JPCERT/CC, Japan's incident-report center, said on October 8 that attackers behind a run of personal data leaks abused mobile app APIs and known software flaws, The Hacker News reported. Security firm Macnica counted 119 similar public incidents in Japan this year through October 6. Park24 said a third party took data on about 6.6 million Times Car accounts.
JPCERT/CC called its picture limited and fragmentary, and named no attacker or victim. Macnica said 65 of 81 cases made public since July gave too little detail to show the entry point. In some cases, Macnica said, attackers took API keys from a phone app and made calls that looked normal. JPCERT/CC also named CVE-2026-72898, a flaw in Metabase, a tool companies connect to their databases. An attacker needs no account, and the flaw can give admin access, from which stored database logins could be stolen. AhaSlides said a third party had access to its Metabase from August 12 to September 7, after the August 6 fix was released. Neither source says which leak used which method.
Macnica said scrambling an app's code does not hide keys built into it. A Metabase flaw could expose the databases it connects to. Do our apps ship secrets? Which internal tools face the internet? How fast do we patch?