Japanese companies disclosed a long list of cyberattacks and data breaches between September 1 and the first week of October 2026. The biggest exposed the accounts of millions of people. Bloomberg's headline, as summarized by Techmeme, says the slew of attacks exposed the data of millions and prompted calls for security checks, "as AI lowers hacking barriers." Bloomberg is paywalled, so this post rebuilds the picture from company disclosures and from outlets we could read: BleepingComputer, Jiji Press (via Nippon.com), Hackread and Beinsure.
One note on scope. Some of these incidents began in July or August, and several were announced in October. The "September wave" is a media label. We use it for incidents that surfaced from September 1 to October 7, 2026.
TL;DR: the incidents in one table
| Company | What was reported | Type of attack | Who says so |
|---|---|---|---|
| Times Car (Times Mobility, Park24) | About 6.6 million current and former accounts; about 1.6 million with ID documents | Unauthorized access; entry point not disclosed | Times Car updates, via BleepingComputer and Hackread |
| Gyazo (Helpfeel) | About 23.62 million user records; metadata on about 490 million images | Server flaw led to code execution | Helpfeel notice, via Tech Insider and others |
| Keio Corporation | Business systems down, mostly hotels | Ransomware | Keio, via BleepingComputer |
| Tokyo Metro | 59,000 member email addresses | Not stated | BleepingComputer |
| Monogatari (Yakiniku King) | 10,788,963 member records | Unauthorized access to app member system | Monogatari, via Japanese press and Qatar Tribune |
| Daiwa Securities | About 110,000 customers at a contractor | Unauthorized access at Scala Communications | Daiwa, via Beinsure |
| GMO Research & AI | 948,498 members; 2.86 million yen in points taken | Unauthorized access to a survey site | GMO, via Jiji Press |
| Mr Max Holdings | Up to 1,735,154 members | Unauthorized access to app and online store servers | Mr Max, via Jiji Press and Japanese press |
| Nikkei | 1,646 people's names and emails; about 9,000 phishing emails | Hijacked employee accounts | Nikkei, via BleepingComputer |
| Advantest | Personal data stolen in a February attack | Ransomware | Advantest notice, via BleepingComputer |
What is confirmed, and what is only claimed
Most of the facts above are company statements. In this post:
- Confirmed means the company said it in its own notice, and a news outlet we read reported that notice.
- Reported means a news outlet says it, and we could not read the company notice.
- Claimed means someone else says it, such as a hacker group or an analyst.
We found no hacker-group claim for most of these attacks. BleepingComputer states that no ransomware group had claimed the Keio attack, and that it found no public claim for Advantest. No source we read attributes the September incidents to a named group or to any state.
Times Car: the largest identity-document exposure
A badge on a lanyard, standing for the stolen driver's license and ID records in the Times Car data breach
Times Car is a car-sharing service run by Times Mobility, part of the Park24 Group. BleepingComputer reports that the company announced the incident on September 25, saying a third party had accessed its systems at the beginning of the month, and that it blocked the access on September 26.
On September 28, the company confirmed data theft. It said the intrusion affects about 6.6 million current and former Times Car members, plus members of the Times Business Service corporate program. According to BleepingComputer, the exposed data includes:
- full name, and department name for corporate members;
- physical address, date of birth, telephone number and email address;
- driver's license information and identity-verification document information;
- account password and linked service IDs.
Times Car said passwords were stored in "a form that cannot be restored," and that credit card information was not affected. It said it had no evidence that the data was distributed online.
Hackread adds details from Park24's updates. Times Mobility detected the unauthorized access at 9:07 a.m. on September 25. A September 29 update confirmed that identity-verification information on about 1.6 million accounts was accessed. That includes driver's license images, utility bills used to verify addresses, student ID cards and family verification documents. The company reported the incident to Japan's Personal Information Protection Commission and to police. The exact entry point is still under investigation.
Hackread also reports a side effect. The credit-information agencies CIC and JICC saw heavy traffic from people checking their credit files, and CIC reported trouble issuing reception numbers on September 29. Neither agency confirmed that the Times Car breach caused the surge.
