You Don't Need All Seven: How Leaked Personal Data Fits Together

“Japan keeps My Number information in different places, right?” “Then if every place leaks, is it like collecting the seven Dragon Balls?”

Where this applies: This article explains how things work in Japan. Rules, amounts and procedures may be different where you live.

How reading tools work

Listen reads the article aloud. Speed read shows phrases in sequence at your chosen pace. Language practice compares available translations. Save keeps a bookmark in this browser; find it in the player’s bookmarks.

Share this article
You Don't Need All Seven: How Leaked Personal Data Fits Together
AI-generated image
Advertisement
Advertisement

0. The dragon hasn't appeared, but the profile has

“Japan keeps My Number information in different places, right?” “Then if every place leaks, is it like collecting the seven Dragon Balls?”

A nationwide collectible-card event nobody wanted.

The terrifying twist is that nobody needs all seven. A shopping record, a workplace contact list and some publicly shared posts might already reveal a surprisingly detailed picture of someone's life.

Yet two things must not be confused: reconstructing a person's profile is not the same as gaining access to every government database. One is about piecing together clues. The other is about breaking into protected systems.

1. What actually happened in Japan

On October 9, 2026, a social-media post brought fresh attention to a claim that Japan's Digital Agency had leaked approximately 246,000 pieces of personal information. The agency's original announcement, however, was made on September 11, not October 9.[1]

The affected service was a shared work environment for government personnel. On June 25, unusual access to many files through a maintenance account was detected. On July 9, investigators identified an intrusion that exploited a weakness in equipment used for outside connections. The account was suspended and external communication with the compromised equipment was cut off. On September 11, the agency announced that about 246,000 records might have leaked.[1]

The possible records involved names, email addresses, telephone numbers and addresses of government staff, contractors and others involved in government work. Roughly 189,000 records concerned officials and related public employees; roughly 57,000 concerned companies and individuals involved in the work. A record count is not proof that 246,000 different people definitely had data stolen.[1][2]

The agency stated that ordinary residents' administrative records were not included. Nor were My Number identifiers, bank account details or pension numbers. Many listed phone numbers and addresses were work contacts.[2]

2. “I never got the card, so I win!” Not so fast

Some reactions celebrated never applying for a My Number card. But the system attacked here was a government work service, not the chip inside residents' cards or a universal citizen database.

The card does not store your entire tax record, medical history and pension history. Those records remain with the organizations responsible for them.[3][4]

This is not a declaration that government security is perfect: there really was an intrusion, and improvements are needed. It simply means criticism should be aimed at the incident that happened, rather than an imaginary card breach.

3. Why the information is kept separately

Japan's tax agencies keep tax records. Pension offices keep pension records. Municipalities keep local-tax and welfare information. The My Number system does not move everything into one giant vault.[3]

When public bodies exchange necessary information, they generally use different internal codes rather than treating the 12-digit My Number as a universal password. Access is limited to authorized work.[3]

Picture valuables locked in separate buildings. Stealing one building's key should not automatically open every other door. That is the point of splitting records.

But what happens when copies of the documents are stolen from several buildings independently? That is a different problem.

4. Two games: opening safes and assembling discarded papers

Risk one: a chain of intrusions. An attacker who enters one organization's system tries to move into others. Separate storage, separate codes and restricted access help prevent that.

Risk two: joining data already outside the walls. Separate lists from unrelated breaches may have overlapping information about the same person. Each vault may remain locked while its leaked copies are compared elsewhere.

In Dragon Ball terms, one stolen ball does not unlock the other six. But scraps found on the ground might still carry the same owner's name.

Separate storage isn't useless. It protects against a different kind of failure.[3][5]

5. What could private and public information reveal together?

These are hypothetical examples, not a description of what was stolen in the Digital Agency incident.

Possible source What a leaked record might reveal
Online store Delivery address, contact details, purchases
Social platform Interests, friends, public plans
Employer or work service Role, department, work contacts
Public body Only the specific tax, household or other data actually present
Health provider Visits or care details, but only if such data really leaked

An order history alone describes a customer. A workplace list alone describes an employee. Combine them with public posts, and the outline of a person's life grows clearer.

That does not mean “three breaches reveal everything.” It depends on which records escaped, whether they truly concern the same person, and how recent they are. The danger is that meaningful information can emerge without breaking into every system.

6. How can two records be linked—and mislinked?

A shared email address, telephone number, or combination of name and address may suggest that records belong to the same person. But names repeat. Addresses change. Families share contact details. Phone numbers get reassigned.

A plausible match is not necessarily a correct match. Falsely attaching somebody else's illness, debts or personal history to a person can itself be harmful.

Research published in 2019 showed that people can sometimes be identified from records with names removed when enough other characteristics are available. The US National Institute of Standards and Technology also warns that removing obvious identifiers does not eliminate every privacy risk.[5][6]

Neither source proves that a particular Japanese resident was identified in this incident. The study's figures cannot simply be pasted onto these 246,000 possible records.

7. What changes when computers help?

Computers can compare large collections and organize scattered notes much faster than people. Modern text-generating tools can also turn partial knowledge into convincing-sounding descriptions and messages.

A fake email mentioning a real workplace or recent interest can feel alarmingly personal. The Digital Agency explicitly warned that information from this incident could be used for impersonation or deceptive messages.[1]

But such tools do not magically know missing facts. They can confidently combine the wrong people. And building a profile does not automatically reveal card passwords, open bank accounts or bypass identity checks.

8. Sensible defenses on both sides

Organizations need to fix known weaknesses promptly, limit who can read which records, stop retaining data they no longer need, detect unusual bulk access, and respond clearly when an incident occurs. Splitting storage is useful, but protecting copies once they leave a system matters too.

On July 9, the agency disabled the affected account and blocked the compromised equipment's external communication. It has said it will review how weaknesses are managed and how outside access works.[1] Those are relevant actions; they do not erase the initial failure.

For individuals, avoid signing in through unexpected messages. Open official sites or apps yourself, stop reusing passwords, and enable extra sign-in protection where available. If the agency contacts you as an affected person, verify instructions through official channels.

This incident alone is not a reason for every My Number cardholder to cancel a card.

9. Conclusion: the dangerous thing is the fragments

Keeping official records separate makes a one-stop theft of everything harder. It is a meaningful safeguard.

Yet leaked pieces from different public and private sources can sometimes be joined after the breaches. The next question is therefore not only “What if all seven locations are broken into?” but also:

“Could just two or three overlapping fragments tell someone far too much?”

Shenron: “Come back when you have all seven.”

Leaked data: “Sorry, the story was already revealing itself at three.”

Preventing a master-key disaster and preventing a data jigsaw are two separate jobs. We need both.

References (1)

[1] Digital Agency, Japan — government work environment incident, September 11, 2026 [2] Digital Agency, Japan — incident questions and answers, updated September 12, 2026 [3] Digital Agency, Japan — My Number system and separate storage [4] Japan Agency for Local Authority Information Systems — My Number card security [5] NIST — De-Identifying Government Datasets, September 2023 [6] Rocher, Hendrickx & de Montjoye — Nature Communications, July 23, 2019

If this article helped you, you can support the site. Support

Advertisement

Read this today

Each one answers a question readers of this article tend to ask next.

Browse all articlesMore on Work

Find other articles

All articles

Mendoi-chan

Who runs this site

Mendoi-chan

She turns friction at work and in everyday life into clear structure and practical next steps.