Urgent.News

What's breaking now, across thousands of outlets.

Tech

Surge in Cyberattacks on Japanese Firms Leading to Increase in Personal Data Breaches

There has been a surge in the number of Japanese companies and organizations reporting massive data breaches following cyberattacks on their systems.

In recent months, Japanese firms have faced a surge in cyberattacks, resulting in an uptick in personal data breaches. According to Trend Micro Inc. and The Yomiuri Shimbun, at least 51 incidents have been reported from October 1-9 alone, indicating October is on track to surpass the monthly total for any other month this year. Previously, credit card data from e-commerce sites was the primary target, but now personal information from a variety of services has been stolen.

Once personal information is compromised, it can be sold on the dark web and misused in various crimes. These include phishing scams to steal credit card or bank account numbers, opening bank accounts or taking out loans under false pretenses, and even robbery. Moreover, unauthorized use of membership points has also been reported.

In a recent instance, members of a survey website operated by GMO Research & AI, Inc., had their login information and encrypted passwords stolen, as well as some reward points exchanged for online shopping gift codes.

The rise of artificial intelligence adds to the concerns surrounding personal data misuse. "AI makes it possible to piece together large amounts of fragmented data to create 'big data,'" explains Masaya Takahashi, a senior specialist at Trend Micro. "There is also a risk that it could be misused in crimes targeting specific individuals, such as sending scam emails pretending to be from services that the individual has used in the past."

If your personal information is stolen, it's crucial to report it promptly. After a cyberattack on Times Mobility Co., operators of car-sharing service Times Car, driver’s licenses along with other data were stolen. Victims should report their stolen ID, such as a driver’s license, to designated credit reporting agencies like Japan Credit Information Reference Center Corp. and Credit Information Center.

These organizations will alert financial institutions to watch for applications, like requests to open bank accounts, submitted using the victim’s name.

For the Times Mobility cyberattack, victims can apply for the reissuance of their driver’s license under the Road Traffic Law. However, a senior official at the National Police Agency warned, even after license number reissuance, the stolen images of the license cannot be deleted, posing a risk of misuse. To protect yourself, experts advise strong password management.

Prof. Tetsutaro Uehara from Ritsumeikan University suggests making passwords as complex as possible, avoiding using the same password for multiple services, and changing passwords immediately if a data breach is reported. Additionally, using Passkey, which allows users to log in using a fingerprint or facial recognition, or multi-factor authentication whenever possible, is recommended as it's more secure than relying on passwords alone.

Be cautious of scam emails disguised as apologies or compensation offers regarding a data breach incident. Always verify official websites and apps before clicking on any links.

Written by urgent.news from The Japan News by The Yomiuri Shimbun's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at japannews.yomiuri.co.jp →

More in Tech

Moving 530k Jobs from Supabase to Postgres on a Free Oracle VM (14s -> 47ms)

I built a job feed. It pulls jobs straight from company career pages into one searchable list. No login, no redirects through job boards. In a few months it grew from 10,000 jobs to over 530,000.

  • Job feed grew from 10,000 to over 530,000 listings
  • Supabase improved load times but filters remained slow
  • Oracle VM reduced query times to under 0.25 seconds

Advisory Wording Diffs: The OSINT Signal Hidden in Security Prose

Security advisories are written by lawyers as much as by engineers. Which means the text itself is a signal source - and diffs of that text, tracked over time, leak information that no single advisory…

  • Lawyers and engineers write security advisories, providing valuable OSINT sources.
  • Correlating prose diffs with calendar shows changes often precede CVE publication by 24-72 hours.

More from Saturday 10 October →