Key takeaways

  • Asahi Kasei Therapeutics (旭化成セラピューティクス), the pharmaceutical arm of Japan's Asahi Kasei group, said on October 6, 2026 that attackers had broken into the member database behind Pharma DIGITAL, its information website for doctors and other healthcare professionals in Japan.
  • The site is run by an outside vendor, Pharma Information Network (医薬情報ネット, PIN). PIN detected the attack and reported it on October 2.
  • Data on up to 514,000 healthcare professionals may have been viewed or taken: names, workplaces, workplace addresses, job types and specialties. About 44,000 of them also had email addresses stored. Data on about 700 employees was also affected.
  • It follows a similar leak of healthcare professionals' data at Sanofi in Japan in 2024, also involving an outside contractor.

What happened#

According to notices from Asahi Kasei Therapeutics and PIN:

Date (2026) Event
Oct 2 PIN confirms that the database linked to Pharma DIGITAL was accessed in a cyberattack, and reports it to Asahi Kasei Therapeutics the same day. The website is shut down immediately
Oct 6 Both companies publish notices

The companies say the route the attackers used has been closed, and no further access has been seen. They have reported the incident to the authorities and are investigating with outside experts. Pharma DIGITAL remains offline.

Pharma DIGITAL provides doctors, pharmacists and other healthcare professionals in Japan with information on the proper use of Asahi Kasei Therapeutics' prescription drugs and other medical information. The company was called Asahi Kasei Pharma until April 2026, and in September Asahi Kasei announced it would unify its global pharmaceutical business under the Asahi Kasei Therapeutics name. The breach concerns the Japanese site.

What may have been exposed#

Who Data People (maximum)
Healthcare professionals Name, facility name and address, job type, specialty and more About 514,000
Of those Also email address and more About 44,000
Asahi Kasei Therapeutics employees Name, email address, photo About 700

No payment card data or sensitive personal data, such as health information, was stored, the companies say. They have found no misuse so far. Affected healthcare professionals will be contacted by email.

What we don't know yet#

The companies have not said:

  • How the attackers got into the database
  • When the access began, and how it was detected
  • Whether data was actually taken or only possibly viewed
  • Whether PIN runs similar sites for other pharmaceutical companies on the same systems, and whether any of them are affected
  • Whether a ransom has been demanded. As of October 7, we found no listing on ransomware leak site trackers

Our analysis#

A directory of Japan's healthcare workers#

The data is not medical records. But it is close to a directory: who works where, in what role and in which specialty, for more than half a million healthcare professionals. For attackers, that is targeting material. A phishing email that names a doctor's hospital and department, and appears to come from a drug company they deal with, is far more convincing than a generic one. Hospitals in Japan have been among the country's most damaging ransomware victims in recent years. Doctors and pharmacists on this list should treat unexpected messages about Asahi Kasei products, seminars or the breach itself with caution.

Pharma's healthcare professional databases keep leaking#

Drug companies build large databases of healthcare professionals for marketing and information services, and often hand their running to outside firms. In August 2024, Sanofi in Japan disclosed a leak affecting about 730,000 people, mostly healthcare professionals. In that case, an outside consultant had stored database login details on a personal computer, against Sanofi's policy, according to ITmedia.

Asahi Kasei Therapeutics now faces the same problem through a different vendor. Its notice promises to strengthen oversight of its contractors. That is the same promise Daiwa Securities and Citizen made this week after their inquiry-management vendor was breached. It is the third incident this week in which a breach at one organization spread to others: Scala Communications' clients, Nikkei BP, phished from a hijacked Nikkei mailbox, and now Asahi Kasei Therapeutics through PIN.

One vendor, possibly more clients#

PIN provides marketing support to pharmaceutical and medical device companies, according to its website. Its notice covers only Pharma DIGITAL and does not say whether its other services or clients share infrastructure with it. After the i-ask breach, where one server held data for up to five companies, that is the obvious next question. We have no indication that other clients are affected. But PIN and its clients should say so either way.

Both notices ask readers to use an inquiry form at a shortened link (x.gd). The same notices warn healthcare professionals not to open links in suspicious emails. A link shortener hides the destination, which is exactly what people are trained to distrust. Breach notices should link directly to a page on the company's own domain.

What this means for readers#

  • If you are a healthcare professional registered with Pharma DIGITAL, expect an email from Asahi Kasei Therapeutics. Treat other messages that mention the breach, Asahi Kasei products or your workplace with caution, and do not enter login details through links in them.
  • Hospitals and pharmacies may want to warn staff that their names, workplaces and specialties may be in attackers' hands, and that targeted phishing is possible.
  • Pharmaceutical companies that outsource healthcare professional websites should ask their vendors where their data is stored, and whether it shares systems with other clients.

Japanese terms at a glance#

Japanese Reading Meaning
旭化成セラピューティクス Asahi Kasei Serapyūtikusu Asahi Kasei Therapeutics (formerly Asahi Kasei Pharma)
医薬情報ネット Iyaku Jōhō Netto Pharma Information Network (PIN), the vendor
医療従事者 iryō jūjisha Healthcare professionals
所属施設 shozoku shisetsu Workplace (hospital, clinic, pharmacy)
診療科 shinryōka Medical department or specialty
要配慮個人情報 yō hairyo kojin jōhō Sensitive personal data (e.g. health information)
委託先 itakusaki Contractor, vendor

We will update this article when the companies publish the cause, or if other pharmaceutical companies report being affected.