Japan is facing another major personal data leak after BOOKOFF and Daiichikosho, the company behind the BIG ECHO karaoke chain, confirmed on Oct. 9 that databases linked to subsidiaries and outsourced vendors had been illegally accessed by a third party. The number of affected member records was estimated at 6.43 million and 8.72 million respectively, putting the combined total close to 15 million.
The companies said the exposed information included member names, dates of birth, phone numbers and email addresses. Both stressed that the systems involved did not store full credit card details. As of now, neither company has confirmed any case of unlawful third-party use of the leaked data.
Unauthorized access to internal systems has become a central attack route
The report says recent cyberattacks in Japan have largely centered on unauthorized access to internal systems. Attackers obtained employee or system credentials through specific channels, logged in successfully, and extracted large volumes of customer data.
According to Trend Micro, Japanese companies had reported 604 security incidents from January to early October this year. Data from Japan's National Police Agency also showed 123 ransomware attacks in the first half alone, the highest level on record.
The impact has spread beyond retail and entertainment. JR East, convenience store chain Lawson, and online travel agencies Adventure and Skyticket have also reported system intrusions. The article says the cumulative number of affected records across Japan has now exceeded 62 million.
AI tools are seen as lowering the cost of cybercrime
The article says there is no conclusive evidence that artificial intelligence directly drove the recent attacks in Japan. Even so, cybersecurity specialists believe large language model, or LLM, technology can run on ordinary hardware, cutting labor costs and lowering the execution threshold for criminal groups. That makes large-scale attacks easier to carry out.
IBM research cited in the report says nearly one-quarter of malicious attacks worldwide are enabled by AI tools. Attackers use those tools to overcome language and cultural barriers and create highly convincing phishing websites and emails.
Gartner also said only about 30% of large Japanese companies are able to manage system vulnerabilities properly. Many small and mid-sized businesses, according to the report, may not even realize their internal systems have already been accessed illegally.
Japan moves to strengthen active cyber defense
As cyber risk expands, Japan is upgrading its national defenses through legislation and institutional changes. The Japanese parliament has passed the Active Cyber Defense Act and established the National Cybersecurity Office.
Under the framework described in the report, the government is authorized to proactively collect communications information when signs of a potential threat are detected and to take preemptive Access Neutralization measures.
The financial sector is also raising its response level. Delta Wall 2026, a cybersecurity drill organized by Japan's Financial Services Agency, drew participation from 181 financial institutions. Industry representative Akio Yamaguchi said companies should treat cybersecurity defense as a necessary "strategic investment" by updating systems in real time, patching software vulnerabilities, introducing multi-factor authentication, or MFA, and strengthening defenses against phishing attacks.