Gyazo: a screenshot tool with a 23.62 million record leak
Illustration of a data breach leak: beads spilling from a cracked vessel, like the Gyazo records exposed in Japan's cyberattacks
Helpfeel, a Kyoto company, runs the image-sharing service Gyazo. Tech Insider reports, citing Helpfeel's notice, that an attacker broke in on September 11, and that the company confirmed it on September 16. The notice says about 23.62 million user records were disclosed without authorization. Metadata on about 490 million images was also exposed.
According to Tech Insider, the exposed items include emails, password hashes, IP addresses, text extracted from images, and in some cases location data. It also says Helpfeel described an upload-server flaw that allowed the intruder to upload malicious files and run commands. Tech Insider names The Hacker News, TechRadar Pro and Security Affairs as outlets that reported the same figures. We could read only Tech Insider, so treat the technical detail as reported, not independently confirmed.
Keio and Tokyo Metro: ransomware and a second incident
Keio Corporation is a major private railway operator. BleepingComputer reports that Keio confirmed a ransomware attack on its group servers in the early hours of September 26, 2026. The attack mainly hit the hospitality business, which includes 25 hotels, and disrupted payment systems. Train operations were not affected.
Keio gave this statement, as quoted by BleepingComputer: "We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts." Keio had not said whether customer or partner data was accessed, and no ransomware group had claimed the attack.
BleepingComputer also reports that Tokyo Metro disclosed a separate incident over the same weekend. Attackers accessed 59,000 member email addresses. BleepingComputer said it was unclear whether the two incidents were linked. We found no source that links them.
The early October disclosures
Several large disclosures arrived in the first week of October.
Monogatari (Yakiniku King). Japanese press reports that Monogatari Corporation announced on October 5 that unauthorized access hit the member-management system of its official app. The company put the number of leaked member records at 10,788,963, out of 10,808,784 registered app users. Leaked fields: member IDs, names, email addresses and phone numbers. The company said login passwords, birthdates, genders, postal codes and store-usage history were not leaked, and that it does not store card data. Beinsure reports that the company detected the breach on a Friday and had no evidence of misuse.
Daiwa Securities. Beinsure reports that the breach involved a server run by an outside contractor, Scala Communications, which provides an online customer inquiry service. Unauthorized access occurred between Friday evening and Saturday morning. About 110,000 brokerage customers may be affected (about 220,000 records when inquiries without personal data are counted). Potentially exposed: names, email addresses and account numbers. Daiwa said the data could not be used to place trades.
GMO Research & AI and Mr Max. Jiji Press, published on Nippon.com, says GMO Research & AI reported unauthorized access to its "infoQ" survey site that compromised names and phone numbers of 948,498 members. Reward points worth 2.86 million yen were fraudulently exchanged for Amazon gift codes, and GMO plans to compensate affected members in full. Jiji says discount retailer Mr Max Holdings also reported an attack that exposed phone numbers, email addresses and other data of up to 1,735,154 members of its apps and online stores. Japanese press adds that Mr Max said a third party abused a software function used to configure the service.
Nikkei. Per BleepingComputer, Nikkei said an employee's Google Workspace account was accessed in late July, which may have exposed names and email addresses of 1,646 people. In September, attackers accessed another employee's Microsoft 365 account. On September 30 they used it to send about 9,000 phishing emails to staff and interviewees. Nikkei had not attributed the attacks.
Advantest. BleepingComputer reports that the chip-test equipment maker confirmed, in a notice dated October 6, that data was stolen in a ransomware attack that began February 15. The data includes SSNs, national ID numbers, passport numbers and medical and financial information. The company has not said how many people are affected.
Context: how we got here
These incidents sit on top of a bad year. Threat-intelligence aggregator reports say Japan recorded 123 ransomware cases in the first half of 2026, the most since records began in 2020, with small and mid-size firms making up most of them. We could not verify that count against a primary source, so treat it as a secondary figure.
