日本語版はこちら
In July 2026, Japan’s Ministry of Internal Affairs and Communications issued administrative guidance to LY Corporation over the external transmission of approximately 8.03 million pieces of user-related information from several LINE games.
Source: Sankei Shimbun / Ministry of Internal Affairs and Communications, Japan
The information included internal user identifiers sent by a development and operations partner to an external analytics service without LY Corporation’s approval and without the required notice to users.
The incident lasted for nearly four years.
At first glance, this may look like yet another story about one company failing to manage user data properly.
But in Japan, the name LINE carries much more weight than an ordinary messaging app.
And that is where this story becomes more interesting.
Ohakonbannichiwa❗️ This is RYO from the Rikigaku Observation Institute.
To Understand the Issue, You First Need to Understand LINE in Japan
For readers outside Japan, a little background is necessary.
LINE was launched in Japan in 2011 by NHN Japan Corporation, which had been established by South Korea’s NHN Corporation, now NAVER Corporation.
So simply calling LINE either a “Japanese app” or a “Korean app” does not fully describe its history.
What matters here is that LINE became extraordinarily successful in Japan.
By March 2026, LINE had about 100 million monthly active users in Japan, equivalent to more than 80 percent of the country’s population.
People use it to talk with family and friends.
Companies use it to communicate with customers.
Stores use official accounts for marketing, reservations and customer service.
And local governments and public organizations have also adopted LINE for administrative communication and public services.
After concerns arose over LINE’s data management in 2021, the Japanese government actually surveyed the use of LINE by government agencies and local authorities and published guidelines for its continued use.
That fact alone tells us something important.
LINE had already become something close to social infrastructure in Japan.
The 2021 Controversy Was More Complicated Than “Servers in China”
This history also explains why some Japanese users react strongly whenever another LINE-related data incident appears in the news.
There is an important factual distinction here.
The 2021 controversy was not simply that “LINE stored all Japanese user data on servers in China.”
The actual problem included the fact that contractors located in China had been able to access certain personal information belonging to Japanese users.
LINE reported to Japan’s Personal Information Protection Commission that such access from China had been blocked by March 23, 2021.
At the same time, some data — including certain photos, videos and files — had been stored in data centers in South Korea.
LINE subsequently began moving the relevant Japanese user data to servers in Japan.
LY Corporation says that the migration of all data covered by that plan was completed by June 2026.
There were also later incidents.
In a major unauthorized-access incident disclosed in 2023 and updated in 2024, LY Corporation reported that 302,980 pieces of user-related personal data had been leaked or potentially leaked, along with information relating to business partners and employees.
That incident began after malware infected a computer used by an employee of a contractor connected to South Korea’s NAVER Cloud.
None of this means that every piece of information on LINE is currently sitting exposed somewhere overseas.
Nor does Korean corporate origin itself prove that a service is unsafe.
The real issue is governance.
Who can access the data❓️
Where is it stored❓️
Which companies and contractors are connected to the system❓️
And are users and public institutions being told those facts accurately❓️
That is a much more useful security question than simply asking which country a company came from.
Infrastructure Does Not Automatically Mean Trust
There is another contradiction in Japan that is easy to miss from overseas.
LINE has become infrastructure-like, but not everyone wants to participate in that infrastructure.
There are Japanese users who consciously avoid LINE, PayPay and other services associated with the broader SoftBank–LY ecosystem.
The reasons are not all the same.
Some are specifically concerned about privacy, cross-border data management or past security incidents.
For others, the reaction is less technical and almost instinctive:
“I simply don’t want to give that corporate ecosystem more of my data.”
There is no reliable statistic telling us exactly how many Japanese people avoid LINE or PayPay for this particular reason.
So it would be wrong to exaggerate this into a majority view.
But privacy-driven refusal of digital services itself is certainly not imaginary.
A 2026 Japanese consumer survey found that, among respondents who felt uncomfortable providing personal information, 35 percent said they had stopped using a service.
This produces an interesting kind of friction.
If a privately operated platform becomes deeply embedded in everyday life, choosing not to use it begins to carry a cost.
A person may distrust the service, yet discover that a company, store, school, neighborhood association or local authority assumes everyone has it.
The technical freedom not to use a service still exists.
But the practical price of exercising that freedom gets higher as the network grows.
That is worth remembering when somebody says:
“If you don’t trust LINE, just don’t use it.”
The Front Door Is Fortified — While the Back Door Is Left Open
Now let us move from LINE itself to corporate information security.
Many companies protect their company-issued computers and smartphones very seriously.
USB storage is restricted.
Software installation is controlled.
Access logs are recorded.
Smartphones are managed through MDM.
Endpoint protection and access-control systems are installed.
Employees receive repeated information-security training.
All of this is reasonable.
Companies also tell employees not to discuss confidential matters carelessly in restaurants, trains or drinking parties.
Yet something strange sometimes happens when the same employees open a private messaging app on their own smartphones.
The level of caution can suddenly collapse.
A logistics company, for example, might exchange messages such as:
“The cargo has left the aviation security area.”
“It should arrive at XX around 11:30.”
“Loading has been completed.”
Each individual message looks almost worthless.
But is it❓️

