Japan's government-backed ★3 and ★4 security marks for suppliers open for applications in March 2027. How the SCS system works, what it costs, and why it is unlikely to replace buyers' security checklists or make supply chains more secure.
Shueisha, the Japanese publisher, says attackers exploited a CMS misconfiguration to create an admin account on a system for its fashion magazine bloggers and took data on 2,835 people, plus emails and partner lists. It was noticed only because the attacker sent emails.
TOPPAN, which runs a shared insurance-certificate service for 14 Japanese non-life insurers, mistakenly sent data on 177,426 Sompo Japan customers to another insurer after a drag-and-drop error. What happened, what was exposed, and why its recurrence measures lean on a human checker.
Seicomart, Hokkaido's convenience store chain, says an attacker reached its member database through the server behind its smartphone app, possibly exposing data on about 570,000 loyalty accounts. It was spotted after a single fraudulent membership cancellation.
Park24 confirmed that attackers took data on about 6.6 million accounts from its Times Car car-sharing service, including images of identity documents such as driver's licenses for about 1.6 million of them. What was taken, how Park24 has handled it, and what users should do.
Tokyo Metro says an unauthorized party, apparently from overseas, accessed a server for its Metpo points service, possibly exposing about 59,000 member email addresses. What was on the server, how the access was found, and what members should watch for.
Japan's National Police Agency recorded 123 ransomware cases in the first half of 2026, a record. Who gets hit, how attackers get in, how long recovery takes, what it costs, and why backups so often fail, in figures from the NPA's own reports.
Keio Corporation, the Tokyo rail and retail group, confirmed a ransomware attack on a group server on September 26, 2026. Card payments at some group stores and hotel reservations were disrupted. Trains are running normally. What Keio has confirmed so far.
A National Police Agency panel has proposed letting police remotely access phones used by Japan's anonymous fraud and robbery rings to read encrypted messages. What the proposal says, why its scope may reach beyond those groups, and why six weeks of deliberation feels too short.
Japan Post has suspended an online service for tracing lost or damaged international mail after finding possible unauthorized access to its server on September 25, 2026. What is known, what is not, and the questions the follow-up needs to answer.
On September 23, 2026, 'a large volume of external access' overloaded J:COM's DNS servers and cut internet service for up to 4.08 million households for about nine hours. What J:COM has confirmed, whether it was a DDoS, and why customers were left in the dark.
Attackers exploited a VPN vulnerability to break into the Government Solution Service (GSS), the shared IT platform run by Japan's Digital Agency, exposing data on about 246,000 officials and contractors. Timeline, the likely flaw, and what it means.
From October 1, 2026, Japan's critical infrastructure operators must report cyber incidents, and police gain powers to neutralize attack infrastructure. What the law actually does, how it is misread in Japan, and what it means for foreign vendors.