Japan Hits 600 AI-Fueled Cyberattacks in 2026, Tops 2025 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Japan’s cybersecurity agencies have a number that tells the story on its own: 600. That is how many unauthorized-access incidents Japanese companies and local governments had disclosed publicly between January and the end of September 2026, according to security firm Trend Micro. It already beats the 593 cases logged across the entirety of 2025, with three months still left on the clock. The common thread running through the worst of this year’s breaches, at Times Car, Daiwa Securities, Citizen Watch and a SoftBank cloud subsidiary, is that artificial intelligence is doing work that used to require a skilled human attacker, and doing it faster than most targets can patch.

Tokyo’s government responded this week by convening ministries and ordering companies to treat cybersecurity as a management-level priority rather than an IT afterthought. The wave has also pulled in neighboring South Korea, where banks and a megachurch network were hit by comparable AI-assisted intrusions, feeding a regional narrative that the barrier to large-scale hacking has dropped just as fast as AI capability has risen. Reporting from Bloomberg, Nikkei Asia, NBC News, Semafor and the finance-news outlet Briefs has converged on the same conclusion over the past week: this is not a one-off breach, it is a pattern, and AI is the accelerant.

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

Japan’s 2026 Cyberattack Wave, by the Numbers

Trend Micro’s tally of 600 disclosed incidents through September is the headline figure, but the monthly trend inside that total is what alarmed officials. September alone produced 86 incidents, a roughly 18% jump from August and a 37% jump from July, with 13 breaches logged in a single day, the highest daily count recorded so far this year. That acceleration curve matters more than the raw total, because it suggests the pace of attacks is still climbing rather than leveling off.

Separately, Cisco Talos researchers counted 90 organizations hit by ransomware in Japan during the first half of 2026, up about 4.7% from 86 incidents in the same period a year earlier. Small and midsize firms with capital under JPY 1 billion made up roughly 80% of those ransomware victims, and manufacturing was the hardest-hit sector at 34% of incidents, a pattern consistent with Japan’s dense base of mid-tier industrial suppliers that often run older, less-monitored IT systems. Our earlier coverage of Japan’s record-high ransomware caseload in the first half of 2026 tracked the early stages of this same climb.

Two ransomware crews dominate the Talos data. The Gentlemen was the most active group in Japan during the period, with leak-site listings more than doubling between January and July. Qilin ranked second with seven confirmed incidents, but it is the one researchers flagged for AI use: Talos found Qilin deploying AI-generated Python scripts to automate wipers and disable backup systems, a level of tooling sophistication that previously required dedicated malware developers. Japanese police made an arrest tied to the group this year, detailed in our report on the Qilin ransomware core member caught in Japan, though the arrest has not slowed the group’s broader AI-assisted activity elsewhere.

Who Got Hit: Times Car, Daiwa Securities and a SoftBank Subsidiary

The breach with the largest blast radius hit Times Mobility, operator of the Times Car rental and car-sharing service. The company detected unauthorized access on a Friday morning and says it blocked the access route by the following morning, but in that window attackers reached roughly 6.6 million current and former customer accounts, including about 1.6 million identity-verification documents. Those files included scanned driver’s licenses with personal photographs, utility bills and student ID images, the kind of data that is far more damaging in the wrong hands than a password.

Daiwa Securities and Citizen Watch were hit through a shared point of failure: both companies had outsourced customer inquiry management to the same external contractor, and attackers compromised that contractor’s server. Daiwa disclosed that up to 220,000 customer records were exposed. Citizen said roughly 100,000 people’s personal information was potentially accessed. The shared-vendor pattern echoes what we saw in the Advantest breach disclosed 233 days after the initial ransomware hit, where third-party exposure, not a direct network intrusion, was the opening.

A separate, larger-scale incident hit IDC Frontier, a cloud and hosting subsidiary of SoftBank. Ransomware against IDC Frontier’s infrastructure disrupted services for 495 companies and local governments that relied on its hosting, a scale that pushed it beyond a single-company story into critical-infrastructure territory. Tech-Insider covered the operational fallout in detail, including which of the 495 affected clients lost access to unrecoverable data across four hosting zones. Convenience chain FamilyMart also disclosed a data leak this period, and reporting from the Seoul Economic Daily and Nikkei Asia named Daiwa Securities, SoftBank and Lawson together as companies facing the broader surge in incidents.

