What happened
Japan’s National Cybersecurity Office issued a nationwide warning, urging government bodies, local authorities and private companies to strengthen their cyber defences. The alert follows a marked increase in cyber incidents during 2026, with Reuters reporting more incidents in the first nine months than in all of 2025, and September alone seeing 86 attacks – an 18% rise from August. Major firms such as Daiwa Securities, SoftBank, convenience‑store chain Lawson and car‑sharing service Times Car have reported breaches, the latter exposing data linked to about 6.6 million customers. Officials highlighted that artificial‑intelligence tools are lowering the barrier for attackers, enabling automated vulnerability scanning, phishing‑message generation and code assistance. While investigations are ongoing, the government is urging organisations to review basic security practices, improve authentication controls and prepare for follow‑on phishing or smishing campaigns.
In early October 2026, Japan’s Digital Transformation Minister Toshiharu Furukawa convened a meeting of ministries and agencies to address a surge in cyber incidents. The National Cybersecurity Office prepared a set of warnings and instructions for government departments, local authorities and private companies, emphasizing the need to review basic cybersecurity hygiene and improve authentication controls.
The warning follows a series of high‑profile breaches. Times Car, a car‑sharing service, disclosed that data linked to roughly 6.6 million customer accounts—including contact details and driving‑license information—had been exposed. Other affected organisations include Daiwa Securities, SoftBank and Lawson, all of which reported unauthorized access to customer data.
Data from Reuters and India Today indicate that Japan recorded more cyber incidents in the first nine months of 2026 than in the entirety of 2025. September alone saw 86 incidents, an 18% increase from August and a 37% rise from July. Separate research cites over 500 attacks so far this year, compared with 473 in 2025.
Japanese officials, citing experts, warned that AI tools are reducing language and technical barriers that previously limited cross‑border attacks. AI can automate vulnerability scanning, generate convincing phishing messages and assist in writing malicious code, making it easier for less‑skilled actors to launch sophisticated campaigns.
Why it matters
The warning signals a shift in Japan’s cyber threat landscape, where AI‑driven tools are amplifying the scale and sophistication of attacks. By lowering technical barriers, AI enables less‑skilled actors to launch large‑scale operations, increasing the risk of identity theft, fraudulent transfers and broader economic disruption. The involvement of high‑profile companies underscores the potential for widespread personal‑data exposure, which can fuel secondary scams. Moreover, the coordinated government response—bringing together ministries, local authorities and the private sector—reflects growing recognition that traditional security measures may be insufficient against AI‑augmented threats. This development also mirrors similar trends in South Korea, suggesting a regional escalation that could influence global cyber‑security policies and industry standards.
The surge underscores how AI is reshaping the cyber threat environment, turning what were once niche, highly technical attacks into more widespread, automated operations. This democratisation of attack capabilities raises the baseline risk for all organisations, not just high‑value targets.
Large‑scale data exposures, such as the Times Car breach, provide attackers with rich personal data that can be weaponised in follow‑on scams, increasing the potential for financial loss and erosion of public trust in digital services.
Japan’s coordinated governmental response may set a precedent for other nations grappling with AI‑enabled cybercrime, potentially leading to new regulatory frameworks, mandatory security standards, or increased funding for AI‑driven threat‑intelligence capabilities.
The parallel rise in South Korea suggests a broader East Asian trend, which could regional cooperation on cyber‑defence strategies and shared intelligence about AI‑assisted attack techniques.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').Why can ethical evaluation not be reduced to one model score?
What to watch next
Watch for further details from Japan’s National Cybersecurity Office on specific AI‑related tactics used in the breaches, as well as any regulatory measures or mandatory security standards that may be introduced. Monitor how Japanese firms adapt their security architectures, particularly regarding multi‑factor authentication and AI‑driven threat‑intelligence platforms. Regional cooperation between Japan and South Korea on AI‑enabled cyber defence could also produce joint initiatives or information‑sharing agreements. Finally, observe whether other governments cite Japan’s warning when formulating their own policies on AI‑assisted cybercrime.
Details of any forthcoming regulations or mandatory security standards issued by Japan’s National Cybersecurity Office.
Adoption rates of AI‑enhanced threat‑intelligence platforms by Japanese enterprises and any reported effectiveness against the new wave of attacks.
Joint cyber‑security initiatives between Japan and South Korea, including information‑sharing agreements or coordinated response exercises.
Potential legislative or policy responses in other countries that reference Japan’s warning as a catalyst for action on AI‑driven cyber threats.