Key takeaways

  • Every year, Japan's Information-technology Promotion Agency (IPA) publishes the Information Security White Paper, the closest thing Japan has to an official annual review of cybersecurity. The 2026 edition, subtitled "A new era of cyber defense: prepare for a double-edged evolution", came out as a PDF on September 30, 2026. It is only in Japanese.
  • It covers fiscal 2025 (April 2025 to March 2026). Phishing reports rose 15% to 2.31 million. Losses from illicit online banking transfers hit ¥10.4 billion, the worst in five years, with businesses taking a sudden 45% share.
  • The headline policy themes are the active cyber defense law, AI, including the government's Project YATA-Shield response to AI models that find vulnerabilities, and the new SCS supply chain security rating.
  • The government's main request to critical infrastructure in the AI era is to get the basics right, the same basics that police data shows are still failing.
  • A column in the paper notes that certification such as ISMS does not necessarily guarantee strong security, a point that also applies to the new SCS rating.

What the white paper is#

IPA is the government agency under the Ministry of Economy, Trade and Industry (METI) that runs Japan's national IT exams, handles vulnerability reports, and will run the SCS rating scheme. Its white paper collects the year's statistics, notable incidents and policy changes in one 208-page volume.

Period covered Fiscal 2025: April 2025 to March 2026, with some later events. Most sources were checked in July 2026
Published PDF on Sep 30, 2026. Print edition on Oct 19, 2026 (¥2,200)
How to get it The PDF is free from IPA's white paper page after a short survey
Structure Prologue; Ch. 1 threats; Ch. 2 cyber security policy, AI and disinformation; Ch. 3 domestic policy, skills, certification schemes and SMEs; Ch. 4 international policy and standards

Because the paper mostly compiles figures from other bodies, such as the National Police Agency (NPA) and the Council of Anti-Phishing Japan, many numbers are already public. Its value is in having them in one place, alongside the government's own account of its policies.

The year in numbers#

The paper compiles these figures from other organizations (section 1.1.2):

Indicator 2025 Original source
Phishing reports 2,308,796 (fiscal year), up 15.0%, about 4 times FY2021 Council of Anti-Phishing Japan
Brands impersonated in phishing 1,254 (fiscal year), the most in five years Council of Anti-Phishing Japan
Fraudulent trades after phishing of online brokerage accounts About ¥740.8 billion in trades, peaking in April National Police Agency
Losses from illicit online banking transfers ¥10.4 billion, the worst in five years. Businesses: ¥4.7 billion, 45% of losses but only 4% of cases National Police Agency
Personal data leaks and losses disclosed by listed companies 180 incidents, 30.6 million people, 158 companies, the most companies since the survey began in 2012 Tokyo Shoko Research

The business banking losses were driven by voice phishing: callers claiming that an online banking update is needed get an email address out of staff, then send a phishing email. The paper says one company lost more than ¥400 million. Text messages also became a much bigger lure: the share of illicit transfers that started with an SMS roughly tripled.

Ransomware: cases and fake claims#

The white paper's ransomware statistics are the NPA's figures for 2025. The NPA has since published figures for the first half of 2026, which we cover in our ransomware statistics explainer. What the white paper adds is detail on individual cases.

It names two major cases from the year. At Asahi Group, attackers entered around September 19, 2025 through a network device at a group site, and the company has confirmed leaks of 115,513 records of personal data. At Askul, an office supplies e-commerce company, the logs had been deleted, so the cause cannot be fully established.

It also describes fake leak claims. In January and February 2026, a group calling itself "0APT" claimed to have stolen data from more than 200 organizations. Some of the named organizations found no trace of intrusion, and most of the posted files were empty dummies. The paper notes that such fake claims can serve other purposes besides extracting a ransom, such as pushing down a company's share price to profit from short selling, or showing off a list of "victims" to recruit affiliates.

Policy theme 1: active cyber defense#

Section 2.1 summarizes the active cyber defense law and the government's basic policy under it, adopted in December 2025. The paper was written before the law's main provisions took effect on October 1, 2026.

The law has five pillars in the paper's summary: public–private cooperation, use of communications data, provision of analysis and vulnerability information, access and neutralization, and organizational changes. Most of the section is about the first three: incident reporting by critical infrastructure operators, information sharing councils, agreements on communications data, and what the government will share and with whom. Points from the basic policy include:

  • Agreements with infrastructure operators must not become de facto compulsory, and companies that do not sign must not be treated unfairly.
  • Selected communications data may not be used for criminal investigations.
  • Reports from operators should be set so they are not an excessive burden, and the government will work to create a single reporting point.
  • Incident reporting and the collection and handling of communications data will be reviewed about three years after the law takes effect.

Neutralization of attackers' servers by the police and the Self-Defense Forces appears as one item in the list.

