Wave of cyberattacks on Japanese companies exposes data of millions
Tokyo urges security reviews as experts say AI lowers the hacking bar
Partly confirmed
The takeaway
In September and early October 2026 a run of intrusions at Japanese companies (Park24’s Times Car car-sharing, 6.6M accounts; the Yakiniku King chain operator Monogatari, 10M+ customers; Daiwa Securities, ~110,000 clients; and others) exposed the personal data of millions.
Status
- Claim
Partly confirmed
- Our reporting
- Medium confidence
- Importance
- 2 of 5
- Last verified
- 10 October 2026
Your AI and this story
- GPT-6 Astra162 days after its cutoff
- Claude Opus 5.5101 days after its cutoff
- Gemini 3.8 Flash192 days after its cutoff
- Grok 4.7131 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 101 days before it.
Key facts
- Park24 (Times Car car-sharing): ~6.6M accounts; names, addresses, contact details, driver’s license data and ID documents; no credit-card data (MLex summary via search)
- Monogatari Corp. (Yakiniku King): data of 10M+ customers via its reservation and rewards app; Daiwa Securities: ~110,000 customers (~220,000 records incl. inquiries) via contractor Scala Communications’ server; detected Oct 4 (Beinsure)
- Also reported: Mr Max Holdings (~1.7M customers), Citizen Watch (~100,000), GMO Research & AI (948,000 users), a ransomware attack at Osaka Metropolitan University (EFE via De Último Minuto)
- Scale: 83 breach/unauthorized-access disclosures by Japanese organizations between Sept 1 and Oct 5, 18 of them affecting 100,000+ people or records (MLex, per search summary). Japan’s Digital Agency separately disclosed a breach of its Government Solution Service network exposing ~246,000 people (eSecurity Planet)
- Government: government spokesperson Minoru Kihara said the government takes the attacks ‘very seriously’ and is gathering information (EFE); Bloomberg (Oct 9): officials urged a sweeping review of corporate security
- AI angle: Bloomberg cites security experts saying AI tools lower the barrier for criminals with limited skills to hack at scale; this is a general assessment, not a finding about these breaches. Contrast South Korea, where the president said AI ‘appears’ to have been used in bank hacks (see related)
What happened
A cluster of breaches disclosed in late September and the first week of October hit Japanese retailers, restaurant chains, brokers, a university and a government network. Bloomberg’s Oct 9 story (paywalled; written here from its Techmeme summary and other outlets) framed it as a national wave and reported the government’s call for security reviews.
Why it matters
It came the same week South Korea’s president said AI appeared to have been used in bank hacks. Both governments are treating AI-accelerated cybercrime as a policy issue. For Japan, though, the AI link is still experts’ general assessment, not attribution.
Sources
5 sources from 5 sites. Numbers match the chips in the text.
5 sources: 5 press
Press
- Bloomberg: Wave of cyberattacks prompts Japan to urge security reviews (Oct 9)bloomberg.com, press
- Japan Times: Cyberattacks against Japanese firms continue, putting millions at risk of identity theft (Oct 7)japantimes.co.jp, press
- Beinsure: Japan data breaches expose millions of customer recordsbeinsure.com, press
- De Último Minuto (EFE): Multiple cyberattacks expose the data of millions of people in Japandeultimominuto.com, press
- eSecurity Planet: Japan government network breach puts 246,000 people at riskesecurityplanet.com, press
Changes
- Filed (Techmeme; Bloomberg and Japan Times not fetchable, facts from other outlets)