Japan hit by string of cyberattacks, data breaches affecting millions-Xinhua

Japan hit by string of cyberattacks, data breaches affecting millions

Source: Xinhua

Editor: huaxia

2026-10-06 13:02:00

TOKYO, Oct. 6 (Xinhua) -- Several Japanese companies and a university have reported data breaches or cyberattacks since Monday, potentially affecting millions of customers, members, students and teachers in a series of separate incidents.

Osaka Metropolitan University said Monday that data on at least 130,000 students and teachers may have been leaked following a cyberattack that caused a system failure at the institution.

About 500 servers supporting the university's information system stopped operating after a suspected ransomware attack Friday last week, according to the university.

The campus network for students and the portal site for teaching staff remained unusable as of Monday, while lectures were canceled.

Japanese discount store chain operator Mr. Max Holdings Ltd. said Tuesday that personal data of up to 1.7 million customers may have been compromised following unauthorized access to a server handling its online shopping services.

The retailer has halted services, blocked the attack route and is working with external security specialists, regulators and police to investigate and strengthen monitoring.

Japan's internet service firm GMO Research & AI Inc. said Monday that up to 948,500 records of its members were stolen following unauthorized access to its server.

The company said some members' rewards, worth about 2.9 million yen (about 18,000 U.S. dollars), were illicitly exchanged for Amazon gift card codes.

Monogatari Corp., which operates the Yakiniku King barbecue restaurant chain, said Monday that more than 10 million pieces of customer information, covering almost its entire registered user base, were leaked following unauthorized access to a system supporting its smartphone app for restaurant reservations and rewards.

The leaked information included email addresses and phone numbers, the company said, adding that no misuse of the data had been confirmed.

Meanwhile, Daiwa Securities Group Inc. said Monday that data on around 110,000 customers of its securities brokerage unit, along with other nonpersonal information, may have been compromised following unauthorized access to a server operated by one of its contractors.

The company said that even if the information had been leaked, it could not be used to conduct transactions, including online transactions.

The incidents were separately reported by the organizations involved, and there is no indication from the information disclosed so far that they are linked to a common cyberattack. ■