Security · October 11, 2026
JPCERT/CC warns of rising unauthorized access incidents and data breaches
The Japan Computer Emergency Response Team Coordination Center, known as JPCERT/CC, issued a statement on October 8 regarding a surge in unauthorized access incidents affecting companies and organizations. The advisory highlights a specific increase in attacks that have led to the leakage of information, including personal data, distinct from routine ransomware cases. The organization noted that while reports of such incidents have become prominent since late August, the specific causes are not yet fully confirmed across all cases. Media reports have recently suggested a commonality in these incidents, attributing them to the misuse of artificial intelligence, but JPCERT/CC clarified that no single attack method has been confirmed for every case. The center emphasized that technical information sharing remains limited and fragmented, yet the potential for expanded damage necessitates immediate caution. The advisory is based on information received by JPCERT/CC and does not imply that all incidents share the same technical characteristics.
The organization outlined three distinct attack scenarios observed in recent reports. The first scenario involves scanning for various known software vulnerabilities to attempt exploitation. Attackers are reportedly probing for weaknesses in different systems and exploiting misconfigurations, such as stealing environment or backup files, rather than relying on a single common vulnerability. The second scenario involves unauthorized operations through application programming interfaces. Reports indicate that attackers send invalid requests to management APIs, leading to unauthorized data modification. Specific techniques include analyzing public mobile applications to identify API endpoints and keys, attacking internal APIs that are not accessible through standard user interfaces, and using API keys stolen from other compromised systems. These internal attacks may involve changing user permissions, creating fraudulent accounts, or using NoSQL injection to extract account information.
The third scenario involves the exploitation of a SQL injection vulnerability in the Metabase product, identified as CVE-2026-72898. This vulnerability is also exploited through invalid requests to APIs. JPCERT/CC had previously issued a warning about this specific vulnerability on August 14, 2026. For the second and third scenarios, the center has published information on suspicious access sources, including IP addresses and user agents, which may be updated periodically. The organization recommends that organizations consult its website for the latest details on these specific threats.
To mitigate these risks, JPCERT/CC provided a comprehensive list of recommended countermeasures. For API security, organizations should implement rate limiting to prevent rapid or bulk requests, especially for high-risk functions like login and password resets. Access controls must be enforced on all API endpoints, including non-public ones, to ensure only authorized users and methods are accepted. API tokens should be granted the minimum necessary permissions and have appropriate expiration dates to avoid long-term validity. Unused or suspected leaked tokens must be invalidated immediately. General security measures include restricting access by region where applicable, applying updates for known vulnerabilities, and reviewing lateral movement defenses after a breach. Organizations should also review their incident detection and response procedures, prepare for potential secondary impacts on customers through multi-factor authentication, and remove unnecessary services from public internet exposure. Data that has exceeded its legal retention period or is no longer needed for its intended purpose should be deleted.