How Many Misdirected Emails a Year? Japan's Statistics Don't Separate Them
I went looking for a count of misdirected emails in Japan's public sources. The regulator's 2,889 "missending" cases also cover posted documents, a survey of listed companies folds email into "misdisplay and missending," and the IPA threat ranking is decided by vote rather than by incident counts.

How often does a misdirected email actually happen? I read the Japanese public sources that would be expected to say so, and none of them supports a figure like "X cases a year" for email alone. One reason is that missending is counted together with other kinds of incident.
"2,889 missending cases" is not 2,889 emails
The Personal Information Protection Commission (PPC), Japan's data-protection regulator, publishes an annual report on the breach notifications it processes. The fiscal 2025 edition covers April 1, 2025 to March 31, 2026, and breaks down the causes of the 13,345 notifications the Commission received directly from private-sector organizations.
Of those, 11,040 (82.7%) were leaks at the reporting organization itself: 6,072 cases of misdelivery (45.5%) and 2,889 cases of missending (21.6%). Both percentages are against the same 13,345.
But "missending" is not an email category. The report's own examples are documents handed to the wrong person at hospitals and pharmacies, and credit cards mailed to the wrong address. You cannot read 2,889 as a count of misdirected emails.
Another survey folds email into "misdisplay and missending"
Tokyo Shoko Research, a corporate research firm, counts the incidents that listed companies and their subsidiaries disclose themselves. For 2025 it counted 180 such incidents. The largest cause is virus infection and unauthorized access, at 116 cases (64.4%); "misdisplay and missending" comes second at 37 cases (20.5%).
The firm's examples of human error in that group include mixing up CC and BCC when sending mail, and misconfigured systems. Again, the email share is not broken out.
This survey is also the firm's own tally of what listed companies chose to disclose. Its population and method differ from the regulator's, so the two sets of numbers cannot be added or compared directly.
A threat ranking is not an incident count
In the IPA's "10 Major Security Threats 2025" — the annual list from Japan's Information-technology Promotion Agency — "information leaks caused by carelessness" ranked 10th for organizations. In the 2026 edition it is no longer in the top 10.
That is not evidence of a decline. The list is not a ranking by number of incidents: the IPA selects candidate threats from the previous year's significant events, and a "10 Major Threats Selection Committee" of around 250 researchers and practitioners decides the order by discussion and vote.
What to check before quoting a number
When you meet a number about misdirected email, it is worth checking what is being counted, who is included, and whether non-email incidents share the same category.
The sources do show that missending happens. What they do not support is stitching different tallies together into a sentence like "there are X misdirected emails a year in Japan."
References
- Personal Information Protection Commission, "Annual Report for FY2025" — Publisher: Personal Information Protection Commission (Japan) / Period: April 1, 2025 – March 31, 2026 / Published: July 7, 2026 / announcement page, in Japanese, external. Figures are from p.9 and appendix table 2(2)⑤ of the full report, PDF, in Japanese, external; the breakdown is against the 13,345 notifications received directly by the Commission.
- Tokyo Shoko Research, TSR Data Insight, "Personal information leak and loss incidents at listed companies: 180 cases, the second highest on record, with about twice as many people affected at 30.63 million" — Publisher: Tokyo Shoko Research, Ltd. / Scope: incidents disclosed in 2025 by listed companies and their subsidiaries, tallied by the firm / Published: January 30, 2026 / article, in Japanese, external
- IPA, "10 Major Security Threats 2025" and "10 Major Security Threats 2026" — Publisher: Information-technology Promotion Agency, Japan / Published: January 30, 2025 and January 29, 2026 / 2025 edition, in Japanese, external / 2026 edition, in Japanese, external
Every figure in this note was checked against the primary sources on September 12, 2026. The next review is set for February 28, 2027, after the IPA's 2027 edition and Tokyo Shoko Research's 2026 survey are published.