How AI Is Lowering the Barrier for Attackers

The mechanism security researchers keep pointing to is speed, not novelty. AI tools do not invent new categories of attack so much as they compress the time between finding a weakness and exploiting it at scale. Recent incidents in Japan have taken on the character of what researchers call saturation attacks, where AI automates the same intrusion attempt across thousands of targets simultaneously rather than a human operator hand-picking one victim at a time. AI has also narrowed the language gap that used to protect Japanese firms somewhat, since attackers no longer need native-level Japanese to craft a convincing phishing lure or navigate a Japanese-language admin panel.

Nobuo Miwa, president of security firm S&J Corp, described the cumulative effect bluntly: “AI doesn’t get tired… My view is that Japan is essentially being subjected to carpet-bombing,” he told the Straits Times. His framing captures why defenders are struggling: traditional security operations assume attackers need rest, resources and specialized skill to mount each new attempt, and AI removes all three constraints at once.

A Dissenting Voice on How Much AI Actually Matters

Not every expert agrees that AI deserves the lion’s share of the blame. Hiroki Takakura, professor and director of the Strategic Cyber Resilience Research and Development Center at Japan’s National Institute of Informatics, told ASCII.jp that “it’s true that CVEs are exploding due to AI-driven vulnerability discovery,” acknowledging the scale effect. But assessing the specific wave of attacks on companies including Times Car and Keio Corporation, he offered a more measured take: “I believe AI was used for attack automation, but it didn’t play a major role. In other words, I think the countermeasures were insufficient.”

That nuance matters for how companies should respond. If AI is the root cause, the fix is largely about detecting AI-generated traffic patterns. If the real problem is years of underinvestment in patching, access controls and vendor oversight, as Takakura suggests, then AI is less a new threat category than a magnifier of existing gaps that boards had been able to ignore until the breach count made that impossible.

Tokyo’s Government Response: Ministries Convene, Warnings Go Out

Japan’s digital transformation minister, Toshiharu Furukawa, convened a meeting of relevant ministries and agencies after the cluster of recent attacks, according to Bloomberg and Nikkei Asia. The country’s National Cybersecurity Office is now preparing formal warnings to businesses, and the government is urging companies broadly to elevate cybersecurity to a management priority, strengthen IT system defenses and overhaul incident-response frameworks rather than treating each breach as an isolated event. The timing lines up with South Korea’s own response to a parallel wave, where financial regulators ordered security checks at banks following a string of AI-linked breaches, a story Tech-Insider tracked in its reporting on South Korea’s probe into AI’s role in bank hacks that exposed 68,000 records.

The Financial Sector Got There First: Claude Mythos and the Pre-emptive Task Force

What makes Japan’s response notable is that part of it predates this specific attack wave. Back in April 2026, Japan’s then-finance minister Satsuki Katayama announced a dedicated financial-sector task force, bringing together the Financial Services Agency, the Bank of Japan, the National Cybersecurity Office, the country’s three largest banks and the Japan Exchange Group. The trigger was not an active breach but a preview of Anthropic’s Claude Mythos model, which reportedly uncovered thousands of previously unknown vulnerabilities across every major operating system and web browser during testing.

Miho Matsubara, chief cybersecurity strategist at NTT, explained why that discovery rattled the financial sector specifically: “Claude Mythos has two significant implications for cybersecurity. First, it is extremely capable of discovering a large number of vulnerabilities in a very short time,” she said, per News on Japan. Banking systems are especially exposed to that kind of capability because they tend to run complex, interconnected and often decades-old technology stacks, where a single newly discovered flaw can cascade into a market-wide disruption rather than staying contained to one institution. As of this reporting, there have been no confirmed breaches directly tied to Mythos itself. Tech-Insider’s earlier deep dive into the model, Anthropic’s Claude Mythos and the $100 million Project Glasswing defense effort, covers how Anthropic itself is trying to get ahead of the same risk the task force was created to manage.