Policy theme 2: AI that finds vulnerabilities#

Section 2.2 is the longest new material. It describes AI lowering the bar for attackers, automating attacks, and changing what attacks are possible. Examples it cites include:

  • A report by AI developer Anthropic in November 2025 on a group it assessed as China-based using its AI to attack about 30 organizations, with 80–90% of the work automated. The paper notes that others questioned whether the claims could be verified.
  • Amazon reported in February 2026 that a financially motivated actor with limited skills used commercial AI services to build tools and plan attacks, and compromised more than 600 FortiGate devices in over 55 countries. No vulnerability was exploited: the attacker logged in through exposed management interfaces with weak passwords.
  • Anthropic's Claude Mythos Preview, announced in April 2026, which the company said found thousands of serious vulnerabilities, including a 27-year-old bug in OpenBSD. Anthropic has not released it publicly and limits access through Project Glasswing. Mozilla fixed 271 vulnerabilities it found in Firefox.
  • The side effects for defenders: the curl project ended its bug bounty in January 2026 after a flood of low-quality AI-generated reports, and NIST began prioritizing which CVEs it analyzes in the US National Vulnerability Database from April 2026.

The government's response is Project YATA-Shield, a package of measures adopted on May 18, 2026. The name stands for "Yielding Advanced Threat Awareness with AI" and also refers to the Yata no Kagami, the sacred mirror. It asks critical infrastructure operators to:

  • Make sure basic measures are actually in place: asset management, risk assessment, vulnerability management, access control, backups, monitoring, business continuity, incident response and supply chain risk
  • Prepare for vulnerabilities being found and fixed faster and in larger numbers, and apply patches or mitigations quickly
  • Move toward zero trust design, strengthen threat hunting, and use advanced AI for defense

Policy theme 3: the SCS supply chain rating#

Section 3.4 describes the SCS rating scheme, which we analyzed in detail:

★3 ★4 ★5
Aim Minimum for every company in a supply chain Standard target Advanced
Requirements 26 43 To be decided
Assessment Self-assessment checked by a security expert Third-party assessment Third-party assessment
Validity 1 year 3 years, with an annual self-assessment To be decided

★3 and ★4 are expected to start around the end of fiscal 2026, that is, early 2027. A new type of the "Cyber Security Otasuketai" support service for SMEs, designed to help them get a ★, entered a trial in September 2026.

The paper presents the scheme as the answer to a real problem: suppliers face different security demands from each customer, and customers cannot see what suppliers actually do.

Our analysis#

The basics are the story#

Project YATA-Shield is a response to frontier AI, but its main request to critical infrastructure is to do the basics properly, and to be ready for patches arriving faster and in larger numbers.

The police figures on ransomware, which the white paper repeats and we have covered, show how far that is from reality. Attackers mostly get in through VPN devices and remote desktop. In 2025, fewer than half of the victims who answered had applied the latest patches to the device they came in through. Most victims had backups, but most could not restore from them.

If AI speeds up how quickly vulnerabilities are found, the gap between a patch existing and a patch being applied becomes more dangerous, not less. That is our inference, but it follows from the figures.

Active cyber defense is mostly about information#

In Japanese media, active cyber defense is mostly discussed as the police and military neutralizing attackers' servers. The white paper's account is different. Most of its section deals with reporting, sharing and analysis: what operators must report, what the government will collect and what it will give back. Neutralization is one item in a list. That matches what we found when we read the law itself: for most companies, the practical change is reporting duties and new channels for threat information.

On certification, the paper's own column raises the question#

A column on supply chain security in the white paper suggests using the SCS scheme as a reference when vetting suppliers. The same column says that certification such as ISMS is a useful guide, but "does not necessarily guarantee the strength of security measures."

That is a fair point, and it applies to any certification. The SCS section does not discuss how the new rating will relate to ISMS, the Privacy Mark or the automotive industry's JAMA/JAPIA guidelines, which many suppliers already have to meet. Its schedule lists "coordination with preceding domestic and foreign schemes" as a task. Until that is settled, there is a risk, as we argued earlier, that suppliers get one more certificate rather than fewer checklists.

How to read it yourself#

  • The PDF is free from IPA's white paper page after a two-minute survey. A version with clickable footnote links is due on October 19.
  • IPA allows quotation with attribution. If you reuse figures, check the credit: IPA cannot authorize reuse of charts it made from other organizations' data.
  • The PDF should not be reposted: IPA asks that people link to its page instead.

Japanese terms at a glance#

Japanese Reading Meaning
情報セキュリティ白書 jōhō sekyuriti hakusho Information Security White Paper
情報処理推進機構(IPA) Jōhō Shori Suishin Kikō Information-technology Promotion Agency, Japan
ボイスフィッシング boisu fisshingu Voice phishing (vishing)
不正送金 fusei sōkin Illicit (fraudulent) money transfer
サイバー対処能力強化法 saibā taisho nōryoku kyōka hō The active cyber defense law
無害化 mugaika Neutralization (of attackers' servers)
フロンティアAI furontia ēai Frontier AI
SCS評価制度 esu-shī-esu hyōka seido Supply chain security rating scheme
サイバーセキュリティお助け隊 saibā sekyuriti otasuketai Government-backed security support service for SMEs