Friday, Oct 9 | --:--
Back to home

Japan's Cyber Office Asks Companies to Treat Security as a Management Issue After a Run of Data Breaches, Citing AI Misuse

On Oct. 9, Japan's National Cybersecurity Office in the Cabinet Secretariat asked businesses that hold large volumes of personal or sensitive data to tighten security quickly, after multiple breaches in which data was stolen through web-system vulnerabilities, supply chains and weak data management. Its notice asks executives to treat cybersecurity as a management issue, with investment and staff, "as cyberattack methods, including the misuse of AI, become more advanced." It is a request, not a law. A ruling-party cybersecurity panel met the same day; its head called the situation "an emergency in cyberspace," according to Nikkei.

Times of AI Desk 4 min read Tokyo View as Markdown
Cover illustration for Japan's Cyber Office Asks Companies to Treat Security as a Management Issue After a Run of Data Breaches, Citing AI Misuse

Japan's government has told companies that a string of data breaches is now a boardroom problem, not just an IT one. On October 9, the National Cybersecurity Office (NCO) in the Cabinet Secretariat (内閣官房国家サイバー統括室) published a four-page notice asking businesses, especially those holding large volumes of personal or sensitive information, to "promptly consider" tightening their defences. Kyodo News reported that the request went to companies nationwide through the relevant ministries.

What the notice says

The NCO says it has confirmed multiple cases in which the systems of businesses handling large amounts of personal data were broken into and data, including personal information, was stolen. It names three routes: exploited vulnerabilities in web systems, compromises through supply chains, and data management that lacked robustness.

Its checklist covers three areas:

  • Web systems: apply security patches promptly, stop using unsupported products, run regular vulnerability assessments, introduce multi-factor authentication, keep and monitor logs, and prepare incident response, on the assumption that internet-facing systems "could be attacked at any time."
  • Supply chains: check contractors' security, write breach-reporting duties and access controls into contracts, and give contractors only the data they need.
  • Data: know what information is held, delete what is no longer needed, encrypt stored data, limit access rights, and review access logs for signs of intrusion.

The notice closes with the line that frames the rest: damage from cyberattacks "is no longer a problem for the IT department alone," and, "as cyberattack methods, including the misuse of AI, become more advanced and sophisticated," executives are asked to position cybersecurity as a management issue and strengthen measures, including necessary investment and staffing. Organisations that are hit are asked to share technical information quickly with the NCO, the ministries that oversee them, or specialist bodies.

The document is a request (お願い), not a new legal obligation.

Who else spoke

  • Ministers: Cyber security minister Toshiharu Furukawa said attack methods "are becoming more sophisticated by the day" and countermeasures need updating, Nikkei reported. Trade minister Ryosei Akazawa said his ministry would alert companies broadly through industry groups.
  • The ruling party: The Liberal Democratic Party's national cybersecurity strategy headquarters met the same day and called for stronger public-private coordination, including a response to increasingly capable AI, per Nikkei. Its head, former digital minister Masaaki Taira, called the situation "an emergency in cyberspace." Seoul Economic Daily, relaying Kyodo, quotes Taira as saying recent attacks have taken on the character of "saturation attacks," in which AI is used to repeat assaults automatically at massive scale.
  • The IPA: Japan's Information-technology Promotion Agency issued its own alert, saying the attacks have not so far been tied to a vulnerability in any specific product or service, and that published cases suggest compromised internet-facing applications, services and accounts as starting points.

The breaches behind it

Seoul Economic Daily reports that about 6.6 million items of user personal data at Times Car, the country's largest car-sharing operator, were exposed in a cyberattack, and that Daiwa Securities and convenience-store chain FamilyMart also reported leaks. Japanese security authorities are investigating who was behind the incidents, the methods used and any links between them, the paper says. Bloomberg summarised the government's move as a call for security checks "as AI tools lower the barriers to large-scale hacking."

The AI link is how the LDP's Taira, Seoul Economic Daily and Bloomberg frame the wave; the NCO's own notice lists AI misuse as part of a general rise in attack sophistication and does not attribute any named breach to AI. No perpetrator or method has been published.

Limits

  • Quotations from the NCO notice, Kyodo, Nikkei and the IPA are Times of AI translations from Japanese.
  • Seoul Economic Daily's article is labelled as AI-translated from Korean and relays Kyodo; its quotes from Japanese sources may not match the original wording. Taira's "saturation attacks" remark comes only from that relay.
  • Bloomberg's report was seen only as its headline and summary.
  • The Times Car, Daiwa and FamilyMart details come from Seoul Economic Daily; the companies' own notices were not checked.

Sources

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading