Key takeaways

  • Within one week, from October 7 to 9, 2026, Japan's national cybersecurity office, its privacy regulator, the IPA, the police and four ministries all issued warnings or requests after a run of large data breaches at Japanese companies. JPCERT/CC published the technical details.
  • The government also held an inter-ministerial meeting on October 8, where the minister in charge of cybersecurity called the situation "very urgent" and officials agreed to centralize information at the National Cybersecurity Office (NCO).
  • The messages largely agree: the attacks start from exposed web applications, services and accounts, not one product; companies should patch, add MFA, watch their logs, manage contractors and delete data they no longer need.
  • The most concrete step comes from the Financial Services Agency. Because driver's license images have leaked, it told banks and other financial firms to stop accepting uploaded ID photos for online identity checks before the legal deadline of April 2027, and switch to reading the IC chip.
  • None of the warnings creates a new legal obligation. They are requests, and sharing attack details with the government remains voluntary.

A week of warnings#

Date (2026) Who What
Oct 1 (reported Oct 7) Ministry of Land, Infrastructure, Transport and Tourism Asked the rental car industry to check its data protection after the Times Car breach, and report by October 30
Oct 7 Personal Information Protection Commission (PPC) Warning to large data holders, and a preview of tougher security guidance
Oct 8 JPCERT/CC Technical warning on the attack patterns, with attacker IP addresses. Updated October 9
Oct 8 Inter-ministerial meeting First government meeting on the breach wave, according to Japanese media
Oct 8 National Police Agency Cyber police bulletin, "Beware of data leaks", aimed at the public and companies
Oct 9 National Cybersecurity Office (NCO) Warning to companies holding large volumes of personal or sensitive data
Oct 9 IPA Urgent checklist for companies
Oct 9 Financial Services Agency (FSA) Warning to financial institutions, including on identity verification
Oct 9 Ministry of Economy, Trade and Industry (METI) Warning and a request to report incidents
Oct 9 Ministry of Internal Affairs and Communications (MIC) Passed the NCO warning to the companies it oversees

The inter-ministerial meeting#

On the afternoon of October 8, the minister in charge of cybersecurity, Toshiharu Furukawa, and the NCO's top official met officials from METI, MIC and other ministries, according to Kyodo News. "We are in a very urgent situation," Furukawa said, according to TV Asahi. "The whole government needs to work together on countermeasures."

According to TV Asahi, the meeting decided to centralize information on unauthorized access at the NCO, and confirmed a policy of asking companies to manage data properly and delete data they do not need, to stop leaked data being misused. No official record of the meeting had been published as of October 9.

What each agency is asking#

National Cybersecurity Office: three areas#

The NCO, Japan's central government body for cybersecurity, says it has confirmed multiple cases in which attackers broke into the systems of companies holding large volumes of personal data, through web system vulnerabilities, compromise via the supply chain and weak data management. Its warning, aimed at companies holding large volumes of personal or sensitive data, is organized in three areas:

  1. Web systems. Assume you "could be attacked at any time". Patch operating systems, middleware, CMSs and applications quickly, including internal servers. Do not use products or versions that are out of support. Shut down unused systems, run regular vulnerability assessments, use MFA, and monitor for suspicious or high-volume access.
  2. The supply chain. Manage contractors "together with" them: check their security, certifications and subcontractors on an ongoing basis, write breach reporting duties into contracts, give them only the data they need, and make sure they delete it when the work ends.
  3. Data. Know what data you hold and where. Delete data once its purpose is served or its legal retention period has passed. Limit access, separate read and write rights, encrypt data, never store passwords in plain text, check the public settings of cloud storage and databases, and monitor for bulk data retrieval.

It ends with a message to executives: cyberattacks are "no longer just a problem for the IT department". It notes that attack methods, "including the misuse of AI", are becoming more sophisticated, and asks victims to share technical details with the NCO, their ministry or specialist bodies.

IPA: a checklist, and an assessment#

The IPA, the government's IT promotion agency, gives the clearest assessment of what is going on. It says the attacks have not been confirmed as targeting a vulnerability in any particular product or service. From the disclosures so far, they appear to start from the compromise of externally exposed applications and services, or of accounts.

Its urgent checks:

  • Your own exposed applications. List every application and service you built and run yourself. Check their logs for anomalies, such as error volumes or differences from normal, starting with the last month and then the last three months. Apply missing patches.
  • External services you use. List every cloud service, VPN and other external service, including those used by individual departments. Check their logs, and look for accounts that should not exist or that were re-enabled.
  • Your data. Re-check what you hold, and stop holding what you do not need.

