Japan is logging cyber incidents at a pace that has its own security establishment reaching for blunt language. A string of breach disclosures in late September and early October 2026 has hit some of the country’s best-known names, including Daiwa Securities, SoftBank, and convenience store chain Lawson, alongside retailers, a restaurant chain, a research firm, and a public university. Trend Micro says it has counted 600 unauthorized-access incidents disclosed by Japanese companies and local governments between January and the end of September 2026. Security researchers and officials are now arguing in public over how much of this is driven by attackers using AI tools, and how much simply reflects weak patching habits finally catching up with large organizations.

A Wave of Breaches Hits Japan’s Biggest Names

The pattern became impossible to ignore once several unrelated companies disclosed incidents within days of each other. Daiwa Securities Group Inc. said unauthorized access to a contractor-operated server may have affected data tied to roughly 110,000 customers, though one report put the potential exposure as high as 220,000 records, a figure the company has not confirmed. Monogatari Corp., which runs the Yakiniku King restaurant chain, reported that more than 10 million pieces of customer information leaked after attackers got into its reservation and rewards app, with one account putting the number closer to 10.79 million. Separately, Times Car disclosed exposure of personal data tied to roughly 6.6 million users, a breach covered in detail here after parent company Keio confirmed ransomware involvement.

None of these companies operate in the same sector, which is part of why the cluster of disclosures has drawn attention from outlets like GhanaWeb and Briefs Finance as a distinct trend rather than a single incident. Securities firms, car-sharing platforms, restaurant chains, and research companies do not typically share infrastructure or vendors, so the common thread officials keep returning to is the growing availability of AI tools that can automate reconnaissance, phishing content, and exploit development.

The Numbers: Who Was Hit and How Badly

Laid out together, the scale of the disclosures becomes clearer. Some figures are confirmed directly by the companies involved, while others come from secondary reports that have not been independently verified by the organizations themselves.

Confirmed Figures vs. Disputed Estimates

The gap between confirmed and unconfirmed numbers matters here. Daiwa Securities’ own statement cites approximately 110,000 affected customers, while a separate report doubled that figure to 220,000. Monogatari Corp. confirmed “more than 10 million” records, while another outlet quantified it at 10.79 million. Readers should treat the higher figures as estimates pending company confirmation, not as settled facts.

OrganizationNature of incidentPeople/records affectedConfirmation status
Times CarRansomware/data exposure (parent: Keio)~6.6 million usersConfirmed
Monogatari Corp. (Yakiniku King)Unauthorized access to reservation/rewards app10 million+ (one report: 10.79 million)Confirmed (precise figure disputed)
Mr Max Holdings Ltd.Unauthorized access to app/online storeUp to 1,735,154 membersConfirmed
GMO Research & AI Inc.Unauthorized access to infoQ websiteUp to 948,498 registered membersConfirmed
Osaka Metropolitan UniversityCyberattack causing system failureAt least 130,000 students/staffConfirmed
Daiwa Securities GroupContractor-server breach~110,000 (one report: up to 220,000)Confirmed (higher figure unconfirmed)
IDC Frontier (SoftBank subsidiary)Ransomware attack on IDCF Cloud platformOrganizational outage, not a user countConfirmed

Daiwa Securities: A Contractor’s Server, Up to 220,000 Customers

Of all the incidents in this cluster, the Daiwa Securities disclosure carries the most weight for financial markets, since it involves a listed brokerage handling client assets. The company said the breach ran through a server operated by an outside contractor rather than its own core systems, a detail that mirrors a recurring theme in Japanese breach disclosures this year: attackers increasingly target the weaker links in a company’s vendor chain instead of hardened internal networks. Daiwa has confirmed roughly 110,000 customers may be affected. The 220,000 figure reported elsewhere has not been confirmed by the firm, and readers should treat it as a disputed upper estimate rather than a company-verified number.

