This page lists every data breach disclosed in Japan in 2026 that affects one million or more records, ranked by size. We update it as new breaches are disclosed and as companies revise their numbers.

Key takeaways

  • 24 breaches of a million records or more have been disclosed in Japan so far in 2026. Eight of them involve more than 8 million records each.
  • Tokyo Shoko Research counts 10 breaches of a million or more at listed companies and their subsidiaries as of October 5, already more than the 6 it counted in all of 2025. Three of those exceed 10 million, as many as in the whole of 2012 to 2025.
  • Most were disclosed in a burst from mid-September to early October, including skyticket, Yakiniku King, Times Car, Bookoff and Lawson.
  • Many of the largest were not attacks on the brand itself but on a platform or vendor it relied on: an ISP email system, a booking platform, an e-commerce platform, an email delivery service hosted on IDCF Cloud, and a contractor's PC.

The list#

Ranked by the organization's own figure. "Taken" means the organization confirmed the data was taken or leaked; "Possible" means it says the data may have been viewed or taken.

Records Organization Disclosed What happened
23.62 million (taken) Gyazo (Helpfeel), screenshot sharing service Sep 16 A server vulnerability let attackers run commands and copy user data: names or nicknames, emails, password hashes and session data. The count includes anonymous accounts. Metadata for about 490 million images also leaked, including the IDs used in image URLs.
22.18 million records (taken) EPARK Relax & Esthe, booking platform for salons Jul 31 Customer data in its PeakManager booking and customer management platform was transferred out. The company says the records cannot be converted into a number of people.
14.64 million (taken) skyticket (Adventure), travel booking Oct 8 Three separate intrusions, the largest through admin functions. Names, passport spellings, birth dates, contact details and hashed passwords.
12.23 million (taken) KDDI, email system used by ISPs Jun 23 Third-party software in a mail system run for several internet providers was exploited. Email addresses leaked, and passwords for 7.62 million of them.
10.9 million (lost) Kyushu Electric Power Transmission and Distribution Jun 8 A backup storage device holding customer data went missing from its storage place. No leak has been confirmed. Bank and card data were not on it.
10.79 million (taken) Yakiniku King (Monogatari), restaurant app Oct 5 Member numbers, names, emails and phone numbers for 99.8% of app users.
8.85 million (taken) ShopServe (E-Store), e-commerce platform Aug 1 A malicious program on its servers sent shoppers' data out for over two months: names, addresses, contact details, and card holder names with partial card numbers. The count may include duplicates.
8.72 million (possible) Daiichikosho, Big Echo karaoke chain Oct 8 A contractor's PC was infected with malware.
7.72 million (taken) Murauchi.com, online electronics store Jul 24 Attackers got into part of its systems in July; a September report put the leak at about 7.7 million.
6.6 million accounts (taken) Times Car (Park24), car sharing Sep 25 Member data including driver's license details and 1.6 million images of ID documents.
6.43 million (taken) Bookoff, used goods stores Oct 9 Member data including addresses, birth dates and password hashes.
6.09 million (possible) JR East and View Card, via IDCF Cloud Oct 9 An email delivery service hit in the IDCF Cloud ransomware attack. Mainly email addresses.
4.45 million people (possible) Temairazu, hotel booking management system Sep 28 Guests of hotels using the system received suspicious messages. Names, phone numbers and emails may have been viewed or taken.
4.4 million people (viewed) Aflac Life Insurance Japan Jun 30 Customer websites were accessed without authorization, exposing policyholders' and agents' personal data.
3.89 million (possible) dip, Baitoru job sites Oct 9 A flaw in part of the website was exploited from overseas. Email addresses only.
3.18 million (taken) 2rinkan (Yellow Hat group), motorcycle supplies app Apr 23 The app's API was abused. Member data including app passwords and vehicle information.
2.16 million (taken) Lawson, Lawson ID Oct 8 Names and emails, plus phone numbers and addresses for some users.
1.8 million (possible) Yellow Hat, car maintenance booking Aug Its reservation system was breached. Names, phone numbers, emails and member numbers.
1.74 million (taken) Mr Max, discount stores Oct 6 Functions of the software behind its app and online store were misused. Member IDs, names, emails and phone numbers.
1.54 million (taken) Fines, booking system for shops Sep 25 Bookers' names, phone numbers, emails and booking details.
1.36 million accounts (possible) Sakura Internet, hosting provider Aug 19 Its sales management system had been accessed since 2023. The company says this is not a confirmed leak count.
1.3 million (possible) JR Kyushu, via IDCF Cloud Oct 9 Email addresses of JR Kyushu Web members at an email delivery service.
1.05 million accounts (taken) White Essence, dental whitening clinics Aug Its booking site and core systems were breached. The account count was announced on October 5.
1.04 million (possible) REXT, WonderGOO and Shinseido stores Aug 10 A ransomware attack encrypted servers holding member data.

How to read the numbers#

  • Records are not people. Most companies count accounts, member numbers or database records. One person can have several, and some counts include closed or anonymous accounts. Bookoff, EPARK and E-Store say so explicitly.
  • "Possible" is common. Japanese notices often say data "may have been viewed or taken" (閲覧・取得された可能性) when a company cannot rule it out. That is not the same as a confirmed leak.
  • Numbers change. Aflac, 2rinkan and EPARK all revised their figures after investigation. We use the latest.

How we compile this list#

  • Which cases: breaches first disclosed in 2026 by organizations in Japan, where the organization's own figure is one million records, accounts or people or more, including "up to" figures. Losses, such as the Kyushu Electric drive, are included.
  • Not included: breaches first disclosed before 2026 even if final numbers came out this year, such as Universal Music's online stores (3.1 million, first disclosed in October 2025) and the Bandai Channel video service (up to 1.37 million, December 2025); and figures that come only from attackers' claims, such as a claimed sale of 101 million Rakuten records.
  • Sources: each organization's own notice where available, our own articles, and the Japanese tech news sites INTERNET Watch, Impress Watch, ScanNetSecurity and Security NEXT. All sources are listed at the end of this page.

Smaller breaches appear in our weekly reviews. Ransomware attacks are tracked separately in our ransomware tracker. For how regulators have responded, see the Personal Information Protection Commission's warning and the government's response.

Japanese terms at a glance#

Japanese Reading Meaning
情報漏えい jōhō rōei Data leak, data breach
不正アクセス fusei akusesu Unauthorized access
閲覧・取得された可能性 etsuran / shutoku sareta kanōsei May have been viewed or taken
最大 saidai Up to
件 / 名 / 口 ken / mei / kuchi Records / people / customer accounts
委託先 itakusaki Contractor, vendor