Security & privacy

Japanese data leaks surge due to mobile API abuse and Metabase flaws

A sharp rise in web data leaks in Japan stems from mobile API reverse engineering and exploitation of a critical Metabase vulnerability, affecting millions of records.

A cracked smartphone screen with leaking API code and a warning icon.
Illustration generated for this article

Japanese organizations are experiencing a significant spike in personal data leaks driven by attackers exploiting mobile application programming interfaces (APIs) and known software vulnerabilities. The JPCERT Coordination Center issued an alert on October 8, 2026, highlighting these trends based on incident reports from September 2026. The attacks have compromised millions of user accounts across various sectors, including car-sharing services and restaurant chains.

What happened

The volume of publicized data breach incidents in Japan has risen sharply in recent months. Security Research Center Macnica reported 119 such incidents through October 6, 2026, with 81 occurring in July or later. This contrasts with 84 incidents in all of 2025 and 62 in 2024. These figures exclude ransomware cases and focus on web system compromises leading to data theft. While many cases lack detailed technical explanations, the targets range from online retail shops to internal business systems and customer support platforms.

High-profile examples illustrate the scale of the damage. Park24 disclosed that a third party accessed data for approximately 6.6 million accounts in its Times Car car-sharing service, including identity documents for 1.6 million users. Similarly, Monogatari Corporation reported that over 10.7 million records leaked from the member system of its Yakiniku King app. Although both companies stated investigations were ongoing, the pattern suggests systematic exploitation rather than isolated errors. Macnica also identified 99 similar cases in other countries, including South Korea and France, indicating a broader global trend.

How it works

Attackers are primarily using three methods to gain unauthorized access. First, they reverse-engineer publicly available smartphone apps to discover hidden API endpoints and keys. They then send unauthorized requests to these management APIs, often bypassing the app’s user interface restrictions. Techniques include blind NoSQL injection, manipulating authentication tokens, and changing user privileges. In some instances, attackers use API keys stolen from other compromised systems to mimic legitimate traffic.

Second, attackers scan for a variety of known flaws and poor configuration practices. This includes exploiting weak admin passwords, accessing backup files, or targeting APIs that return excessive data or allow anonymous access to member functions. Rather than relying on a single zero-day exploit, adversaries probe each target for multiple weaknesses, leveraging logic errors and session management faults.

Third, a specific critical vulnerability in Metabase, an open-source business intelligence tool, has been widely exploited. Identified as CVE-2026-72898, this SQL injection flaw carries a maximum severity score of 10.0. It allows unauthenticated attackers to inject SQL commands into Metabase’s application database, potentially gaining administrator access. From there, they can steal credentials for connected databases and exfiltrate large volumes of data. The flaw was actively exploited as a zero-day before patches were fully adopted.

Key details

  • JPCERT/CC reported a sharp increase in data leaks in Japan during September 2026, with 81 of 119 annual incidents occurring since July.
  • Attackers reverse-engineer mobile apps to find and abuse internal API endpoints, often using stolen keys or manipulating authentication headers.
  • CVE-2026-72898 is a critical SQL injection vulnerability in Metabase that allows unauthenticated remote code execution and data theft.
  • Metabase users must upgrade to specific minimum safe releases, such as 0.63.13 for version 63, as earlier fixes were insufficient.
  • Indicators of compromise include specific source IP addresses like 3.112.252[.]14 and User-Agent strings such as python-requests/2.34.2.
  • Macnica observed 99 similar incidents in 13 other countries, suggesting the attack methodology is not limited to Japan.

Why it matters

For software engineers and security teams, this trend highlights the risks of assuming mobile app APIs are secure by obscurity. When client-side code contains keys or endpoint definitions, attackers can easily extract them and interact directly with backend services. This bypasses front-end validation and exposes internal management functions that were never intended for public access. The sheer volume of data leaked in these incidents demonstrates how quickly automated tools can scrape exposed APIs once access is gained.

The Metabase exploitation underscores the importance of timely patching and understanding the difference between a initial fix and a comprehensive security release. Many organizations may have applied the first patch for CVE-2026-72898 but remained vulnerable because Metabase subsequently raised the minimum safe version requirements. Failure to monitor vendor advisories for updated guidance left many instances exposed to continued attacks even after initial remediation efforts.

What you can do

  • Audit all mobile app API endpoints and ensure strict access controls are enforced on every endpoint, regardless of whether it is public-facing.
  • Implement rate limiting on sensitive API functions such as login, password reset, and search to prevent bulk data extraction.
  • Check your Metabase version against the latest safe release list and upgrade immediately if you are running a vulnerable build.
  • Rotate all API keys and database credentials if you suspect any exposure, and revoke any unrecognized active sessions.
  • Monitor server logs for sudden spikes in error responses like 403 or 404, and investigate traffic from known malicious IP addresses.
  • Restrict access to internal management APIs by IP whitelist or require strong mutual TLS authentication for service-to-service communication.

Tools from the Bytechap store

Keep reading

All stories