Contractor and vendor breaches are not new to Japanese finance, but the timing here, landing in the same month as half a dozen other unrelated disclosures, is what has turned this into a talking point beyond the usual security trade press.

Monogatari Corp.: Yakiniku King’s Massive Record Breach

Monogatari Corp.’s disclosure stands out simply on volume. The company said unauthorized access to its reservation and loyalty-rewards application led to the leakage of more than 10 million pieces of customer information, making it one of the largest single breaches reported by a Japanese restaurant operator. A separate report pegged the number at approximately 10.79 million records, a figure Monogatari has not independently confirmed in the same terms.

Restaurant chains collect less sensitive data than banks, typically names, phone numbers, and reservation history rather than financial account details. But the sheer size of the Yakiniku King customer base means the breach still represents a meaningful exposure of personal information tied to tens of millions of individual restaurant visits and loyalty-point transactions.

Retail, Research and Education: The Wider Blast Radius

GMO Research & AI Inc. reported unauthorized access affecting up to 948,498 registered members of its infoQ questionnaire platform, a site used to run market research surveys. Mr Max Holdings Ltd., a retail chain, said personal information belonging to as many as 1,735,154 app and online-store members may have been affected. And in the public sector, Osaka Metropolitan University confirmed that data concerning at least 130,000 students and faculty may have leaked after a cyberattack caused a system failure.

Three sectors, three very different risk profiles. A market-research platform’s exposure is mostly survey-response and contact data. A retailer’s loyalty program leak touches purchase history and payment-adjacent details. A university breach risks academic records and staff personal data. What ties them together is scale: each incident crossed into seven-figure or near-seven-figure record counts within weeks of each other, a clustering that would be statistically unusual in a typical year, based on prior disclosure patterns tracked on this site through the first half of 2026.

IDC Frontier Ransomware Knocks Out a SoftBank Cloud Unit

While most of this cluster involves data exposure, one incident hit infrastructure directly. IDC Frontier, a subsidiary of SoftBank, confirmed a ransomware attack disrupted its IDCF Cloud platform on October 7, 2026. That date places it squarely inside the same two-week window as the Daiwa, Monogatari, and university disclosures, reinforcing the sense among Japanese security researchers that this is a concentrated wave rather than coincidence. Shattered.io previously reported on the scope of that IDCF Cloud disruption, which affected hundreds of organizations relying on the platform for hosting.

A ransomware hit on a cloud infrastructure provider carries different stakes than a customer-data leak. Instead of one company’s records being exposed, every downstream business running on that infrastructure inherits the outage, which is why IDC Frontier’s incident drew attention beyond SoftBank’s own customer base.

Is AI Actually Driving the Surge? Experts Disagree

The AI framing of this story did not come from marketing departments. It came from security practitioners trying to explain why so many unrelated companies got hit in such a short window, and the answer they’ve landed on is contested even among people who study Japanese cybersecurity for a living.

The Automation Argument

Nobuo Miwa, president of S&J Corp., has been blunt about the scale of what Japan is facing. “My view is that Japan is essentially being subjected to carpet bombing,” Miwa said, describing the breadth of attacks hitting companies including Daiwa Securities, SoftBank, and Lawson, according to The Economic Times. Miwa has also argued that the tooling behind these attacks has gotten dramatically faster to produce. “Attack programs can be created in the blink of an eye with AI,” he said in comments reported earlier this year.

The Patching Counterargument

Hiroki Takakura, a professor and director at the National Institute of Informatics’ Strategic Cyber Resilience Research and Development Center, takes a more measured view. “I believe it’s true that CVEs are exploding due to AI-driven vulnerability discovery,” Takakura said, per ASCII.jp. But he stopped short of blaming AI for the specific wave of breaches hitting Japanese firms this month, adding: “I believe AI was used for attack automation, but it didn’t play a major role. In other words, I think the countermeasures were insufficient.”