The company has installed the latest electronic locks and surveillance cameras at the front entrance — its official IT systems.
Meanwhile, the back door may be left open through private smartphones and informal group chats.
Under those conditions, the statement “We take information security very seriously” begins to sound slightly strange.
“Everyone Uses It” Quietly Becomes Evidence That It Is Safe
Why does this happen❓️
One of the simplest answers is probably:
“Because everyone uses it.”
Everyone uses LINE.
Nothing serious has happened to us yet.
Other companies use it too.
Therefore, it must be fine.
This resembles a form of normalcy bias.
But widespread use and suitability for a particular purpose are not the same thing.
Everyone eating McDonald’s does not turn McDonald’s into the fundamental staple food of humanity.
Everyone drinking Coca-Cola does not make Coca-Cola a substitute for water.
Yet with communication tools, popularity can quietly become confused with appropriateness.
“Everyone uses it” gradually becomes “It is safe enough for business.”
That leap deserves more scrutiny.
In the AI Era, Fragments of the 5W1H Can Have Value
And now we reach the central point of this article.
Traditional information security tends to focus on information that is obviously valuable by itself.
Customer lists.
Engineering drawings.
Contracts.
Passwords.
The conventional objective is simple:
Do not let the important file escape.
That remains essential.
But AI changes another part of the equation.
Imagine five isolated pieces of information.
“Company A.”
“Kumamoto.”
“2:00 p.m.”
“Shipment.”
“Prototype.”
Individually, they tell us almost nothing.
But suppose similar fragments are accumulated continuously for months or years.
Who❓️
When❓️
Where❓️
What❓️
Which organization❓️
A human being would struggle to read millions of fragments and discover all of their relationships.
AI does not face the same practical limitation.
It can compare huge numbers of fragments.
It can search for recurring patterns.
It can correlate time, location, people, organizations and objects.
It can cross-reference those fragments with publicly available information.
And it can rank combinations according to how likely they are to be meaningful.

At first, there are only dots.
Then some dots begin to connect into lines.
Eventually, enough lines may reveal a larger structure.
The information does not need to leak as one neat document labeled “CONFIDENTIAL.”
The fragments can acquire value only after they are combined.
That is the important change.
A Cloud Can Emerge from Particles of Information
This is not quantum mechanics itself, of course.
But I like to imagine the result as something similar to a probabilistic cloud.
One observation tells us almost nothing.
Repeat similar observations an enormous number of times, however, and differences in density begin to appear.
Perhaps activity is unusually concentrated at a particular location.
Perhaps shipments repeatedly appear at a particular time.
Perhaps the same people appear around the same type of event.
Perhaps several companies begin moving in a correlated pattern.
No single fragment proves anything.
But the density itself becomes information.

The first useful answer produced by AI does not have to be:
“This is exactly what Company A is secretly doing.”
It may be enough to say:
“Something unusual appears to be happening around these coordinates.”
A human analyst can investigate from there.
Or another AI system can perform a deeper analysis.
Finding the cloud can itself be valuable.
The Next Security Question Is Not “Is This Confidential❓️”
This is why future information security cannot rely only on classifying individual files.
Managers still need to ask:
“Is this information confidential❓️”
But they also need to ask another question.
“What could this information become when combined with other information❓️”
And another.
“What becomes visible if a million fragments like this accumulate outside our control❓️”
The fact that no accident has occurred so far does not prove that a system is safe.
It may simply mean that nobody has yet observed the fragments at sufficient scale.
This Is Not Really an Article About Whether LINE Is “Dangerous”
So this article is not ultimately an argument that LINE is dangerous and Microsoft Teams is safe.
Every communication system has risks.
And replacing one platform with another does not automatically solve poor information governance.
The LINE incident is useful because it forces us to look again at spaces that users psychologically treat as “closed.”
A private group chat feels private.
A smartphone feels personal.
A small operational message feels insignificant.
But those three feelings do not constitute a security architecture.
AI does not necessarily need your confidential document.
It can collect the particles that humans dismiss as meaningless.
It can connect them.
It can observe the dynamics between them.
And once technology can do that at enormous scale, protecting only the “important documents” may no longer be enough.
Information security may now have to protect not only secrets, but also the structures that fragments can reveal when combined.

Reference
個人情報保護委員会:2021年、中国所在の委託先からのアクセス問題
個人情報保護委員会:2021年4月のLINEへの行政上の対応
LINEヤフー:韓国保管データの国内移転完了(2026年6月完了)
LINEヤフー:2023~24年の不正アクセス・302,980件
English Translation by AI Watt — the hardworking canine AI robot of Rikigaku Observation Institute.🐾️


コメントを残す