Japan Orders 1,000 Firms to Harden Cyber Defenses | #ransomware | #cybercrime



Japan’s government spent the first ten days of October 2026 doing something it has rarely done this forcefully: ordering companies, not just advising them, to get their cyber defenses in order. A new critical-infrastructure security framework took effect on October 1, the Financial Services Agency told banks on October 9 to review how they verify customer identity, and the National Cybersecurity Office sent a fresh vigilance warning to every government ministry the same day. The trigger is not abstract. Japan’s National Police Agency confirmed 123 ransomware attacks in the first half of 2026 alone, the highest half-year total since comparable records began in 2020, according to News On Japan.

That statistic sits alongside a string of incidents that have already made headlines on this site, including the ransomware attack on cloud provider IDCF that knocked out service for 495 clients and the surge past 600 AI-fueled cyberattacks tracked in 2026. What is new this month is not another breach disclosure. It is Tokyo’s attempt to turn a year of reactive damage control into a standing legal and operational regime, built on mandatory incident reporting, a public-private threat-hunting council, and direct pressure on regulated industries from the Financial Services Agency and the Ministry of Economy, Trade and Industry (METI).

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

Japan’s New Cyber Rules Take Effect as Attacks Mount

On October 1, 2026, Japan’s Common Cybersecurity Standards for Critical Infrastructure entered into force, according to the National Cybersecurity Office. The standards create a unified security baseline across sectors designated as critical, including notification requirements for systems considered essential to service delivery and mandatory reporting of qualifying cyber incidents on short timelines. Crucially, the regime does not wait for a breach to be confirmed. It also covers precursor events, meaning indicators of compromise and certain attempted intrusions must be reported even when an attack has not yet disrupted anything, according to a legal analysis published by Herbert Smith Freehills.

The scope is broader than a typical breach-notification law. Computing resources that a critical-infrastructure operator obtains through cloud services can fall within the systems it must register and report on, closing a gap that has become increasingly relevant as more essential services run on shared cloud infrastructure rather than owned data centers. That detail matters given how exposed shared infrastructure already proved to be in 2026: the IDCF Cloud ransomware incident disrupted hundreds of downstream clients precisely because they shared common infrastructure with the compromised provider.

The Legal Backbone: Act No. 42 and Active Cyber Defense

The October 1 standards sit on top of legislation passed in May 2025: the Act on Prevention of Harm Caused by Unauthorized Acts against Critical Computers, enacted as Act No. 42 of 2025. That law, paired with the Cyber Response Capability Strengthening Act, commonly described in Japan as the Active Cyber Defense Law, expands what the government is legally permitted to do when it believes a serious cyber threat is underway. It also creates the legal basis for the deeper public-private cooperation that is now rolling out.

This is a meaningful shift in posture. For years, Japanese cybersecurity policy leaned on voluntary disclosure, sector-specific guidance, and after-the-fact investigation by the National Police Agency. The new framework instead gives the state standing authority to look for intrusions before a company even knows it has one, and it obligates designated operators to tell the government about suspicious activity rather than waiting to assess the full scope of damage first.

Inside the New Public-Private Threat-Hunting Council

A new council for public-private cyber cooperation is scheduled to begin operating in October 2026, tasked with facilitating threat-intelligence sharing between the government and private operators, according to Japan’s Growth Strategy documentation. The government’s more ambitious move, however, is planned for fiscal 2027: an expansion of threat hunting carried out jointly with power utilities and telecommunications companies to determine whether attackers have already infiltrated their networks and are sitting there undetected, as reported by Jiji Press via Nippon.com.

The National Cybersecurity Office plans to use intelligence gathered from suspected threats to recreate attacks in a virtual environment, then develop detection methods it can share across the private sector. Japan’s Defense Ministry is expected to support this effort directly, offering to dispatch personnel with threat-hunting expertise drawn from work on Self-Defense Forces information systems to critical-infrastructure operators that request assistance. It is a notable expansion of the military’s role into civilian network defense, something that would have been politically difficult to propose even a few years ago.

Financial Services Agency Cracks Down on Banks

On October 9, Japan’s Financial Services Agency formally called on financial institutions to review their cybersecurity measures, responding to a series of customer-data breaches tied to unauthorized access, according to a report from Jiji Press. Financial Services Minister Satsuki Katayama urged banks and other institutions to strengthen identity verification, specifically calling out the need to properly read data stored on the integrated-circuit chips embedded in identification documents, a detail that points directly at how some of the recent fraud attempts have slipped through weaker manual verification checks.

