NEWS

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

JPCERT/CC says Japan logged 119 web data-leak incidents in 2026, driven by mobile API abuse and an unauthenticated Metabase SQLi flaw (CVE-2026-72898).

Dylan H.

News Desk

October 8, 2026
8 min read
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Japan's national incident response body, the JPCERT Coordination Center (JPCERT/CC), issued alert JPCERT-AT-2026-0030 on October 8, 2026, warning that personal-data leaks tied to web-system intrusions at Japanese organizations are accelerating sharply. Drawing on incident reports it has received and research from Japanese security firm Macnica, JPCERT/CC tied the surge to two overlapping techniques: abuse of APIs built for mobile apps to reach backend functionality and data that were never meant to be reachable directly, and active exploitation of an unauthenticated SQL injection flaw in the business-intelligence platform Metabase, tracked as CVE-2026-72898 with a maximum CVSS score of 10.0. JPCERT/CC described the pattern as distinct from ransomware and other routine incidents, cautioning that the evidence it has is "limited and fragmentary" and that not every leak necessarily involved the same method.


Incident Details

AttributeValue
Alert IDJPCERT-AT-2026-0030
Issued ByJPCERT/CC (Japan Computer Emergency Response Team Coordination Center)
Date IssuedOctober 8, 2026
Incidents in 2026119 publicly disclosed web-system breaches through October 6, 2026 (Macnica dataset)
Year-over-Year Trend62 incidents in 2024, 84 in 2025, 119 in 2026 (through early October) — 265 total since January 2024
Recent Acceleration81 of the 119 2026 incidents were disclosed in July or later
International Scope99 comparable cases found in 13 other countries/regions since July, including 30 in South Korea, 11 in France, and 8 in Poland
Primary Attack VectorsMobile API abuse; weak admin-panel credentials and known software flaws; Metabase SQL injection
Key VulnerabilityCVE-2026-72898 — unauthenticated SQL injection in Metabase, CVSS 10.0
Disclosure QualityRoughly 80% of recent public disclosures lacked enough technical detail to classify the intrusion method
Notable Incidents (broader dataset)Park24 / Times Car (approximately 6.6 million accounts, 1.6 million identity documents); Monogatari Corporation / Yakiniku King (10,788,963 records)
Affected SectorsOnline shops, membership services, internal business systems, libraries, tourist booking platforms, and BI dashboards

How It Worked

Mobile API abuse

JPCERT/CC said it received multiple reports describing a consistent pattern: attackers reverse-engineer a publicly released smartphone app to recover the API endpoints and keys it talks to, then probe those APIs directly rather than through the app's own screens. From there, attackers targeted internal APIs that the app's user interface never exposes, using them to escalate account privileges, create unauthorized accounts, and manipulate request headers or submit malformed tokens to see how the backend responded. In several cases, attackers used blind NoSQL injection against these endpoints to extract account details that the API was never designed to return directly. A secondary path involved API keys stolen during the compromise of another, unrelated system, which were then replayed against the exposed endpoints. Underlying weaknesses cited by JPCERT/CC included excessive data returned by endpoints, overprivileged access tied to anonymous or low-trust sessions, application logic errors, and weak session-management controls.

Weak admin credentials and known flaws

JPCERT/CC confirmed a second, related pattern in some incidents: attackers reached administrative login screens protected only by weak or reused passwords, and in other cases exploited publicly known software vulnerabilities that had not been patched. Several of the systems involved — business intelligence tools and employee-facing management applications — were never intended by their operators to be reachable from the public internet at all, yet were still discoverable and exposed.

Metabase SQL injection (CVE-2026-72898)

The alert separately flagged active exploitation of CVE-2026-72898, an unauthenticated SQL injection vulnerability in Metabase that requires no account or valid session to trigger. The flaw allows an attacker to inject SQL into Metabase's own internal application database, which can be leveraged to obtain administrator access to the Metabase instance itself. From there, an attacker can retrieve the credentials Metabase stores for its connected databases and use them to read or export the underlying data directly — turning a single unpatched BI dashboard into a path straight into production data warehouses. Metabase shipped patches in August 2026, and JPCERT/CC had already warned about the vulnerability on August 14, 2026, urging organizations to upgrade to the vendor's minimum safe releases. Organizations still running versions below those fixed releases as of this alert remain exposed.

