- The Japanese Atomic Energy Agency (JAEA) confirmed unauthorized access to its JRR-3 research-support site, compromising 2,419 files.
- The exposed materials included 367 files containing personal information of 175 persons.
- JAEA stopped external access, notified affected individuals and authorities, and reported no impact on its internal business network.

The Japan Atomic Energy Agency has confirmed the hacking of a cloud-based website that was providing information to users of the JRR-3 research reactor. The incident exposed personal information linked to people who registered for site access and radiation-control procedures.
JAEA said its investigation found that 2,419 files had been downloaded without authorization. Among them, 367 files contained personal information connected to 175 individuals, according to the agency’s October 1 disclosure.
The Agency Finds Unauthorized Access to Research Support Site
JAEA confirmed the incident on September 25, 2026, after detecting unauthorized access to its research-support environment. The affected platform supports external users of JRR-3 at the Nuclear Science Research Institute in Tokai-mura, Japan. The agency said an unauthorized party downloaded files from the RING user site. JAEA operates the site for research-related support and procedures linked to external users.
The investigation identified 2,419 files that left the system without authorization. JAEA also found that 367 of those files contained personal information. The report stated that the leaked data involved 175 users registered from May 2026 onwards. The people are those registered to gain access to the reactor and radiation-control procedures.
The leaked data also involved different types of identification information and health records of the users. JAEA listed names, identification images, radiation-work medical examination results, and radiation-worker certificates among the affected material. However, the agency said account IDs, passwords, and names entered on registration forms did not leak – this distinction limits the scope of the confirmed exposure.
Personal and Radiation-Related Information Exposed
JAEA reported that 200 of the affected files contained photo identification images. These included driver’s licenses, My Number cards, passports, and residence cards. The agency confirmed My Number information for six people within the exposed files. My Number refers to the individual identification system in Japan, which supports administrative procedures.
The breach also involved 146 files containing results from special medical examinations for radiation work. Another 21 files contained radiation-worker certificates. These records create a different type of concern from ordinary contact information. Medical and radiation-related documents can reveal sensitive details about a person’s work activities and health checks.
JAEA has not reported evidence that attackers accessed its internal business systems. According to the agency, the affected scientific research support site functions independently from its internal business system. The distinction is vital since JRR-3 provides research work based on neutron beams and irradiation studies.
Further, JAEA indicates that JRR-3 is a 20 MW research reactor serving numerous research experiments. Therefore, the confirmed incident currently points to a data exposure involving the external support environment. It does not indicate a compromise of the internal control systems of the reactor.
The Agency Cuts External Access and Starts Notifications
JAEA stopped external access to the affected site on the same day it confirmed the unauthorized activity. The agency then continued its investigation to determine the extent of the exposure. The organization also began contacting people whose information appeared in the affected files. In addition, JAEA notified the Personal Information Protection Commission of Japan, relevant authorities, and police.
The agency has not publicly laid the attack to any hacker or criminal group. Also, it has not explained whether this intrusion was a ransomware attack at all. This is crucial since the information available addresses only the issue of proven intrusion but not who was responsible for it and what the intention was behind performing such actions.
The response from JAEA also reflects the importance of separating public-facing research services from internal systems. The agency has earlier referred to the JRR-3 as a facility that primarily intends to conduct neutron beam and irradiation studies.
The history of the reactor as a research facility is long, and it started functioning again in 2021 after passing through a series of regulatory and safety procedures. JAEA said the facility could support research and innovation through its neutron capabilities. For this incident, however, the disclosure from JAEA does not report an impact on reactor operations.
What the Breach Means for Affected Users
The breached records contain information related to identification, medical, and radiation work. That combination could give unauthorized parties a detailed picture of some affected individuals. Still, JAEA has not reported misuse of the exposed information. The current disclosure of the agency focuses on the files that investigators confirmed as downloaded.
Since there are no exposed account IDs and passwords, there is a lower immediate risk of direct account takeover by using the credentials. On the other hand, the exposed identification records could result in separate privacy and impersonation concerns.
Other recent breaches have also exposed users to credential-related risks, including Anthropic revoking Claude sessions after malware steals user login tokens, where malware was used to steal login tokens.
JAEA has notified the affected people, as well as the relevant authorities. More investigations could help to understand whether the unauthorized person has accessed any additional information and whether there is a cause for this attack. Meanwhile, the disclosure by JAEA provides no evidence that the incident reached its internal business network or disrupted JRR-3 operations.