What happened
Japan has been dealing with a burst of cyber incidents, and officials are telling firms to tighten up. The message from Tokyo is to check defenses, including third-party risk and identity verification, while the broader backdrop is that attack-ready AI tools are spreading fast.
Trend Micro says breach reports spiked in September, with 13 cases packed into one day - the most in any single day this year. The drumbeat didn't stop there, and big brands were pulled in, including SoftBank Corp. and Daiwa Securities.
Several cases involved major data exposure. Times, one of the country's largest car-rental operators, said a leak affected 6.6 million members, and that some of the compromised details were extracted from driver's license data. At the Japan Atomic Energy Agency, researchers saw their government-issued identification cards compromised. Rakuten Drive, a cloud storage service, found that photos and documents tied to roughly 15,000 accounts were accessed.
How AI is shifting the balance
AI-enabled, downloadable tools are making attacks cheaper and easier to scale. Gambit Security found that software used this summer to siphon credit card data from e-commerce sites ran about $25.46 per operation on average. At the same time, open-weight AI models that are freely available are getting better.
Yoji Watanabe, Cyber Security Cloud's chief technology officer, said the attacks are becoming chores "even amateurs can carry out." His team's review of unauthorized-access logs indicates AI may be orchestrating multiple attack tools, with people making the calls and handing "the small, tedious tasks to AI." He said evidence of this pattern has risen since September.
Mihoko Matsubara, Chief Cybersecurity Strategist at NTT Corp., noted the recent wave "seemingly aim at stealing personal information rather than causing disruption," and warned that "some actors could try to identify the threshold of Japanese active cyber defense," raising the chance of more damaging attacks ahead.
AI is making attacks cheaper and faster for everyone involved. Market Briefs covers corporate security free every weekday.
The scale and recent history
It isn't just leaks. Japan is seeing ransomware and supply chain compromises too. On Wednesday, SoftBank Corp. unit IDC Frontier disclosed a ransomware incident that has led to disruptions at several client companies.
The uptick is global as well. Check Point says organizations worldwide endured an average of 2,803 cyber incidents per week in September - up 16% from August and 48% from a year earlier. In South Korea, authorities are probing AI use in recent bank attacks, while CrowdStrike's analysis points to a Chinese-built agentic tool called ARTEX being used alongside large language models.
Japan still remembers two major ransomware cases from 2025, including one that crimped beer supplies at Asahi Group. Last week, Japanese outlets said a member of Qilin, the hacker group that claimed responsibility for the Asahi strike, was taken into custody and extradited to Germany. Cisco Talos tallied 90 ransomware victims in Japan during the first half of 2026 and found Python script artifacts suggesting Qilin is leveraging generative AI to extend its reach.
What this means for your money
Finance Minister Satsuki Katayama urged financial institutions on Friday to reassess cybersecurity, and the Financial Services Agency asked companies to scrutinize third-party exposure and be extra careful when verifying users online. Translation: cyber risk is no longer a niche IT problem - it can disrupt operations, dent customer trust, and spill into the real economy. If you own or work at a business, factor in that incidents can mean downtime, remediation costs, and reputational harm. If you're a customer, expect more identity checks and, hopefully, faster breach notifications as companies try to keep pace.
Defense spending by companies is becoming a real cost line. Join Market Briefs free and follow the threat.
