Japan alert highlights API abuse and Metabase attacks behind data leaks

Japan’s JPCERT Coordination Center has warned of a series of personal-data leaks involving abuse of mobile-app APIs, exposed business systems and known software vulnerabilities. The October 8 alert follows incidents disclosed around September 2026 and does not identify either a responsible actor or affected organizations.
Macnica’s Security Research Center counted 119 publicly disclosed incidents in Japan through October 6 that it judged similar to the current series, compared with 84 in all of 2025 and 62 in 2024. Of this year’s total, 81 were disclosed from July onward; 65 of those notices contained too little detail to establish how intruders gained access.
API exposure and weak controls are central concerns
JPCERT/CC said attackers have sent unauthorized requests to management APIs used by mobile applications. Reported activity includes analysing publicly released apps to identify API endpoints and keys, reaching internal functions unavailable through the normal app interface, altering privileges, creating unauthorized accounts and using blind NoSQL injection to obtain account details.
The centre also described API keys stolen through compromise of another system, alongside flaws such as excessive API responses, over-privileged tokens, anonymous access to member functions, logic defects and session-management failures. Weak administrator passwords and exploitation of known vulnerabilities were confirmed in some cases. JPCERT/CC stressed that the available information is limited and fragmentary, and that the same method has not been established across every incident.
The affected services span online shops, member platforms, business systems and customer support functions. Park24 said a third party obtained data on about 6.6 million Times Car accounts, and later said identity documents had leaked from about 1.6 million accounts. Monogatari Corporation said 10,788,963 records leaked from the member system for its Yakiniku King app; both companies said the causes remained under investigation at the time.
Metabase vulnerability remains an urgent patching issue
JPCERT/CC also highlighted CVE-2026-72898, a CVSS 10.0 SQL-injection vulnerability in the open-source BI platform Metabase. An unauthenticated attacker can inject SQL into Metabase’s application database, potentially obtain administrator access, recover credentials for connected databases and read or export their data. The remediation history for Metabase zero-day remediation history shows why applying only an initial fix may not meet the vendor’s later minimum-safe-release guidance.
Metabase said its August 6 update fixed CVE-2026-72898, but subsequently raised the minimum safe versions after another critical advisory. For open-source builds, the current minimum safe releases are 0.63.13, 0.62.16, 0.61.18, 0.60.24, 0.59.28 and 0.58.31. Versions below 58 are not affected by this vulnerability. Where upgrading is impossible, Metabase recommends blocking /api/session/reset_password as a temporary measure.
A likely compromise indicator is a POST request to that reset endpoint returning 400, followed by a GET request to /api/user/current returning 200. After exposure, Metabase advises revoking active sessions, reviewing API keys and administrator accounts, rotating credentials for every connected database, and checking warehouse, activity and query logs.
Practical checks for operators
JPCERT/CC recommends enforcing authorization on every API endpoint, limiting requests overall and on high-risk functions, applying least privilege to tokens, expiring tokens and enabling rapid revocation. Macnica adds that secrets and database credentials must not be embedded in distributed app or browser code, because obfuscation does not conceal them.
For businesses, the immediate implication is to combine patch validation with API and log reviews: investigate abnormal traffic, error spikes, unavailable-file requests and unusual use of administrative functions, then reduce exposed functionality and retain only personal data that remains necessary.