That distinction matters for how companies should respond. If AI tooling is the root cause, the fix looks like better AI-aware threat detection. If insufficient patching and vendor oversight are the root cause, as Takakura suggests, the fix looks more like basic security hygiene that Japanese enterprises have underfunded for years. Both explanations can be true at once, and the available evidence does not establish that AI caused each individual incident in this cluster.

Trend Micro’s Tally: 600 Incidents Since January

Trend Micro announced on October 6, 2026, that it had recorded 600 unauthorized-access incidents made public by Japanese companies and local governments from the start of 2026 through the end of September. That is a running tally across nine months, not a count specific to the current cluster of disclosures, but it gives the October wave useful context: Japan was already on pace for an elevated incident count well before Daiwa, Monogatari, and the others came forward.

MetricJapanSouth Korea
Headline incident tracker600 unauthorized-access incidents, Jan.–Sept. 2026 (Trend Micro, Oct. 6)4 lenders under regulatory review for AI-linked hacks
Sectors hit in current waveSecurities, telecom/cloud, retail, restaurants, research, higher educationBanking and consumer lending
Largest single disclosure (current wave)10 million+ records (Monogatari Corp./Yakiniku King)Not publicly quantified by regulators
AI’s cited roleDisputed among researchers, automation cited alongside weak patchingSecurity vendor CrowdStrike linked an AI agent (ARTEX) to one hack
Government responseRuling-party AI policy lead calls for automated anomaly detection (Oct. 9)Financial regulator orders bank security checks

The regional comparison is not coincidental. Shattered.io has separately reported on South Korea’s own AI-linked bank hacks, where regulators opened probes into incidents affecting four lenders, and on CrowdStrike’s analysis tying an AI agent called ARTEX to one of those Korean banking breaches. Japan and South Korea are facing parallel pressure, with security vendors and officials in both countries reaching for the same explanation: AI tools are lowering the skill floor needed to run large-scale attacks, even where the direct causal link to any single breach remains unproven.

Historical Context: Japan’s Ransomware Curve Since 2023

This wave did not appear out of nowhere. Japan’s National Police Agency and private security vendors have tracked a steady climb in ransomware and breach disclosures since 2023, and shattered.io reported earlier in 2026 that Japan logged a record 123 ransomware cases in just the first half of the year. Globally, the picture is similar: ransomware groups have increasingly pivoted toward data theft and extortion rather than pure encryption, a shift documented in detail on this site, where data-theft-only incidents surged 275% even as straight ransom payments declined.

Seen against that backdrop, October’s cluster of Japanese disclosures looks less like a sudden AI-powered escalation and more like the visible peak of a trend that has been building for three years. What’s new in 2026 is the vocabulary officials and vendors are using to describe it, not necessarily the underlying attack volume.

Market and Customer Fallout

For a listed brokerage like Daiwa Securities, a breach disclosure invites scrutiny from regulators and customers alike, even when the company moves quickly to contain it. Retail and restaurant brands face a quieter but still real cost: loyalty-program trust erodes when customers learn their reservation history and contact details sat in a database that got breached. Universities face a different kind of fallout, since students and staff cannot simply switch providers the way a retail customer can abandon a loyalty app.

The IDC Frontier ransomware incident adds a layer most of the other breaches in this cluster don’t carry: downstream business disruption. Companies hosting workloads on IDCF Cloud had to manage their own outage response on top of whatever customer communication their own breach, if any, required. That compounding effect, one company’s ransomware attack becoming another company’s infrastructure outage, is a recurring feature of cloud-era incidents and one Japanese enterprises are still adapting their contingency planning around.

Tokyo’s Political Response: Automated Defense as Policy

The political reaction arrived almost as fast as the breach disclosures themselves. Masaaki Taira, who heads AI policy for Japan’s governing party, called for technical measures capable of catching breaches before data actually leaves a network. “We need technical countermeasures that can automatically detect anomalies and block the spread of damage after an IT system is breached but before sensitive information is actually leaked outside,” Taira said, according to The Korea Economic Daily.

