Ransomware Hits University Research Lab: 43 Hospital Patients Potentially Affected

On June 10, Kyushu University announced that a device managed by one of its on-campus research laboratories had been infected with ransomware, and that the personal information of 43 patients from the university hospital may have been compromised.

According to the university, the device managed by the research laboratory was subjected to unauthorized access and is believed to have been infected with ransomware. As a result, the university stated that it cannot rule out the possibility that the names of 43 patients from Kyushu University Hospital, along with surgical video data stored on the device, may have been leaked to external parties.

Japan’s Top 10 Cybersecurity Threats: Ransomware Remains No. 1, AI Risks Rise

According to the latest “Top 10 Information Security Threats (for Organizations) released by Japan’s Innovation Platform Agency (IPA), ransomware attacks—which encrypt system data and demand payment for its recovery—ranked as the number one threat for another consecutive year. In addition, the misuse of artificial intelligence (AI) has emerged as a rapidly growing new cybersecurity risk.

Japan’s Top 10 Information Security Threats for Organizations are as follows:

  1. Damage caused by ransomware attacks
  2. Attacks targeting supply chains and outsourced service providers
  3. Cybersecurity risks associated with the use of AI
  4. Attacks exploiting system vulnerabilities
  5. Targeted attacks aimed at stealing confidential information
  6. Cyberattacks driven by geopolitical risks
  7. Information leakage and other incidents caused by insider threats
  8. Attacks targeting remote work environments and related systems
  9. Distributed Denial-of-Service (DDoS) attacks
  10. Threats arising from the release of software patches or the end of product support

Cyber Incident at Shin-Nihon Certification Association May Have Exposed Customer Data

On May 11, 2026, the General Incorporated Foundation Shin-Nihon Certification Association announced that, as a result of a cyberattack against the organization, personal data—including customer information belonging to major non-life insurance companies for which it had been providing outsourced services—may have been leaked to external parties.

On the same day, the following insurance companies disclosed details of the incident:

  • Mitsui Sumitomo Insurance Company, Limited
  • Tokio Marine & Nichido Fire Insurance Co., Ltd.
  • Sompo Japan Insurance Inc..

Nippon Yusen Discloses Unauthorized System Access

Nippon Yusen Kabushiki Kaisha (NYK Line) announced on April 9, 2026, that its vessel fuel procurement system had been accessed illegally by a third party.

According to the company, the unauthorized access occurred on March 24, 2026, and there is a possibility that data was exfiltrated. The information potentially affected includes the personal data of employees (including former employees) and employees of business partners, such as names, company names, phone numbers, and email addresses.