Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
JPCERT/CC warns of a surge in Japanese web data leaks via mobile API abuse and Metabase SQL injection.
JPCERT/CC warned that Japanese organizations are seeing a run of personal-data leaks through abused mobile-app APIs and exploitation of known flaws, including Metabase SQL injection CVE-2026-72898 (CVSS 10.0), which was exploited as a zero-day and added to CISA’s KEV catalog on August 11. Macnica counted 119 similar public incidents in Japan through October 6, 2026, versus 84 in all of 2025, with 81 since July. Park24 said about 6.6 million Times Car accounts were exposed and identity documents leaked from about 1.6 million; Monogatari Corporation reported 10,788,963 Yakiniku King member records leaked. Attackers extracted API keys from apps, called hidden management APIs, used blind NoSQL injection, and, in confirmed Metabase cases including AhaSlides, reached connected databases.