Skip to content
Rush Commerce
Software & Dev3 min read

Japan cyber emergency: your mobile app API keys are public

Japan declared a cybersecurity emergency after 20+ firms were breached. JPCERT says attackers pulled API keys out of mobile apps. Lock down your backend.

Japan's cyber emergency started with API keys hidden in mobile apps. On Friday, Digital Minister Masaaki Taira called a crisis meeting and described a "cybersecurity emergency" after a wave of breaches at Japanese companies. The Financial Times counts at least 20 affected firms. The detail that matters for every business with an app: Japan's national CERT says attackers took apps from the public app stores, pulled out the API endpoints and keys, and then called internal APIs the app screens never show. If your app ships with a key, that key is public.

What actually happened

According to heise online, the attacks started at the end of September. Tokyo Metro disclosed 59,000 leaked customer email addresses on September 27. The restaurant chain Yakiniku King reported that data for 10.8 million customers was copied from its membership system. The Japan Atomic Energy Agency said ID documents for 175 people leaked through a contractor's cloud platform. Cybersecurity minister Toshiharu Furukawa called the situation "extremely critical." Japan's banking supervisor told banks to stop accepting driver's licenses alone as ID for new accounts.

On October 8, JPCERT/CC published an alert that named three attack patterns, as The Hacker News reports:

  • Management API abuse. Attackers reverse-engineer public smartphone apps to find endpoints and keys, then probe internal APIs. They also reuse API keys stolen from other breaches.
  • Scanning for known flaws, including theft of configuration and backup files.
  • Metabase CVE-2026-72898, a CVSS 10.0 SQL injection in the open-source BI tool that has been on CISA's KEV list since August.

Park24, which runs the Times Car car-sharing service, reported that data on about 6.6 million accounts was obtained, with ID images from about 1.6 million accounts. Security firm Macnica counts 119 similar incidents in Japan through October 6, against 84 for all of 2025.

Why mobile app API security matters for your business

Most small-business apps we audit share one weakness: the backend trusts the app. The app hides the admin button, so nobody checks permissions on the admin endpoint. The app has a key baked in, so that key can read everything. Obfuscation does not fix this. Anyone with a decompiler and an afternoon can read your APK.

The fix is not exotic, and JPCERT's list matches ours:

  • No secrets in the client. If the key is in the app bundle or the browser, treat it as published. Move privileged calls behind your own server.
  • Check authorization on every endpoint, not just the ones the UI links to.
  • Rate-limit the expensive paths: login, password reset, SMS, search.
  • Short-lived tokens you can revoke fast.
  • Delete data you no longer need. Ten million rows you deleted cannot leak.

Key takeaways

  • Japan declared a cybersecurity emergency after at least 20 major companies reported breaches since late September
  • JPCERT/CC says attackers extracted API endpoints and keys from public mobile apps, then hit internal APIs directly
  • Exploits of Metabase CVE-2026-72898 and reused stolen API keys were also in the mix
  • Any key shipped inside an app or web bundle is public; the server must enforce every permission
  • Rate limits, revocable tokens and data retention limits shrink the blast radius

Does your app's backend trust the app? We decompile your build the way an attacker would, list every key and endpoint we find, then move the secrets server-side and add real authorization checks. Book an API security review, or see how we build backends that assume the client is hostile.

Sources: heise online, The Hacker News.

  • #cybersecurity
  • #api-security
  • #mobile-apps
  • #jpcert
  • #data-breach
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.