The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Throughout September 2026, Japan experienced a surge in data breaches affecting major organizations including Park24's Times Car service (6.6 million accounts) and Yakiniku King restaurant chain (10.7 million records). Attackers systematically exploited mobile API vulnerabilities by reverse-engineering smartphone applications to extract API keys and endpoints, then abusing internal APIs with elevated privileges. A critical component involved exploiting CVE-2026-72898, a CVSS 10.0 SQL injection vulnerability in Metabase business intelligence software that allowed unauthenticated access to administrator functions and connected databases.

This incident represents a concerning evolution in API-focused attacks, demonstrating how threat actors are systematically targeting mobile application backends and business intelligence systems across multiple countries. The campaign's scope expanded beyond Japan to 13 other regions including South Korea, France, and Poland, indicating a coordinated effort to exploit common API security gaps and known vulnerabilities at scale.

Why This Matters Now

API abuse attacks are escalating globally as organizations rapidly deploy mobile applications and cloud services without implementing proper API security controls, creating widespread exposure of sensitive customer data across critical infrastructure and business systems.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers reverse-engineered smartphone applications to extract API keys and endpoints, then abused internal APIs with excessive privileges to access unauthorized data and functions.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained this API-based attack through network segmentation and egress controls, likely reducing the blast radius from over 10 million compromised records across multiple Japanese organizations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility and monitoring would likely have detected the anomalous API access patterns and SQL injection attempts against Metabase instances, potentially constraining the attackers' ability to establish persistent access through these vectors.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation policies would likely have constrained the privilege escalation scope by limiting database access permissions and restricting unauthorized account creation capabilities within segmented network boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained lateral movement between the compromised Metabase system and connected databases, reducing the attackers' ability to pivot across business intelligence and employee management platforms.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Enhanced visibility controls would likely have detected the anomalous API call patterns and token usage behaviors, potentially constraining the attackers' ability to maintain persistent command and control channels through stolen authentication tokens.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have constrained the massive data exfiltration by detecting and blocking the abnormal data transfer volumes and unauthorized database export activities across multiple organizational boundaries.

Impact (Mitigations)

While some sensitive data exposure would likely still have occurred, the overall impact scope would probably have been constrained to a smaller subset of the 10+ million affected records across Times Car and Yakiniku King systems.

Impact at a Glance

Affected Business Functions

  • Customer Data Management Systems
  • Mobile Application Services
  • Business Intelligence Analytics
  • Member Portal Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Personal data from over 17 million records across multiple Japanese organizations, including 6.6 million Times Car accounts with identity documents such as driver's license images, and 10.7 million Yakiniku King restaurant member records. Data exposed through compromised mobile APIs and business intelligence systems.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between business systems and databases even when API credentials are compromised
  • • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts through API abuse and bulk data transfers to external destinations
  • • Enable Multicloud Visibility & Control to identify anomalous API interactions, repeated malformed requests, and suspicious automation patterns that indicate credential abuse
  • • Utilize Inline IPS (Suricata) to detect and block known exploit patterns including CVE-2026-72898 SQL injection attempts before they reach vulnerable applications
  • • Establish Cloud Native Security Fabric (CNSF) with real-time inspection and distributed policy enforcement to autonomously detect and respond to API abuse and privilege escalation attempts

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image