News On Japan

Japan's Cybersecurity Vulnerabilities Exposed as AI-Powered Attacks Rise

TOKYO - Japan is facing a sharp increase in cyberattacks, with experts warning that artificial intelligence is making it easier for criminals to steal and exploit personal information, while the growing sophistication of online fraud is exposing weaknesses in the country's cybersecurity defenses.

An international hacking group known as Qilin has described Japan as "one of the countries with the weakest computer security in the world," a claim that reflects growing concerns over the frequency of attacks targeting Japanese businesses and organizations.

Research by Yutaka Sejiyama, assistant director of the Macnica Security Research Center, shows that the number of publicly disclosed incidents involving information leaks caused by cyberattacks in Japan has been increasing since July.

By October 9, the country had already recorded 25 such incidents during the month. If the current pace continues, the monthly total could exceed 70, highlighting the accelerating threat to corporate networks and personal data.

Sejiyama believes AI is playing a significant role in the increase. "Judging from the circumstances, there is no doubt that AI is being extensively used," he said.

However, the technology being exploited by cybercriminals may differ from familiar consumer AI services such as ChatGPT and Gemini.

According to Sejiyama, attackers are likely using AI models described as "open-weight," which allow users considerable freedom to customize their operation.

Open-weight models provide access to the underlying parameters that determine how an AI system functions, making it possible to modify or adapt the technology for a wide range of purposes. Although this flexibility supports legitimate research and commercial applications, it can also be exploited to develop tools for cyberattacks.

By contrast, commercial AI services such as ChatGPT generally place greater restrictions on how their systems can be customized and used, providing safeguards intended to limit malicious applications.

The expanding threat is not limited to the initial theft of information. Experts warn that AI is also increasing the value of stolen personal data by making it easier for criminals to combine separate pieces of information and identify opportunities for fraud.

Recently disclosed leaks involving images of driver's licenses illustrate the risks. Criminals who obtain such information may be able to impersonate victims, apply for loans from consumer finance companies without their knowledge, or make expensive purchases using their identities.

Stolen personal information is also bought and sold on the dark web, a part of the internet accessible through specialized software and frequently associated with illicit marketplaces.

Even information that appears relatively harmless when considered on its own can become valuable when combined with other leaked records.

For example, a criminal who obtains a person's name and email address may initially have limited opportunities to exploit the information. However, if those details can be connected to another database containing the same person's name and credit card number, the potential for fraud increases considerably.

Additional records showing travel reservations, booking dates, and passwords for reservation websites can provide criminals with an even more detailed picture of a victim's activities.

AI is particularly effective at identifying connections among large volumes of fragmented data, allowing attackers to assemble individual records into more comprehensive personal profiles.

This capability also makes it possible to analyze victims' behavior and determine when fraudulent communications are most likely to appear legitimate.

Rather than sending indiscriminate phishing emails, criminals can tailor messages to match a person's actual activities and circumstances, increasing the likelihood that the recipient will respond without suspicion.

In September, for example, people who had made genuine accommodation reservations received fraudulent emails containing their actual booking information. The messages instructed recipients to reenter their credit card details or make urgent payments.

Because the emails included legitimate reservation details, recipients could have mistaken them for authentic communications from accommodation providers or booking platforms.

Such incidents demonstrate how stolen information can be used not only for direct identity theft but also to create highly convincing scams that exploit the trust people place in familiar commercial transactions.

With cyberattacks becoming more frequent and personal information leaks increasingly difficult to prevent, experts say individuals need to strengthen the security of their online accounts.

Sejiyama recommends avoiding the reuse of passwords across different services and actively enabling multifactor authentication wherever it is available.

"Naturally, people should not reuse passwords, but it is also effective to actively use multifactor authentication, such as biometric verification or authentication apps, on websites that support it," he said.

Multifactor authentication requires users to provide an additional form of verification beyond a password, such as biometric identification or confirmation through a dedicated authentication application.