Impact Assessment

Impact AreaDescription
Scale of Exposure119 disclosed incidents in 2026 alone, nearly double 2025's total, with the majority disclosed since July
Data SensitivityPersonal account data, identity documents, and in some cases full customer records numbering in the millions per incident
Attack Surface ExpansionMobile apps and internal/BI tooling — not just traditional web front ends — are now primary leak vectors
Severity of Metabase FlawCVSS 10.0, unauthenticated, directly enables lateral access to connected production databases
Detection GapRoughly 80% of public disclosures provide too little detail for defenders to map the intrusion method used against them
Global RelevanceSimilar activity observed in 13 other countries/regions, indicating this is not a Japan-specific technique set
Organizational ExposureBI dashboards and admin panels operators believed were internal-only were still internet-reachable and exploited

Recommendations

For mobile app developers and API owners

  • Treat every API endpoint reachable by a mobile app — including those not exposed through any app screen — as a public attack surface, and enforce authorization checks on all of them, not just the ones the UI calls.
  • Apply the principle of least privilege to API tokens: scope them narrowly, set short expiration windows, and build rapid revocation into the token-issuance pipeline.
  • Implement rate limiting and separate, stricter controls on computationally or data-expensive endpoints to blunt automated enumeration and bulk-extraction attempts.
  • Monitor for the abuse indicators JPCERT/CC called out: anomalous header manipulation, malformed or replayed tokens, and NoSQL injection patterns in query parameters.

For organizations running Metabase or similar BI tools

  • Upgrade Metabase immediately to a version at or above the vendor's minimum safe release addressing CVE-2026-72898 if this has not already been done since the August 2026 patch.
  • Audit which BI dashboards, admin consoles, and internal management tools are actually reachable from the public internet — several of the incidents JPCERT/CC reviewed involved systems operators believed were internal-only.
  • Rotate credentials stored for any database connected to a BI tool that was exposed, and review Metabase's own application logs for signs of unauthorized query activity predating the patch.

For security and SOC teams

  • Review access logs for the indicators published in JPCERT/CC's alert, including the listed source IP addresses and User-Agent strings associated with this activity.
  • Strengthen administrator authentication fleet-wide with multi-factor authentication and the retirement of shared or weak admin-panel passwords.
  • Minimize retained personal data wherever feasible, reducing the blast radius of any future API or database compromise.

For consumers of affected services

  • Monitor accounts at Japanese online retailers, membership platforms, and similar services for unauthorized activity, particularly if you hold accounts with organizations named in recent disclosures.
  • Treat unexpected password-reset prompts or unfamiliar login notifications as a signal to change your password and enable multi-factor authentication where available.

Key Takeaways

  1. JPCERT/CC issued alert JPCERT-AT-2026-0030 on October 8, 2026, warning of a sharp rise in web data leaks at Japanese organizations, with Macnica tracking 119 disclosed incidents in 2026 against 84 in 2025 and 62 in 2024.
  2. 81 of the 119 2026 incidents were disclosed in July or later, indicating the trend is accelerating rather than steady.
  3. Mobile API abuse — reverse-engineering app binaries to find hidden endpoints and keys, then attacking internal APIs with privilege escalation, token manipulation, and blind NoSQL injection — is a primary driver.
  4. An unauthenticated SQL injection flaw in Metabase, CVE-2026-72898 (CVSS 10.0), lets attackers gain administrator access to a Metabase instance and pivot to the credentials of every database it connects to.
  5. Similar activity was observed in 13 other countries/regions, including South Korea, France, and Poland, suggesting this is a broader technique set rather than a Japan-specific campaign.
  6. Roughly 80% of recent public disclosures lack enough detail for defenders to classify the intrusion method, underscoring a persistent transparency gap in breach reporting.

Sources