The FSA’s response is not improvised. It builds on a public-private cybersecurity working group established earlier in 2026 that includes 36 organizations, ranging from Japan’s megabanks and internet-only banks to the Bank of Japan itself, plus the Japanese subsidiaries of Anthropic and OpenAI, according to reporting that cites Reuters. The inclusion of two frontier AI labs in a bank-security working group is itself a signal of how directly AI-enabled fraud and AI-assisted intrusion techniques are now shaping Japanese financial regulation, a theme that runs through the broader wave of attacks tech-insider.org has tracked surpassing 600 incidents in 2026.

METI Asks 1,000 Industry Groups to Check Their Systems

The pressure is not limited to finance and critical infrastructure. METI said it would ask roughly 1,000 industry groups, spanning sectors including automotive and retail, to assess vulnerabilities in their communications equipment and information systems, according to the same Jiji Press reporting carried by Nippon.com. That is a strikingly wide net for a single ministry request, and it reflects a recognition that Japan’s exposure runs through supply chains far beyond the handful of sectors formally designated as critical infrastructure.

The timing lines up with a separate warning the National Cybersecurity Office issued on October 9, instructing government ministries to raise vigilance against cyberattacks that are growing both more frequent and more sophisticated, a directive first reported by outlets including the Associated Press and carried by TechXplore. Taken together, the week of October 5 to October 10 amounts to the most concentrated burst of Japanese cybersecurity policy action in 2026.

The Numbers Behind Japan’s Ransomware Surge

The regulatory push is a direct response to deteriorating numbers. The National Police Agency’s 123 confirmed ransomware attacks in the first half of 2026 mark the worst half-year on record since the agency began tracking comparable figures in 2020, and the total is seven cases higher than the same period a year earlier, according to News On Japan. Thirty-one of those cases hit major companies rather than small businesses. In more than half of all cases, recovery took longer than a month. Nine attacks resulted in a complete suspension of business operations, and losses exceeded 10 million yen in roughly 60% of the incidents tracked.

Japan’s broader data-handling problem compounds the ransomware picture. The Personal Information Protection Commission handled 17,139 reports of personal-data leaks and related incidents involving private organizations in fiscal 2025. Many of those stemmed from administrative mistakes rather than attacks, but more than one-fifth were linked to unauthorized access or other malicious activity, a split that officials and outlets covering the figures say illustrates two overlapping problems: chronic weaknesses in how sensitive data is handled, and a separate, faster-growing wave of commercially organized cybercrime.

Double extortion has become the dominant business model behind these attacks. National Police Agency figures for 2024 showed that 111 of 134 ransomware cases in which a payment method could be identified involved double extortion, where attackers steal data before encrypting systems and then threaten to publish it regardless of whether the victim restores from backup. That shift undermines the traditional disaster-recovery assumption that a strong backup strategy is sufficient protection, since the leak threat persists even after systems are restored.

Metric (Japan, 2026) Figure Source
Ransomware attacks, H1 2026 123 confirmed cases National Police Agency, via News On Japan
Cases involving major companies 31 of 123 National Police Agency
Cases with recovery time over 1 month More than half National Police Agency
Cases causing full business suspension 9 National Police Agency
Cases with losses exceeding 10 million yen ~60% National Police Agency
Personal-data leak reports, FY2025 17,139 Personal Information Protection Commission
Share linked to malicious/unauthorized access Over one-fifth Personal Information Protection Commission
2024 ransomware cases involving double extortion 111 of 134 National Police Agency

Case Studies: Asahi, KADOKAWA, and BIGLOBE

Three incidents illustrate why Tokyo moved from guidance to mandate. Attackers breached Asahi Group Holdings’ Japanese network in September 2025 through network equipment at a group location and spent roughly ten days moving through internal systems, largely outside business hours, before activating ransomware on September 29. The disruption went well beyond IT: orders and shipments were delayed, factory operations were affected, some transactions had to be processed manually, and production at Asahi’s six domestic beer factories resumed only gradually, according to the News On Japan account of the incident.

KADOKAWA’s 2024 ransomware attack offered an earlier warning sign. The intrusion disrupted the Niconico video platform and compromised internal file servers run by subsidiary Dwango, eventually exposing personal information belonging to 254,241 people, including employees, former staff, business partners, creators, and job applicants. BIGLOBE, meanwhile, confirmed that more than 5 million email addresses leaked in a separate 2026 incident, including passwords tied to more than 4.6 million accounts, a breach that spread because the affected infrastructure was shared across multiple service providers.

The pattern across all three cases is the same one that shows up in the IDCF Cloud outage, where entire availability zones proved unrecoverable: shared infrastructure and deep, fragmented supply chains mean attackers do not need to breach the strongest target directly. A poorly secured supplier, an unpatched remote-access device, or a vulnerable third-party application can open a route into a much larger network.

