News
- Report
[2025 Corporate Security Incident Survey Report] The number of disclosed incidents per year increased by approximately 1.4 times compared to the previous year. Over 70% were concentrated in five industries.
- The service industry saw the highest number of data breaches, more than 10 times higher than the previous year -
Cyber Security Cloud, Inc., Inc. (Headquarters: Shinagawa-ku, Tokyo; Representative Director, President and CEO: Toshihiro Koike; hereinafter referred to as "Cyber Security Cloud"), a global security manufacturer, is releasing the "2025 Corporate Security Incident Survey Report," based on personal information leak cases at companies and organizations announced in Japan between January 1 and December 31, 2025.
[Survey Summary]
- The number of security incidents announced in 2025will be 165, a four-fold increase from the previous year. An incident will occur approximately once every two days.
- 70.1% of security incidents in Japanwere concentrated in five industries, with the most common being the "service industry"
- The most common cause of incidents was "unauthorized access," accounting for more than 60% of the total. Of the 13 industries, only "municipalities and local governments" saw "human error" as the most common cause.
- The total number of personal information leaks for the year was 21,909,319, an increase of approximately 300,000 cases from the previous year. The service industry had the highest number of information leaks, with a sharp increase of more than 10 times compared to the previous year.
1.The number of publicly announced security incidents in 2025 will be 165, a four-fold increase from the previous year. An incident will occur approximately once every two days.
The total number of security incidents announced by companies and organizations in 2025 was 165. This is approximately 1.4 times the total of 121 in 2024. The frequency of incidents has accelerated from "approximately once every three days" in the previous year to "approximately once every two days," indicating that cyber attacks have become a daily management risk for domestic companies.

2.70.1% of security incidents in Japan were concentrated in five industries, with the most common being the "service industry"
Analysis by industry revealed that of the 13 industries, the top five (services, municipalities, manufacturing, education and learning support, wholesale and retail) accounted for 70.1% of the total, revealing that security incidents are concentrated in specific industries.
Of these, the "service industry" had the highest number of cases at 18.1% (30 cases), a significant increase from third place (11.6%) last year, taking the top spot for the first time. Next was "manufacturing," which was first last year, at 14.5% (24 cases), tying it with "municipalities and local governments (14.5%)" in second place. Next were "education and learning support (13.3%)" and "wholesale and retail (9.7%)."
The reason why the service industry saw the highest number of incidents is that with the advancement of digital transformation, the number of B2C platforms that digitally manage large amounts of customer data is increasing, expanding the environment that is more susceptible to attacks.

3.The most common cause of incidents was "unauthorized access," accounting for more than 60% of the total. Of the 13 industries, only "municipalities and local governments" saw "human error" as the most common cause.
The main cause of security incidents was "unauthorized access (excluding ransomware)," accounting for 63.6% of the total. This is a further increase from 61.1% last year, with cyber attacks still remaining the biggest threat. In particular, "ransomware (9.7%)" saw a significant increase from 6.6% last year, and attack methods were diverse.
It is worth noting that, among all 13 industries, only "municipalities and local governments" showed a different trend from the other industries. While "unauthorized access" was the main cause in most industries, such as the service industry and information and communications industry, in municipalities, 66.7% of the cases (16 out of 24 cases) were caused by "human error," such as emails being sent to the wrong person or lost.
This percentage is particularly high among all industries, suggesting that one of the important issues going forward will be how information management operations are conducted in public institutions, as well as the need for continuous education for employees and a review of operational rules.

4.The total number of personal information leaks for the year was 21,909,319, an increase of approximately 300,000 cases from the previous year. The service industry had the highest number of information leaks, a sharp increase of more than 10 times compared to the previous year.
Based on publicly available data, the total number of personal information leaks for the year was 21,909,319. This is an increase of approximately 300,000 from the previous year's 21,646,108 cases, and the overall number has remained at the same level. However, there were significant changes in the damage situation by industry.
Last year, "wholesale and retail (approximately 8.56 million cases)" and "manufacturing (approximately 8.48 million cases)" ranked high, but in 2025 the "service industry" had the most cases with 11,202,230 cases, accounting for 52.6% of the total. Last year, the number of data breaches in the service industry was approximately 1.04 million (including credit card information breaches), but in 2025 it reached over 11.2 million cases, an increase of more than 10 times compared to the previous year.
The sudden increase in the number of data breaches in the service industry is thought to be due to the occurrence of "mega-breaches," in which a single unauthorized access can lead to the leakage of millions of data, primarily in B2C services with a wide customer base. The figures suggest that web security vulnerabilities on platforms that accumulate large amounts of personal data pose a risk that can have a direct impact not only on corporate management but also on society. *1: Ministry of Internal Affairs and Communications, "FY2025 Information and Communications White Paper"

■Comment from Cyber Security Cloud Representative Director, CTO Yoji Watanabe
This survey revealed that incidents will occur with an extremely high frequency of "approximately once every two days" in 2025, resulting in the leak of approximately 21.9 million pieces of personal information over the course of the year. In particular, the fact that approximately 60% of the causes are attributable to external cyber attacks indicates that threats surrounding web systems are becoming more serious.
In recent years, attacks have become more multi-layered and sophisticated, not only exploiting vulnerabilities in web applications but also cleverly targeting API flaws and access privileges in cloud environments.In light of the current situation in which a single intrusion can directly lead to the leakage of millions of data, it is essential for companies to not only rely on traditional "perimeter defense," but also to implement a WAF that detects and blocks attacks in real time at all touchpoints, including websites and WebAPIs, and to implement continuous vulnerability management (ASPM/VMP) in an integrated manner.
We hope that this report will serve as an opportunity for all stakeholders, including management, to recognize that web security is not simply an IT issue, but a core part of management that supports business continuity and trust, and that it will help them build more effective defense systems.
[Survey Overview]
Survey period: January 1, 2025 to December 31, 2025
Survey subjects: Security incidents at corporations and organizations announced during the above period (165 cases)
In this survey, we focused on information from personal information leak cases that were made public in Japan that specifically confirmed the extent of the damage, and compiled and analyzed the data using our own standards.
Specifically, we only include cases where the number of personal information leaks is clearly stated based on information published by the victim organization, such as press releases, official websites, and official social media. Cases that consist only of news articles and do not provide official primary information from the victim organization are excluded from the calculation.
The count is based on the number of cases, and if different cases involving the same organization are publicly announced, each is treated as a separate case. On the other hand, if the same case is publicly announced multiple times, it is counted as one case based on the information at the time the number of personal information leaks was confirmed.
The analysis results in this article are based on information publicly available as of January 30, 2026. The number of personal information leaks may be added or revised at a later date depending on the timing of the announcement, so the aggregated results may change depending on future publicly available information.
About Cyber Security Cloud, Inc.
Company name: Cyber Security Cloud, Inc.
Address: JR Tokyu Meguro Building 13th Floor, 3-1-1 Kami-Osaki, Shinagawa-ku, Tokyo 141-0021
Representative: Representative Director, President and CEO Toshihiro Koike
Established: August 2010
URL: https://www.cscloud.co.jp
With the mission of "creating a safe and secure cyberspace for people all over the world," we are a Japanese security manufacturer that provides web application security services utilizing world-leading cyber threat intelligence, as well as vulnerability information collection and management tools and fully managed security services for cloud environments. As one of the global companies in cybersecurity, we will contribute to solving social issues related to cybersecurity and providing added value to society.