explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR: the incidents in one table
  • What is confirmed, and what is only claimed
  • Times Car: the largest identity-document exposure
  • Gyazo: a screenshot tool with a 23.62 million record leak
  • Keio and Tokyo Metro: ransomware and a second incident
  • The early October disclosures
  • Context: how we got here
  • Is AI behind the wave?
  • Why it matters
  • How to protect yourself
  • Honest limitations
  • What people are asking
  • Related reading
← Back to blog

explainx / blog

Japan Cyberattacks September 2026: Times Car, Gyazo, Keio and Monogatari Explained

Cybersecurity, Data Breach, Japan, Ransomware, News

Part of AI Security

A wave of Japan cyberattacks in September 2026 hit Times Car, Gyazo, Keio and more. What is confirmed, what is claimed, and how to protect yourself.

Oct 9, 2026·12 min read·Yash Thakker
add explainx.ai
go deep
Japan Cyberattacks September 2026: Times Car, Gyazo, Keio and Monogatari Explained

Japanese companies disclosed a long list of cyberattacks and data breaches between September 1 and the first week of October 2026. The biggest exposed the accounts of millions of people. Bloomberg's headline, as summarized by Techmeme, says the slew of attacks exposed the data of millions and prompted calls for security checks, "as AI lowers hacking barriers." Bloomberg is paywalled, so this post rebuilds the picture from company disclosures and from outlets we could read: BleepingComputer, Jiji Press (via Nippon.com), Hackread and Beinsure.

One note on scope. Some of these incidents began in July or August, and several were announced in October. The "September wave" is a media label. We use it for incidents that surfaced from September 1 to October 7, 2026.

TL;DR: the incidents in one table

table · 4 cols
CompanyWhat was reportedType of attackWho says so
Times Car (Times Mobility, Park24)About 6.6 million current and former accounts; about 1.6 million with ID documentsUnauthorized access; entry point not disclosedTimes Car updates, via BleepingComputer and Hackread
Gyazo (Helpfeel)About 23.62 million user records; metadata on about 490 million imagesServer flaw led to code executionHelpfeel notice, via Tech Insider and others
Keio CorporationBusiness systems down, mostly hotelsRansomwareKeio, via BleepingComputer
Tokyo Metro59,000 member email addressesNot statedBleepingComputer
Monogatari (Yakiniku King)10,788,963 member recordsUnauthorized access to app member systemMonogatari, via Japanese press and Qatar Tribune
Daiwa SecuritiesAbout 110,000 customers at a contractorUnauthorized access at Scala CommunicationsDaiwa, via Beinsure
GMO Research & AI948,498 members; 2.86 million yen in points takenUnauthorized access to a survey siteGMO, via Jiji Press
Mr Max HoldingsUp to 1,735,154 membersUnauthorized access to app and online store serversMr Max, via Jiji Press and Japanese press
Nikkei1,646 people's names and emails; about 9,000 phishing emailsHijacked employee accountsNikkei, via BleepingComputer
AdvantestPersonal data stolen in a February attackRansomwareAdvantest notice, via BleepingComputer
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

What is confirmed, and what is only claimed

Most of the facts above are company statements. In this post:

  • Confirmed means the company said it in its own notice, and a news outlet we read reported that notice.
  • Reported means a news outlet says it, and we could not read the company notice.
  • Claimed means someone else says it, such as a hacker group or an analyst.

We found no hacker-group claim for most of these attacks. BleepingComputer states that no ransomware group had claimed the Keio attack, and that it found no public claim for Advantest. No source we read attributes the September incidents to a named group or to any state.

Times Car: the largest identity-document exposure

A badge on a lanyard, standing for the stolen driver's license and ID records in the Times Car data breachA badge on a lanyard, standing for the stolen driver's license and ID records in the Times Car data breach

Times Car is a car-sharing service run by Times Mobility, part of the Park24 Group. BleepingComputer reports that the company announced the incident on September 25, saying a third party had accessed its systems at the beginning of the month, and that it blocked the access on September 26.

On September 28, the company confirmed data theft. It said the intrusion affects about 6.6 million current and former Times Car members, plus members of the Times Business Service corporate program. According to BleepingComputer, the exposed data includes:

  • full name, and department name for corporate members;
  • physical address, date of birth, telephone number and email address;
  • driver's license information and identity-verification document information;
  • account password and linked service IDs.

Times Car said passwords were stored in "a form that cannot be restored," and that credit card information was not affected. It said it had no evidence that the data was distributed online.

Hackread adds details from Park24's updates. Times Mobility detected the unauthorized access at 9:07 a.m. on September 25. A September 29 update confirmed that identity-verification information on about 1.6 million accounts was accessed. That includes driver's license images, utility bills used to verify addresses, student ID cards and family verification documents. The company reported the incident to Japan's Personal Information Protection Commission and to police. The exact entry point is still under investigation.

