Executive Summary
Throughout September 2026, Japan experienced a surge in data breaches affecting major organizations including Park24's Times Car service (6.6 million accounts) and Yakiniku King restaurant chain (10.7 million records). Attackers systematically exploited mobile API vulnerabilities by reverse-engineering smartphone applications to extract API keys and endpoints, then abusing internal APIs with elevated privileges. A critical component involved exploiting CVE-2026-72898, a CVSS 10.0 SQL injection vulnerability in Metabase business intelligence software that allowed unauthenticated access to administrator functions and connected databases.
This incident represents a concerning evolution in API-focused attacks, demonstrating how threat actors are systematically targeting mobile application backends and business intelligence systems across multiple countries. The campaign's scope expanded beyond Japan to 13 other regions including South Korea, France, and Poland, indicating a coordinated effort to exploit common API security gaps and known vulnerabilities at scale.
Why This Matters Now
API abuse attacks are escalating globally as organizations rapidly deploy mobile applications and cloud services without implementing proper API security controls, creating widespread exposure of sensitive customer data across critical infrastructure and business systems.
Attack Path Analysis
Attackers analyzed mobile app binaries to extract API keys and endpoints, then exploited CVE-2026-72898 in Metabase and abused poorly secured APIs to escalate privileges and create unauthorized accounts. They moved laterally through connected systems using stolen credentials and maintained command and control through legitimate API calls that appeared as normal traffic. Massive data exfiltration occurred through API abuse and direct database access, resulting in over 10 million records stolen from Japanese organizations including Times Car and Yakiniku King systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers reverse-engineered publicly released smartphone apps to extract API endpoints and authentication keys, then exploited CVE-2026-72898 (SQL injection) in internet-facing Metabase instances
Related CVEs
CVE-2026-72898
CVSS 10An SQL injection vulnerability in Metabase allows unauthenticated attackers to execute arbitrary SQL queries and gain administrator access to the application database.
Affected Products:
Metabase Metabase – < 0.58.31, < 0.59.28, < 0.60.24, < 0.61.18, < 0.62.16, < 0.63.13
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: JavaScript
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Account Discovery: Cloud Account
Valid Accounts: Cloud Accounts
Data from Information Repositories: Sharepoint
Exfiltration Over C2 Channel
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Bespoke and Custom Software
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Multifactor Authentication
Control ID: AA.M.2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure through mobile API abuse and Metabase vulnerabilities affecting business intelligence systems, requiring immediate zero trust segmentation and egress security controls.
Financial Services
High-risk sector for API abuse targeting customer data through mobile apps and BI tools, necessitating enhanced encrypted traffic protection and compliance controls.
Retail Industry
Vulnerable to mobile API exploitation affecting customer accounts and payment systems, requiring strengthened access controls and anomaly detection for consumer-facing applications.
Hospitality
Exposed through booking systems and member services targeted by API abuse, demanding improved authentication controls and data exfiltration prevention for customer personal information.
Sources
- Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attackshttps://thehackernews.com/2026/10/japan-sees-sharp-rise-in-web-data-leaks.htmlVerified
- JPCERT/CC Alert on Web Data Leak Incidentshttps://www.jpcert.or.jp/at/2026/at260030.htmlVerified
- Metabase Security-Focused Release Announcementhttps://www.metabase.com/blog/security-focused-release-announcement-2026-08-12Verified
- Macnica Security Research Center Web Incident Analysis 2026https://security.macnica.co.jp/blog/2026/10/web-incidents2026.htmlVerified
- Japan Personal Information Protection Commission Alerthttps://www.ppc.go.jp/files/pdf/261007_alert_dataleakage.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this API-based attack through network segmentation and egress controls, likely reducing the blast radius from over 10 million compromised records across multiple Japanese organizations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility and monitoring would likely have detected the anomalous API access patterns and SQL injection attempts against Metabase instances, potentially constraining the attackers' ability to establish persistent access through these vectors.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation policies would likely have constrained the privilege escalation scope by limiting database access permissions and restricting unauthorized account creation capabilities within segmented network boundaries.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained lateral movement between the compromised Metabase system and connected databases, reducing the attackers' ability to pivot across business intelligence and employee management platforms.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility controls would likely have detected the anomalous API call patterns and token usage behaviors, potentially constraining the attackers' ability to maintain persistent command and control channels through stolen authentication tokens.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained the massive data exfiltration by detecting and blocking the abnormal data transfer volumes and unauthorized database export activities across multiple organizational boundaries.
While some sensitive data exposure would likely still have occurred, the overall impact scope would probably have been constrained to a smaller subset of the 10+ million affected records across Times Car and Yakiniku King systems.
Impact at a Glance
Affected Business Functions
- Customer Data Management Systems
- Mobile Application Services
- Business Intelligence Analytics
- Member Portal Services
Estimated downtime: 7 days
Estimated loss: N/A
Personal data from over 17 million records across multiple Japanese organizations, including 6.6 million Times Car accounts with identity documents such as driver's license images, and 10.7 million Yakiniku King restaurant member records. Data exposed through compromised mobile APIs and business intelligence systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between business systems and databases even when API credentials are compromised
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts through API abuse and bulk data transfers to external destinations
- • Enable Multicloud Visibility & Control to identify anomalous API interactions, repeated malformed requests, and suspicious automation patterns that indicate credential abuse
- • Utilize Inline IPS (Suricata) to detect and block known exploit patterns including CVE-2026-72898 SQL injection attempts before they reach vulnerable applications
- • Establish Cloud Native Security Fabric (CNSF) with real-time inspection and distributed policy enforcement to autonomously detect and respond to API abuse and privilege escalation attempts



