A sweeping cybersecurity survey of Japan's Nikkei 225 companies has exposed a widespread credential leak crisis among the country's largest corporations. Of 224 firms surveyed, 217 — or 96.4% — reported data breaches within the past three years.
The survey, conducted by identity security provider Josys Inc. (ジョーシス株式会社), found that leaked credentials totaled 279,206 across all surveyed companies. With a combined workforce of 9,564,043 employees, the overall breach rate stands at 2.9% — roughly three compromised accounts per 100 employees.
The scale of exposure runs deeper than raw numbers suggest. Some 168 companies, or 75.0% of those surveyed, suffered serious breaches involving sensitive authentication data — including credentials linked to identity management platforms, security systems, and customer relationship management (CRM) applications.
The industry breakdown reveals stark disparities. The pharmaceutical sector recorded the highest employee-adjusted breach rate at 11.6%, followed by construction at 7.0% and food and beverage at 6.5%. At the other end of the spectrum, banking posted the lowest rate overall at just 0.7%, with Japan's megabanks averaging an even lower 0.5%.
The gap between the most and least exposed sectors is striking: pharma's breach rate is more than 23 times that of megabanks — a contrast that lays bare how dramatically cybersecurity risk and preparedness vary across different corners of the Japanese economy.

