Timeline: Japan’s Named Incidents in the 2026 Wave

OrganizationWhat HappenedScale DisclosedSource
Times Car (Times Mobility)Unauthorized access to customer identity documents~6.6 million accounts, ~1.6 million documents accessedBeinsure, Nikkei Asia
Daiwa SecuritiesContractor server compromiseUp to 220,000 customer recordsNikkei Asia, aiweekly.co
Citizen WatchSame contractor server compromise as Daiwa~100,000 people’s dataNikkei Asia
IDC Frontier (SoftBank subsidiary)Ransomware against hosting infrastructure495 companies and local governments disruptedSBS News, rankiteo.com
FamilyMartDisclosed data leakNot fully disclosedNikkei Asia
SoftBank Corp. and LawsonNamed among firms facing the broader incident surgeNot individually broken outSeoul Economic Daily

Market Impact: Security Stocks Rise as Boards Scramble

The breach wave has already shown up in Japanese equity markets. A note circulated among domestic investors counted 22 personal data breaches disclosed in a single month this year, and tracked roughly ten cybersecurity-linked stocks that climbed as much as 20% as investors bet on increased corporate security spending. That kind of reaction mirrors what happened after the Advantest disclosure and after South Korea’s megachurch hacking cases, where breach headlines translated almost immediately into capital rotating toward security vendors, incident-response firms and managed detection providers.

For the companies on the losing end, the cost is less visible but larger. Beyond regulatory fines and customer notification costs, firms like Daiwa Securities and Citizen now face the slower-moving expense of re-auditing every third-party vendor with access to customer data, a process that was already underway industry-wide before this wave but is now accelerating under board pressure. Cyber insurers are watching closely too, since a cluster of AI-accelerated breaches across one country’s mid-cap industrial base is exactly the kind of correlated risk that insurance pricing models have historically struggled to price.

Japan vs. South Korea vs. the Global Ransomware Picture

MetricJapan (2026)Comparison Point
Disclosed incidents, Jan-Sep600 (Trend Micro)593 for all of 2025
Ransomware victims, H190 organizations (Cisco Talos)86 in H1 2025, up ~4.7%
September monthly incident count86 incidentsUp ~18% from August, ~37% from July
Single-day incident peak13 breaches in one dayHighest daily count of 2026 so far
Most AI-linked ransomware groupQilin, 7 incidents, 2nd most activeThe Gentlemen led overall, listings doubled Jan-Jul
Regional parallelSouth Korea banks and megachurch networks hit68,000 records exposed in one bank-hacking probe

Historical Context: From Human-Paced Hacking to Machine-Paced Saturation

Japan has dealt with major corporate breaches before this year, including incidents at Aflac Japan and other large insurers and manufacturers. What distinguishes 2026 is cadence. A decade ago, a sophisticated attack against a company the size of Daiwa Securities or SoftBank required a dedicated team, weeks of reconnaissance and bespoke malware. The data from Cisco Talos and Trend Micro this year shows that same class of attack now running on a near-daily cadence against targets ranging from top-tier financial institutions down to manufacturing subcontractors with a handful of employees. That shift from occasional, high-effort intrusions to constant, low-effort saturation attempts is the real break from prior years, and it is why Japanese officials are treating 2026 as a turning point rather than a bad quarter.

Competitive Landscape: How Vendors and Regulators Are Responding

Security vendors are repositioning quickly around the AI-attack narrative. Detection platforms are marketing their ability to spot AI-generated attack patterns specifically, rather than just signature-based malware. Cisco Talos has leaned into public research reports naming specific groups like Qilin and The Gentlemen, a transparency move that puts pressure on affected companies to disclose faster. Meanwhile, Japan’s financial-sector task force represents a regulatory approach that other countries are likely to copy: rather than waiting for a breach, it tries to pressure-test AI models against the sector’s own infrastructure before attackers do. That mirrors some of what Tech-Insider has covered in Anthropic’s own defensive research spending, and it stands in contrast to the more reactive, breach-driven regulatory posture seen in the United States and the European Union so far this year.

Why Mid-Sized Manufacturers Are the Weak Link

The Cisco Talos finding that SMEs with under JPY 1 billion in capital made up 80% of ransomware victims deserves more attention than it has gotten. Large firms like Daiwa Securities or SoftBank have dedicated security teams and incident-response budgets, even when a contractor’s weak link still lets attackers in. Mid-tier manufacturers and suppliers typically do not. As AI tools make reconnaissance and exploit generation cheap, attackers have every incentive to target the weakest, most numerous link in Japan’s industrial supply chain rather than fighting through a bank’s defenses directly.