Any anomaly should be treated as a security incident, and the IPA "strongly recommends" a detailed investigation by a specialist firm.

Financial Services Agency: stop accepting ID photos early#

The FSA's warning is the one with the most direct consequences for consumers. It notes that recent breaches have leaked customer data "including images of identity documents such as driver's licenses", as in the Times Car case, where images were taken for about 1.6 million accounts.

It asks financial institutions to:

  • Check their cybersecurity, including third-party risk management and incident response, against the NCO warning
  • When verifying customers' identity online, look again for anything unnatural in images of identity documents and of the customer's face
  • Move now to reading the IC chip in identity documents

That last point is the significant one. Under an amendment to the ordinance of Japan's Act on Prevention of Transfer of Criminal Proceeds, the anti-money laundering law, the method of verifying identity by sending images of identity documents will be abolished from April 1, 2027, and identity checks will in principle be unified on reading the IC chip in cards such as driver's licenses and My Number cards. The FSA now asks firms to do this "as soon as possible, without waiting for the effective date".

METI: tell us when you are hit#

METI points companies to the NCO, JPCERT/CC and PPC warnings, and asks for leadership from the top, quick response to vulnerabilities and a move toward zero trust. It also asks companies in the sectors it oversees to report incidents promptly to the relevant METI division, with a timeline, the damage and the type of attack. It promises not to publish the information without consent, but may share it with the NCO, with the company's agreement.

MIC and the police#

MIC passed the NCO's warning to the companies and industry groups it oversees. The National Police Agency's bulletin asks the public not to click links in emails that may be posing as a breached company, not to reuse passwords, and to install anti-fraud apps that block scam calls. It also asks businesses that verify customers' identity to do so thoroughly under the anti-money laundering law.

Our analysis#

The agencies agree on the cause#

The IPA says no single product is behind the attacks. JPCERT/CC describes attackers probing each target for whatever works, including APIs. A security research center's analysis found the same. The NCO lists web vulnerabilities, supply chains and weak data management. Read together, the message is consistent: this is not a patch-one-product problem. Every company with something exposed to the internet has to check its own applications.

Requests, not rules#

None of these documents changes the law. They are warnings and requests, and the PPC's revised security guidance will not take effect until next April. The new Active Cyber Defense law, in force since October 1, requires incident reporting only from operators designated under the Economic Security Promotion Act in sectors such as energy, transport, telecommunications and finance. Most of the consumer services hit this autumn are not covered. For now, what changes depends on whether companies act on the requests.

The ID photo problem#

The FSA's request deals with the part of this wave that will last longest. A password can be changed. A driver's license image cannot. Online identity checks that rely on a photo of an ID document and a selfie have been widely used in Japan, including for opening bank and securities accounts. Once millions of license images are in criminals' hands, that method becomes much weaker, and the FSA is in effect telling banks to stop relying on it before the law requires them to. The FSA's warning covers financial institutions only. Other businesses that accept uploaded ID images are not addressed by it.

Sharing is still voluntary#

Several agencies ask companies to share technical details of attacks, and the government has decided to centralize information at the NCO. But as JPCERT/CC noted, technical information is lacking, and most corporate disclosures say little about how attackers got in. Unless companies actually share what they find, the agencies' checklists will remain general.

What this means for readers#

  • If you run online services in Japan, the IPA checklist is the most practical starting point: list your exposed applications and external services, check a month and then three months of logs, and look for accounts that should not exist.
  • If you work in a Japanese financial institution, expect pressure to move to IC chip identity verification now rather than in April 2027.
  • If your license image may have leaked, the change helps over time, but uploaded images are still accepted by many services until then. Watch for accounts or contracts you did not open.
  • If your company is hit, the government is asking you to share technical details with the NCO, your ministry or JPCERT/CC.

Japanese terms at a glance#

Japanese Reading Meaning
国家サイバー統括室(NCO) Kokka Saibā Tōkatsushitsu National Cybersecurity Office, Cabinet Secretariat
関係省庁会議 kankei shōchō kaigi Inter-ministerial meeting
注意喚起 chūi kanki Warning, advisory
犯罪収益移転防止法 Hanzai Shūeki Iten Bōshi Hō Act on Prevention of Transfer of Criminal Proceeds (anti-money laundering law)
ICチップの読取 IC chippu no yomitori Reading the IC chip (in an ID card)
委託先 itakusaki Contractor, outsourcing partner
情報提供に係る協力依頼 jōhō teikyō ni kakaru kyōryoku irai Request for cooperation in sharing information