Japan has recently been hit by a series of cyber attacks, with reports of system breaches and personal data leaks from cloud services, car-sharing companies, and railway enterprises. In response to these incidents, Japan implemented an active cyber defense system starting from October 1st, allowing the Self-Defense Forces to proactively access servers suspected of being attack sources under certain legal conditions to eliminate network threats. On October 8th, the Japanese government convened a meeting with 29 organizations to discuss response measures.
According to a report from Reuters on October 9th, statistics from the cybersecurity firm TrendAI show that Japan has experienced a surge in cyber security incidents in the first nine months of 2026, surpassing the total number in 2025. In September alone, there were 86 incidents, an increase of about 18% compared to August and approximately 37% compared to July. It is important to note that these statistics are from the cybersecurity firm and may not represent the total number of cyber attacks nationwide in Japan.
In the corporate sector, cloud service provider IDC Frontier’s IDCF Cloud was hit by ransomware attacks, affecting services in Eastern Japan. Meanwhile, Times Car, a car-sharing service, disclosed that personal data from around 6.6 million accounts may have been accessed by third parties. Additionally, Keio Corporation, a railway operator, also reported ransomware attacks that impacted some of its subsidiary business systems.
These incidents involved system disruptions, unauthorized access, and personal data breaches, with varying methods of attack. The Chief of the Japan National Police Agency, Yoshinobu Kusunoki, stated during a press conference on October 8th that the background and interconnectedness of recent cases are still unclear, and investigations are ongoing.
On October 2nd, Japan’s Defense Minister Taro Kono mentioned that with the enactment of the Cyber Response Capability Enhancement Act and other related laws on October 1st, the Self-Defense Forces have been granted new tasks of network access and neutralization. Kono explained that this authorization enables the Self-Defense Forces not only to protect their own command and control systems but also to address significant cyber attacks facing the country and critical infrastructure by “actively accessing attack source servers to eliminate threats.”
He further announced that the personnel of the Self-Defense Forces Cyber Defense Unit would be expanded to approximately 1,200 by the end of the 2026 fiscal year according to the Defense Force Readiness Plan.
This system allows Japan to proactively intervene in target servers such as attack sources under legal conditions, rather than solely conducting investigations after an attack. However, it is important to note that the attack source server may not always be where the attackers operate, as they could exploit third-party devices that have been compromised.
The National Network Coordination Office within the Japan Cabinet Secretariat convened a cross-departmental meeting on October 8th with participation from 29 organizations, including various central government departments, to discuss the unauthorized access and data breaches that have been occurring successively recently.
Minister for Cybersecurity Shunji Yoshikawa stated during the meeting, “The current situation is extremely urgent, and it is necessary for the government to implement comprehensive measures. Continued cooperation is required from the government, the public, and businesses.”
Measures discussed during the meeting included expedited patching of system vulnerabilities, strengthening multi-factor authentication, and reviewing the information security management of outsourced service providers. On October 9th, the National Network Coordination Office issued a cautionary alert, urging enterprises handling a large amount of personal or sensitive data to enhance protection and prevent data leaks from being misused.
According to a report by Reuters on the 9th, cybersecurity experts have pointed out that artificial intelligence may assist attackers in automatically searching for software vulnerabilities, creating phishing messages, and lowering the technical barriers for launching cyber attacks. However, whether AI was utilized in these specific incidents will require individual investigations.
In the past, Japan has disclosed investigations involving cyber attack organizations with ties to China. In September 2023, the Japan National Police Agency and Cabinet office related to cybersecurity issued a notice stating that BlackTech is a cyber attack organization with connections to China. These attacks have targeted government agencies and enterprises in Japan and the United States.
In January 2025, the Japan National Police Agency released the results of an investigation into MirrorFace, indicating that the organization has been conducting cyber attacks against organizations, businesses, and individuals in Japan since around 2019. Japan’s assessment suggests that these actions primarily aim to steal information on Japan’s security and advanced technologies, and there are suspicions of organized cyber attacks potentially involving China.
However, the Japanese government has not confirmed whether the recent corporate attack incidents are related to each other or disclosed evidence indicating that this wave of attacks is orchestrated by specific countries.