Predictions: Where This Goes Next

  • Japan’s 600-incident pace through September will likely push the full-year 2026 total well past 800, based on the accelerating month-over-month trend Trend Micro has logged since July.
  • Expect more joint regulatory task forces modeled on the financial sector’s April 2026 initiative, likely extending into healthcare and logistics, two sectors with the same mix of legacy systems and high-value personal data.
  • Vendor consolidation around AI-pattern detection will accelerate, with Japanese buyers favoring platforms that can demonstrate specific Qilin- or Gentlemen-style detection rather than generic AI-security marketing.
  • Pressure will grow on outsourced contractors like the one that exposed both Daiwa Securities and Citizen Watch, with large enterprise clients likely to demand independent security audits of any vendor touching customer data.
  • South Korea and Japan’s parallel attack waves will likely drive closer intelligence-sharing between the two countries’ cybersecurity agencies, given how similar the AI-saturation pattern has looked in both markets this year.

What Companies Should Be Doing Right Now

The practical response coming out of this wave is less about deploying a specific AI-detection product and more about closing the gaps Takakura flagged. That means accelerating patch cycles for internet-facing systems, since AI-driven vulnerability discovery erases the grace period companies used to have between a flaw becoming public and an attacker weaponizing it. It also means auditing every third-party contractor with data access, given that Daiwa Securities, Citizen Watch and Advantest were all compromised through vendor relationships rather than direct network intrusions. Finally, it means treating backup systems as an active attack target rather than a passive safety net, since Qilin’s AI-generated tooling was specifically built to disable backups before encrypting production data, a tactic that turns a routine ransomware incident into an unrecoverable one.

Frequently Asked Questions

How many Japanese companies have been hit by cyberattacks in 2026?

Trend Micro counted 600 publicly disclosed unauthorized-access incidents affecting Japanese companies and local governments between January and the end of September 2026, already surpassing the 593 cases recorded across all of 2025.

Which major Japanese companies were breached in this wave?

Confirmed incidents hit Times Car (about 6.6 million customer accounts), Daiwa Securities (up to 220,000 records), Citizen Watch (about 100,000 records), SoftBank’s hosting subsidiary IDC Frontier (495 affected companies and local governments) and convenience chain FamilyMart, with SoftBank Corp. and Lawson also named among firms facing the broader surge.

Is AI actually causing these cyberattacks, or just making them faster?

Experts are split. Security firm president Nobuo Miwa describes a “carpet-bombing” effect from AI-driven automation, while Professor Hiroki Takakura argues AI mainly automated attacks that succeeded because underlying security countermeasures were already insufficient. Most researchers agree AI compresses the time between vulnerability discovery and exploitation, even if it isn’t creating entirely new attack categories.

What is Claude Mythos and why does it matter here?

Claude Mythos is an Anthropic AI model that, in preview testing, reportedly surfaced thousands of previously unknown vulnerabilities across major operating systems and browsers. Japan’s Finance Ministry cited that capability when it set up a financial-sector cybersecurity task force in April 2026, months before the current attack wave, as a pre-emptive move rather than a reaction to a Mythos-specific breach.

Which ransomware groups are most active in Japan right now?

Cisco Talos identified The Gentlemen as the most active ransomware group in Japan during the first half of 2026, with leak-site listings more than doubling from January to July. Qilin ranked second with seven incidents and was specifically flagged for using AI-generated Python scripts to disable backups and deploy wipers.

How has Japan’s government responded?

Digital transformation minister Toshiharu Furukawa convened a meeting of relevant ministries and agencies, and the National Cybersecurity Office is preparing formal warnings to businesses. The government is urging companies to elevate cybersecurity to a board-level management priority and overhaul incident-response frameworks.

Are smaller companies more at risk than large corporations?

Yes. Cisco Talos found that small and midsize enterprises with capital under JPY 1 billion accounted for roughly 80% of ransomware victims in Japan during the first half of 2026, with manufacturing the hardest-hit sector at 34% of incidents, reflecting weaker security budgets and older IT infrastructure at smaller firms.

Is this pattern happening outside Japan too?

Yes. South Korea experienced a parallel wave of AI-linked attacks in 2026, including breaches tied to bank hacking investigations and megachurch networks, prompting Korean regulators to order security checks at financial institutions in response.

Related Coverage

Sofia Lindström

Editor-in-Chief

Sofia Lindström is the Editor-in-Chief at Tech Insider, where she leads editorial strategy and oversees coverage across AI, cybersecurity, and enterprise technology. With over a decade in Swedish tech journalism, she previously served as technology editor at Dagens Industri and covered the Nordic startup ecosystem for Breakit. Sofia holds an MSc in Media Technology from KTH Royal Institute of Technology and is a frequent speaker at Web Summit and Slush. She is passionate about making complex technology accessible to business leaders.

View all articles

——————————————————–


Click Here For The Original Source.

.........................