Hackread also reports a side effect. The credit-information agencies CIC and JICC saw heavy traffic from people checking their credit files, and CIC reported trouble issuing reception numbers on September 29. Neither agency confirmed that the Times Car breach caused the surge.

Gyazo: a screenshot tool with a 23.62 million record leak

Illustration of a data breach leak: beads spilling from a cracked vessel, like the Gyazo records exposed in Japan's cyberattacksIllustration of a data breach leak: beads spilling from a cracked vessel, like the Gyazo records exposed in Japan's cyberattacks

Helpfeel, a Kyoto company, runs the image-sharing service Gyazo. Tech Insider reports, citing Helpfeel's notice, that an attacker broke in on September 11, and that the company confirmed it on September 16. The notice says about 23.62 million user records were disclosed without authorization. Metadata on about 490 million images was also exposed.

According to Tech Insider, the exposed items include emails, password hashes, IP addresses, text extracted from images, and in some cases location data. It also says Helpfeel described an upload-server flaw that allowed the intruder to upload malicious files and run commands. Tech Insider names The Hacker News, TechRadar Pro and Security Affairs as outlets that reported the same figures. We could read only Tech Insider, so treat the technical detail as reported, not independently confirmed.

Keio and Tokyo Metro: ransomware and a second incident

Keio Corporation is a major private railway operator. BleepingComputer reports that Keio confirmed a ransomware attack on its group servers in the early hours of September 26, 2026. The attack mainly hit the hospitality business, which includes 25 hotels, and disrupted payment systems. Train operations were not affected.

Keio gave this statement, as quoted by BleepingComputer: "We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts." Keio had not said whether customer or partner data was accessed, and no ransomware group had claimed the attack.

BleepingComputer also reports that Tokyo Metro disclosed a separate incident over the same weekend. Attackers accessed 59,000 member email addresses. BleepingComputer said it was unclear whether the two incidents were linked. We found no source that links them.

The early October disclosures

Several large disclosures arrived in the first week of October.

Monogatari (Yakiniku King). Japanese press reports that Monogatari Corporation announced on October 5 that unauthorized access hit the member-management system of its official app. The company put the number of leaked member records at 10,788,963, out of 10,808,784 registered app users. Leaked fields: member IDs, names, email addresses and phone numbers. The company said login passwords, birthdates, genders, postal codes and store-usage history were not leaked, and that it does not store card data. Beinsure reports that the company detected the breach on a Friday and had no evidence of misuse.

Daiwa Securities. Beinsure reports that the breach involved a server run by an outside contractor, Scala Communications, which provides an online customer inquiry service. Unauthorized access occurred between Friday evening and Saturday morning. About 110,000 brokerage customers may be affected (about 220,000 records when inquiries without personal data are counted). Potentially exposed: names, email addresses and account numbers. Daiwa said the data could not be used to place trades.

GMO Research & AI and Mr Max. Jiji Press, published on Nippon.com, says GMO Research & AI reported unauthorized access to its "infoQ" survey site that compromised names and phone numbers of 948,498 members. Reward points worth 2.86 million yen were fraudulently exchanged for Amazon gift codes, and GMO plans to compensate affected members in full. Jiji says discount retailer Mr Max Holdings also reported an attack that exposed phone numbers, email addresses and other data of up to 1,735,154 members of its apps and online stores. Japanese press adds that Mr Max said a third party abused a software function used to configure the service.

Nikkei. Per BleepingComputer, Nikkei said an employee's Google Workspace account was accessed in late July, which may have exposed names and email addresses of 1,646 people. In September, attackers accessed another employee's Microsoft 365 account. On September 30 they used it to send about 9,000 phishing emails to staff and interviewees. Nikkei had not attributed the attacks.

Advantest. BleepingComputer reports that the chip-test equipment maker confirmed, in a notice dated October 6, that data was stolen in a ransomware attack that began February 15. The data includes SSNs, national ID numbers, passport numbers and medical and financial information. The company has not said how many people are affected.

Context: how we got here

These incidents sit on top of a bad year. Threat-intelligence aggregator reports say Japan recorded 123 ransomware cases in the first half of 2026, the most since records began in 2020, with small and mid-size firms making up most of them. We could not verify that count against a primary source, so treat it as a secondary figure.

Earlier in the year, BleepingComputer reported on August 19 that Sakura Internet, a cloud and data-center provider selected for Japan's Government Cloud program, said up to 1,360,563 member accounts might have been affected after hackers accessed a sales-management system. Sakura told BleepingComputer the incident was not ransomware and no ransom was demanded.

Is AI behind the wave?

The title of Bloomberg's report ties the wave to AI lowering hacking barriers. Jiji Press is more careful: it says the spread of AI "may be contributing" to the spike.

Here is what the sources we read do and do not show. They show that many companies were breached in a short period. They do not show that AI tools were used in any of these specific attacks. Gyazo's described path (an upload flaw, then a database) is an old technique. Nikkei's case is phishing and account takeover. Keio is ransomware. Times Car's entry point is undisclosed.