That framing puts the policy conversation squarely on detection and containment rather than prevention alone, an acknowledgment that stopping every initial intrusion is no longer treated as realistic by Japanese policymakers. It also echoes guidance from bodies like Japan’s Information-technology Promotion Agency and international frameworks such as the NIST AI Risk Management Framework, both of which emphasize layered monitoring over single-point defenses.

What Comes Next: Five Predictions

  • Expect Japan’s Financial Services Agency and sector regulators to push for mandatory vendor-risk audits following the Daiwa contractor-server breach, mirroring moves already made by South Korea’s financial regulator.
  • Trend Micro’s 600-incident count for Jan.–Sept. 2026 will likely be revised upward once Q4 disclosures, including this cluster, are folded into year-end reporting.
  • More companies will probably attribute breaches to “AI-assisted” attacks in public statements, regardless of whether forensic evidence actually isolates AI tooling as the entry point, simply because the framing has become politically convenient.
  • SoftBank and other large conglomerates will face pressure to ring-fence subsidiary infrastructure, like IDC Frontier’s cloud platform, from shared corporate risk after the ransomware disruption.
  • Expect continued disagreement between vendors (who have a commercial incentive to emphasize AI-driven threats) and independent academic researchers like Takakura, who are more likely to point back to unpatched basics.

Frequently Asked Questions

Were all of these Japanese companies hit by the same attacker?
There is no confirmed evidence linking Daiwa Securities, Monogatari Corp., GMO Research & AI, Mr Max Holdings, Osaka Metropolitan University, and IDC Frontier to a single attacker or campaign. The connection researchers have drawn is thematic, a shared pattern of AI-assisted or AI-era attack techniques, not a confirmed shared threat actor.

How many people were affected in total?
Adding the confirmed figures from Times Car (6.6 million), Monogatari Corp. (10 million-plus), Mr Max Holdings (up to 1.74 million), GMO Research & AI (up to 948,498), Osaka Metropolitan University (130,000-plus) and Daiwa Securities (approximately 110,000) puts the confirmed total well above 18 million individual records, though some people may appear in more than one dataset.

Is there proof AI tools were used in these specific attacks?
No. Reports have linked the wider attack trend to AI lowering the barrier to entry for cybercriminals, and researchers like Hiroki Takakura have said AI contributed to automation in some cases. But the available evidence does not establish that AI tooling caused any one of these individual breaches.

What is Trend Micro’s 600-incident figure actually counting?
It covers unauthorized-access incidents publicly disclosed by Japanese companies and local governments between the start of January and the end of September 2026, as announced by Trend Micro on October 6, 2026. It is a running nine-month tally, not a count isolated to this specific October cluster of breaches.

Did the IDC Frontier ransomware attack affect customer data?
The confirmed detail is that the ransomware attack disrupted IDC Frontier’s IDCF Cloud platform starting October 7, 2026. That is a service-availability incident affecting organizations hosted on the platform, distinct from the customer-data breaches reported by Daiwa Securities and the other companies in this story.

How does this compare to South Korea’s recent bank hacks?
South Korean regulators have opened probes into AI-linked hacks affecting four lenders, and security vendor CrowdStrike has tied an AI agent called ARTEX to one incident. Japan’s wave is broader in sector spread (finance, retail, restaurants, research, education, cloud infrastructure) while South Korea’s cases have concentrated in banking.

What should companies do in response to this trend?
Masaaki Taira, Japan’s ruling-party AI policy lead, has called for automated anomaly detection that can catch a breach after initial access but before data actually leaves the network. Security researchers also point to tighter oversight of third-party contractors and vendors, since the Daiwa Securities breach ran through an outside contractor’s server rather than the firm’s own systems.

Is Japan’s incident count unusual compared to past years?
Japan logged a record 123 ransomware cases in the first half of 2026 alone, continuing a climb that has been building since 2023. The current wave of disclosures sits on top of that existing upward trend rather than representing an isolated spike.