Between September 25 and October 3, 2026, Japanese companies disclosed ten data breaches and misuse incidents, from parcel delivery and fashion e-commerce to a life insurer's HR system and a convenience store app. The largest, at car-sharing service Times Car, exposed data tied to about 6.6 million accounts, including about 1.6 million identity document images such as driver's licenses. Stolen order data is already being used in convincing "refund" scams, and the causes hold lessons for any company that keeps customer or employee data in Japan.

Key points

  • Times Car: about 6.6 million accounts and about 1.6 million ID document images, including people who had left the service. License images were kept for seven years after members left.
  • Yamato Transport, Sagawa Express, ABAHOUSE, Moonstar, Dai-ichi Life, Seicomart, Lawson, TOPPAN and Benefit One also disclosed incidents. As of October 3, none reported confirmed credit card number leaks.
  • ABAHOUSE found its breach after customers reported "refund" emails that matched their real orders. Free email senders, moves to LINE chat and deadlines are the warning signs.
  • Several causes were operational: manual file sending without a second check, a known bug left unfixed, and old data on former members and employees that nobody deleted.

Why this matters if you operate in Japan

Your staff and customers in Japan are likely to appear in at least one of these datasets. The two parcel carriers hold data on both senders and recipients, and Sagawa's exposure covers about 100 days of shipments. Times Car's corporate accounts leaked employees' department names, which makes phishing aimed at your staff look more credible. A configuration flaw at Benefit One displayed other companies' employee data, covering 13,460 people at 2,322 companies and organizations, and TOPPAN, working as a contractor, sent an insurer's policyholder data to the wrong company. Both are third-party risks that sit outside your own systems.

The common thread is retention. Times Car kept license images of people who had left, and Dai-ichi Life still held data on office staff who left as far back as 1967. Japan's Act on the Protection of Personal Information (APPI) asks companies to delete personal data without delay once it is no longer needed, and requires breach reports to the regulator and notices to the people affected. The more you keep, the larger the breach and the response.

This analysis combines two IT Mikata reports and is based on company disclosures and official sources as of October 3, 2026.