Recent incidents and affected organizations
A spate of hacking cases involving corporate sites have been reported in Japan in recent weeks. Millions of pieces of personal data were reportedly leaked in some cases.
Daiwa Securities announced on Monday that personal information of about 110,000 clients may have been leaked due to unauthorized access to a contractor's server.
The same day, the operator of the "Yakiniku King" chain of barbecue restaurants reported that more than 10 million customer records had been leaked. The company said its membership management system had been accessed illegally.
Late in September, railway operator Keio said a cyberattack had caused a partial system failure.
The next day, Tokyo Metro said a customer data leak may have occurred due to unauthorized access.
In another case, the operator of car-sharing service Times Car said data from 6.6 million accounts had been compromised.
Expert: Cyberattacks at unprecedented 'speed and scale'
The IT security firm Macnica is pointing the finger at artificial intelligence for the surge of cyberattacks targeting Japanese companies in recent months.
The firm suspects hackers are using AI tools to find vulnerabilities in corporate systems. Macnica has been closely tracking data leaks.
Cases suspected of originating from website or app vulnerabilities jumped from a monthly average of six in the first half of the year to 23 per month since July.
Hackers used to gain unauthorized access to credit card information through shopping sites. But recent data shows unauthorized access occurring across a wide range of systems, including those used for booking sites and apps.
Sejiyama Yutaka of Macnica's Security Research Center says he can't recall personal data leaks occurring this frequently and describes the current situation as highly unusual.
Sejiyama believes attackers are using AI to identify vulnerabilities unique to individual systems, enabling cyberattacks to be carried out at a speed and scale beyond human capability.
He notes that cyberattacks were once limited to people with advanced technical skills. But the emergence of AI appears to be expanding the pool of potential attackers.
He adds that the trend is expected to continue and that companies need to respond quickly.
Macnica urges businesses to check their systems for vulnerabilities and fix them in order of priority. It also calls on companies to delete unnecessary personal information.
The risks and recommended measures individuals can take
Uehara Tetsutaro, a professor at Ritsumeikan University and an expert in information security, says leaked personal information such as email addresses, home addresses and phone numbers is sometimes bought and sold on dark web marketplaces.
He says this data can be used to send phishing emails impersonating companies and other organizations in an attempt to steal credit card and online banking information. He says people whose addresses and mobile phone numbers are exposed may also become targets of scams, including fraudulent money-transfer schemes.
Uehara adds that if identity verification data, such as images of driver's licenses, is leaked along with other personal information, the risks include fraudulent account creation or fraudulent loan applications.
He says contacting a credit information agency after a data leak should lead to more careful identity verification when applying for a card or loan. However, the process requires a fee, and the review of the applicant can also take some time.
He says it is important to take the following steps when personal information is leaked: Be cautious of phishing emails and text messages that exploit leaked data, regularly check credit card statements for any unauthorized transactions and change passwords if they have been reused across multiple accounts.
A shortage of cybersecurity personnel
The Japan Users Association of Information Systems released a survey of corporate IT trends in April. It found that among more than 950 companies that responded, 19.7 percent said information leaks caused by insider misconduct or human error had occurred, or may have occurred without being recognized.
The survey also found that many companies reported a shortage of information security personnel.
Among companies with annual sales of between 100 billion yen and 1 trillion yen, 78.4 percent said they face a shortage of cybersecurity personnel. It was 74.5 percent for companies with sales of 1 trillion yen or more. The findings highlight how staffing shortages leave many companies struggling to keep up with cybersecurity threats.
Digital Transformation Minister Furukawa Toshiharu said at a news conference on Tuesday that the government aims to advance its cybersecurity efforts by getting relevant ministries and agencies to work closely with businesses under the coordination of the National Cybersecurity Office.
Furukawa outlined three measures that individuals can take to help prevent becoming victims. He urged people to stop reusing passwords, enable multifactor authentication, which verifies identity through means other than an ID and password, and remain vigilant against suspicious emails and social media messages.