The AI claim is a plausible, widely discussed theory. It is not a finding. For a case where investigators did point to AI tools, see our coverage of the South Korea bank hacks and ARTEX, and for the wider pattern see Armadin's AI attack swarms.

Why it matters

Three things stand out.

  1. Identity documents are the worst data type to lose. A password can be reset. A driver's license image cannot. With about 1.6 million Times Car accounts affected, fraudsters can try identity theft and account opening for years.
  2. Third parties matter. The Daiwa breach happened at a contractor. Supply-chain exposure means customers cannot tell from the brand name who holds their data.
  3. Loyalty and reward systems are targets. GMO's members lost points that were turned into gift codes. Points are cash-like and often poorly protected.

Our earlier coverage of AI agents in the Papercut breach and of an OpenAI agent in the Australia breach shows the same direction of travel: faster attackers, slower disclosure.

How to protect yourself

A window half covered by a curtain with a padlock, showing basic personal data protection after a Japanese breachA window half covered by a curtain with a padlock, showing basic personal data protection after a Japanese breach

If you are a customer of an affected company:

  • Change passwords for the affected service and for every site where you reused it. Use a password manager.
  • Turn on multi-factor authentication, preferably with an authenticator app or passkey, not SMS.
  • Treat unexpected messages as phishing. Times Car, for example, says it will not ask for passwords or card numbers by email, SMS or phone. Go to the company's site directly instead of using a link.
  • Watch for follow-on fraud. If your ID documents were exposed, consider a credit report check, and watch for loans or cards you did not request.
  • Check points and balances on reward accounts such as survey and loyalty sites.

If you run a company:

  • Patch internet-facing upload and admin functions, and isolate them from your databases.
  • Enforce MFA on email and cloud accounts. The Nikkei case shows one hijacked mailbox can send thousands of phishing emails.
  • Store only the identity documents you must keep, and delete the rest.
  • Review your vendors' access. Ask contractors how they secure customer-inquiry and support systems.
  • If you deploy AI agents with access to email, files or customer systems, put guardrails around what they can do. AgentBeam is the agent security platform from the explainx.ai team that stops AI agents before they take dangerous actions. For a comparison of tools in this space, see our guide to AI agent security platforms.

Honest limitations

We could not read the Bloomberg article, the Japan Times piece of October 7, or the companies' original Japanese notices in full. Figures come from the outlets named in each section. Several numbers are the companies' own early counts and may change as investigations continue. We found no advisory from NISC, JPCERT/CC or the National Police Agency about this specific wave, so we make no claim about one. If you are affected, follow the company's notice first.

What people are asking

The questions above cover the main points. The short version: the attacks are separate incidents, most are unattributed, ransomware is confirmed only at Keio and Advantest, and the AI link is a theory.

Related reading

  • South Korea AI bank hacks and ARTEX: what AI actually did
  • Armadin and AI attack swarms
  • AI agent security platforms compared
  • AI agents and the Papercut breach
  • Chinese hackers scale attacks with DeepSeek
  • Sources: BleepingComputer on Times Car, BleepingComputer on Keio, BleepingComputer on Nikkei, BleepingComputer on Advantest, Hackread on Times Car, Beinsure on Monogatari and Daiwa, Jiji Press via Nippon.com

Figures are as reported on October 9, 2026. Investigations are ongoing and numbers may change.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Oct 10, 2026

FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Probe

Brian Krebs reports that FBI agents arrested the co-founder of a Canadian ransomware negotiation firm in Pennsylvania on October 8, 2026, as part of the ShinyHunters investigation. Here is what the reporting and court records show, what remains sealed, and how the case follows the group's hack of the FBI's jobs portal.

Aug 27, 2026

Hackers Talked Cursor's AI Agent Into Breaching 7 Companies

Reuters reported on August 27, 2026, that a Russian-speaking group called Aur0ra used Cursor's built-in AI coding agent to breach seven companies — by convincing the agent, nearly every time it initially refused, that the attack was an authorized security test. The model reportedly running the agent was Anthropic's Claude Sonnet 4.5. Update (Aug 31, 2026): CloudSEK and Gambit Security confirmed the same operator deployed actual Aurora ransomware — a Zig-coded Windows/Linux/ESXi encryptor — after using Cursor's agent for hands-on exploitation against 10 of 20+ victim organizations, marking one of the first documented cases of an agentic coding tool used as attack infrastructure rather than just text generation.

Oct 9, 2026

AI Labs Wargame the "Day After" a Catastrophe: What Axios Reported vs What Is Verified

An October 9, 2026 Axios scoop says executives at OpenAI, Anthropic and other labs are gaming out the aftermath of a catastrophic AI event, most likely a cyberattack. OpenAI confirmed it runs preparedness drills; Anthropic declined to comment. Here is what is claimed, what is verified, and why it matters.