案について(再発防止策)
Publication date: · Accessed:
https://www.city.amagasaki.hyogo.jp/shisei/si_torikumi/gkaizen/1030947.htmlCapcom — Update Regarding Data Security Incident (Investigation Results)
Publication date: · Accessed:
https://www.capcom.co.jp/ir/english/news/pdf/e210413.pdfファーストリテイリング — リスト型攻撃によるオンラインストアへの不正ログインの発生とパスワード変更のお願い
Publication date: · Accessed:
https://www.fastretailing.com/jp/group/news/1905132000.html厚生労働省 — 日本年金機構における不正アクセスによる情報流出事案について
Publication date: · Accessed:
https://www.mhlw.go.jp/stf/seisakunitsuite/bunya/0000152638.html