2026 Mynavi — unauthorized cloud access (~111.5k individuals; Dec 2025–Mar 2026 notices)
Data compromised
Names, emails, addresses, company affiliations, work phones/emails—no payment cards or My Number per company
Technical writeup
Mynavi Corporation, a major Japanese human-resources and recruitment services company, reported unauthorized access to a third-party cloud service it used, with abnormal activity detected December 5, 2025, and leakage of personal information confirmed by January 16, 2026. Public updates in February–March 2026 (including third-party summaries of a final March 31, 2026 report) described on the order of 111,505 affected records spanning general users, corporate contacts, and employees—fields such as names, email addresses, addresses, company names, and work contact details depending on cohort. Mynavi stated credit-card and My Number national ID data were not involved; it described access blocking, vendor collaboration, and police consultation.
Root cause
Unauthorized access to cloud service hosting Mynavi data (vector summarized as circumventing normal controls in trade press)