Earlier in the year, BleepingComputer reported on August 19 that Sakura Internet, a cloud and data-center provider selected for Japan's Government Cloud program, said up to 1,360,563 member accounts might have been affected after hackers accessed a sales-management system. Sakura told BleepingComputer the incident was not ransomware and no ransom was demanded.
Is AI behind the wave?
The title of Bloomberg's report ties the wave to AI lowering hacking barriers. Jiji Press is more careful: it says the spread of AI "may be contributing" to the spike.
Here is what the sources we read do and do not show. They show that many companies were breached in a short period. They do not show that AI tools were used in any of these specific attacks. Gyazo's described path (an upload flaw, then a database) is an old technique. Nikkei's case is phishing and account takeover. Keio is ransomware. Times Car's entry point is undisclosed.
The AI claim is a plausible, widely discussed theory. It is not a finding. For a case where investigators did point to AI tools, see our coverage of the South Korea bank hacks and ARTEX, and for the wider pattern see Armadin's AI attack swarms.
Why it matters
Three things stand out.
- Identity documents are the worst data type to lose. A password can be reset. A driver's license image cannot. With about 1.6 million Times Car accounts affected, fraudsters can try identity theft and account opening for years.
- Third parties matter. The Daiwa breach happened at a contractor. Supply-chain exposure means customers cannot tell from the brand name who holds their data.
- Loyalty and reward systems are targets. GMO's members lost points that were turned into gift codes. Points are cash-like and often poorly protected.
Our earlier coverage of AI agents in the Papercut breach and of an OpenAI agent in the Australia breach shows the same direction of travel: faster attackers, slower disclosure.
How to protect yourself
A window half covered by a curtain with a padlock, showing basic personal data protection after a Japanese breach
If you are a customer of an affected company:
- Change passwords for the affected service and for every site where you reused it. Use a password manager.
- Turn on multi-factor authentication, preferably with an authenticator app or passkey, not SMS.
- Treat unexpected messages as phishing. Times Car, for example, says it will not ask for passwords or card numbers by email, SMS or phone. Go to the company's site directly instead of using a link.
- Watch for follow-on fraud. If your ID documents were exposed, consider a credit report check, and watch for loans or cards you did not request.
- Check points and balances on reward accounts such as survey and loyalty sites.
If you run a company:
- Patch internet-facing upload and admin functions, and isolate them from your databases.
- Enforce MFA on email and cloud accounts. The Nikkei case shows one hijacked mailbox can send thousands of phishing emails.
- Store only the identity documents you must keep, and delete the rest.
- Review your vendors' access. Ask contractors how they secure customer-inquiry and support systems.
- If you deploy AI agents with access to email, files or customer systems, put guardrails around what they can do. AgentBeam is the agent security platform from the explainx.ai team that stops AI agents before they take dangerous actions. For a comparison of tools in this space, see our guide to AI agent security platforms.
Honest limitations
We could not read the Bloomberg article, the Japan Times piece of October 7, or the companies' original Japanese notices in full. Figures come from the outlets named in each section. Several numbers are the companies' own early counts and may change as investigations continue. We found no advisory from NISC, JPCERT/CC or the National Police Agency about this specific wave, so we make no claim about one. If you are affected, follow the company's notice first.
What people are asking
The questions above cover the main points. The short version: the attacks are separate incidents, most are unattributed, ransomware is confirmed only at Keio and Advantest, and the AI link is a theory.
Related reading
- South Korea AI bank hacks and ARTEX: what AI actually did
- Armadin and AI attack swarms
- AI agent security platforms compared
- AI agents and the Papercut breach
- Chinese hackers scale attacks with DeepSeek
- Sources: BleepingComputer on Times Car, BleepingComputer on Keio, BleepingComputer on Nikkei, BleepingComputer on Advantest, Hackread on Times Car, Beinsure on Monogatari and Daiwa, Jiji Press via Nippon.com
Figures are as reported on October 9, 2026. Investigations are ongoing and numbers may change.