Once enabled, a password alone is no longer sufficient to access an account. Even if login credentials are exposed in a data breach, the additional security requirement can significantly reduce the risk of unauthorized access.

The measure is particularly important as criminals become increasingly capable of linking information obtained from multiple breaches and using it to target individuals through personalized attacks.

The rapid growth of AI-assisted cybercrime is creating a new challenge for Japan's digital economy, where the security of personal information depends not only on the defenses maintained by companies but also on the precautions taken by individual users.

As attackers adopt increasingly sophisticated technology, experts emphasize that traditional password protection alone is no longer enough, making stronger authentication and greater awareness of information security essential defenses against online fraud.

Source: TBS

News On Japan
POPULAR NEWS

Very strong Typhoon No. 29 (Koguma) was moving north near the Ogasawara Islands on the evening of October 11, bringing the risk of high waves and powerful swells along Japan's Pacific coast, particularly around the Izu Islands and coastal areas of the Kanto region, despite expectations of limited direct impacts from the storm. At 9 p.m. on October 11, the typhoon had a central atmospheric pressure of 950 hectopascals and maximum sustained winds of 45 meters per second near its center, maintaining its classification as a very strong typhoon. It was moving north at approximately 15 kilometers per hour.

Japan is expected to experience a warmer-than-normal winter as the El Nino phenomenon currently affecting the Pacific Ocean has reached its strongest level on record, with the Japan Meteorological Agency announcing on October 10th that unusually high sea surface temperatures are likely to persist through the coming winter months.

The Otsu Festival, one of Shiga Prefecture's three major traditional festivals, was held in Otsu City on October 11th, featuring a procession of 13 elaborately decorated floats carrying traditional mechanical puppets through the streets, following the festival's addition to UNESCO's Intangible Cultural Heritage list in December last year.

A series of cyberattacks has disrupted business operations and exposed millions of customer records across Japan, with a ransomware attack on a cloud service provider affecting 495 companies and local governments nationwide, while convenience store operator Lawson has disclosed a separate breach involving more than 2.15 million personal information records.

Japan's first 360-degree projection mapping show will open at the Osaka City Museum of Fine Arts on October 10, transforming the historic building into an immersive world of light, music, and seasonal imagery, with organizers hoping the attraction will also help stimulate the city's nighttime economy.

MEDIA CHANNELS
         

MORE Web3 NEWS

Japan is facing a sharp increase in cyberattacks, with experts warning that artificial intelligence is making it easier for criminals to steal and exploit personal information, while the growing sophistication of online fraud is exposing weaknesses in the country's cybersecurity defenses.

A series of cyberattacks has disrupted business operations and exposed millions of customer records across Japan, with a ransomware attack on a cloud service provider affecting 495 companies and local governments nationwide, while convenience store operator Lawson has disclosed a separate breach involving more than 2.15 million personal information records.

Tokyo hosted an employment support event for older workers on October 6, offering job consultations, interviews, hands-on work experience and training in artificial intelligence as the number of people aged 65 and over in the workforce continues to rise.

The ransomware group Qilin, accused of carrying out repeated cyberattacks against companies including Asahi Group Holdings, has warned that attacks targeting Japanese companies and government agencies could increase after a suspected core member was detained in Osaka and extradited to Germany.

Kawasaki Heavy Industries has unveiled a prototype next-generation shipbuilding robot that can climb vertically along ship hulls, part of an effort to use physical AI to address labor shortages and preserve skilled manufacturing techniques.

Panasonic Holdings is pushing ahead with one of the most sweeping restructurings in its 108-year history, cutting about 12,000 jobs, selling major businesses and reorganizing operations as the Japanese electronics group seeks to build new sources of growth around artificial intelligence, data centers and recurring service revenue.

A Tokyo court has recognized the commercial rights of performers over their voices for the first time, ruling that unauthorized use of AI-generated voices resembling those of celebrities can constitute an infringement of publicity rights in a landmark lawsuit brought by popular voice actor Kenjiro Tsuda against the operator of TikTok.

The Asia-Pacific gaming market has been having a pretty serious moment.