Personal Information Protection Commission: Japan logs over 19,000 personal data breaches in fiscal 2025

Personal Information Protection Commission: Japan logs over 19,000 personal data breaches in fiscal 2025

Japan Sees Near-Record Personal Data Breaches in Fiscal 2025

Japan reported 19,417 personal data breach cases in fiscal 2025, marking the second-highest annual total on record, according to a government report. The figure, just below the previous year’s 21,007 cases, reflects ongoing cybersecurity challenges across both public and private sectors.

The Personal Information Protection Commission (PIPC) revealed that private-sector breaches declined to 17,139 from 19,056, while government agency incidents surged to a record 2,278 up from 1,951 in the prior year. The report, adopted by the cabinet on Tuesday, highlighted enforcement actions, including the PIPC’s first emergency administrative order in May 2024 against a name list broker accused of supplying personal data to fraud groups.

In addition to the order, the commission issued 649 guidance or advisory measures and two formal recommendations. Digital Transformation and Cybersecurity Minister Hisashi Matsumoto noted that many breaches stemmed from human error, such as hospitals and pharmacies sending documents to incorrect recipients or companies misdirecting sensitive items like credit cards.

The findings underscore persistent vulnerabilities in data handling, particularly as government agencies face rising breach incidents. Authorities have pledged to monitor preventive measures and maintain enforcement actions.

Source: https://www.japantimes.co.jp/news/2026/07/08/japan/japan-data-breaches-second-highest/

National Privacy Commission cybersecurity rating report: https://www.rankiteo.com/company/privacygovph

"id": "PRI1783492310",
"linkid": "privacygovph",
"type": "Breach",
"date": "5/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '17,139 breaches (private '
                                              'sector)',
                        'industry': ['Healthcare', 'Pharmaceutical', 'Other'],
                        'location': 'Japan',
                        'type': 'Private Sector'},
                       {'customers_affected': '2,278 breaches (government '
                                              'agencies)',
                        'industry': 'Public Sector',
                        'location': 'Japan',
                        'type': 'Government Agency'}],
 'data_breach': {'number_of_records_exposed': '19,417 cases',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Personal Data'},
 'description': 'Japan reported 19,417 personal data breach cases in fiscal '
                '2025, the second-highest annual total on record. The breaches '
                'affected both public and private sectors, with private-sector '
                'incidents declining slightly while government agency breaches '
                'reached a record high. The Personal Information Protection '
                'Commission (PIPC) took enforcement actions, including an '
                'emergency administrative order against a name list broker '
                'supplying data to fraud groups.',
 'impact': {'data_compromised': 'Personal Data', 'identity_theft_risk': 'High'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Yes (name list broker '
                                                    'case)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Persistent vulnerabilities in data handling, particularly '
                    'human error, contribute to breaches. Government agencies '
                    'face rising breach incidents.',
 'post_incident_analysis': {'corrective_actions': 'Enhanced enforcement, '
                                                  'monitoring of preventive '
                                                  'measures',
                            'root_causes': 'Human error (e.g., misdirected '
                                           'documents, credit cards)'},
 'recommendations': 'Improve preventive measures, enhance enforcement actions, '
                    'and monitor data handling practices.',
 'references': [{'source': 'Personal Information Protection Commission (PIPC) '
                           'Report'},
                {'source': 'Digital Transformation and Cybersecurity Minister '
                           'Statement'}],
 'regulatory_compliance': {'legal_actions': 'Emergency administrative order, '
                                            '649 guidance/advisory measures, 2 '
                                            'formal recommendations',
                           'regulations_violated': ['Personal Information '
                                                    'Protection Laws']},
 'title': 'Near-Record Personal Data Breaches in Japan (Fiscal 2025)',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Human Error'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.