Why Critical Infrastructure Is the New Front Line

Power utilities and telecommunications providers sit at the center of the fiscal 2027 threat-hunting push for a simple reason: a successful intrusion there does not just leak data, it can cascade into service outages that touch every other sector at once. That logic mirrors concerns already raised around critical-infrastructure vendors elsewhere in the region, including the maximum-severity Cisco and SonicWall zero-days that landed on CISA’s Known Exploited Vulnerabilities list this year, underscoring that the networking equipment underpinning critical services remains a persistent soft target worldwide, not just in Japan.

Legacy infrastructure compounds the exposure. Japanese companies have traditionally prioritized extending the operational life of physical assets and enterprise systems, an approach that can be efficient in capital-intensive industries but becomes a liability when software, network equipment, and applications remain in service past the point where they can be securely maintained. Independent research cited alongside the National Police Agency figures notes that smaller companies, which often lack the budget to modernize aging systems, account for a disproportionate share of ransomware victims, with manufacturing especially exposed as production, inventory, and logistics systems become more interconnected.

Market and Business Impact: Compliance Costs and Cyber Insurance

For designated critical-infrastructure operators, the October 1 standards translate directly into new compliance spending: registering specified systems with the government, standing up short-notice incident-reporting workflows, and in many cases hiring or contracting dedicated security staff to meet the new notification deadlines. Cloud-hosted systems are explicitly in scope, which means operators that outsourced infrastructure precisely to cut costs may now need additional contractual and monitoring work with their cloud vendors to meet reporting obligations they cannot fully control on their own.

The business-continuity numbers help explain why insurers and boards are paying closer attention. With nine 2026 ransomware cases resulting in a full suspension of operations and roughly 60% of cases crossing the 10-million-yen loss threshold, cyber risk has moved from a line item in the IT budget to a board-level operational risk, a shift that mirrors how cyber insurance markets elsewhere have hardened underwriting standards for ransomware-prone sectors. Japanese manufacturers with deep supplier networks are likely to face more detailed security questionnaires from insurers and larger counterparties alike as a direct result of incidents like Asahi’s.

How Japan’s Approach Compares Internationally

Japan is not alone in moving toward mandatory, short-window incident reporting for critical infrastructure. The European Union’s NIS2 directive and the United States’ Cyber Incident Reporting for Critical Infrastructure Act have each pushed national regulators toward similar obligations in recent years, reflecting a broader international consensus that voluntary disclosure regimes were too slow and too inconsistent to keep pace with ransomware-as-a-service economics. What distinguishes Japan’s October 2026 framework is the explicit pairing of mandatory reporting with state-run threat hunting and direct Defense Ministry support for operators, a combination that goes further than most comparable Western frameworks, which generally separate civilian incident reporting from military or defense-agency involvement.

That difference reflects Japan’s broader security posture shift since the 2022 National Security Strategy first floated the concept of active cyber defense. Where European and American frameworks have largely stayed within civilian regulatory agencies, Japan’s approach explicitly recruits its Self-Defense Forces’ information-systems expertise into critical-infrastructure protection, a step that required new legislation precisely because it blurs a line that Japanese policy has historically kept firm.

Date (2026) Event Source
October 1 Common Cybersecurity Standards for Critical Infrastructure enter into force National Cybersecurity Office
October 1 New public-private cyber cooperation council begins operating Cabinet Secretariat, Japan’s Growth Strategy
October 4 Government outlines fiscal 2027 plan to expand threat hunting with utilities and telecoms Jiji Press / Nippon.com
October 8 National Police Agency H1 ransomware data (123 cases) widely reported News On Japan
October 9 Financial Services Agency urges banks to review cybersecurity measures Jiji Press / Nippon.com
October 9 National Cybersecurity Office issues vigilance warning to government ministries Associated Press / TechXplore

Risks and Criticism of the New Regime

Not everyone welcomes the expanded state role. Mandatory reporting of precursor events, not just confirmed breaches, raises the compliance burden for companies that may now need to report ambiguous indicators of compromise they cannot yet fully assess. There is also a live debate inside Japan’s tech sector over data sovereignty: domestic carriers including NTT and SoftBank have reportedly pushed back on aspects of a “domestic-only AI cyber defense” framing, arguing that walling off threat-detection tools to purely domestic AI systems could slow adoption of more capable foreign models at exactly the moment attackers are using AI to scale their own operations.

The Defense Ministry’s expanded role in civilian threat hunting also raises oversight questions that Japan has not had to answer at this scale before. Giving personnel trained on Self-Defense Forces systems access to private power-grid and telecom networks, even voluntarily, requires a level of trust between operators and the state that will take time to establish, particularly for companies wary of government visibility into their internal network traffic.

What Comes Next: Fiscal 2027 and Beyond

The most consequential piece of this framework, the joint threat-hunting program with power utilities and telecoms, does not formally launch until fiscal 2027, which in Japan begins in April. Between now and then, expect the newly formed public-private council to spend the winter establishing information-sharing protocols, and expect METI’s outreach to the roughly 1,000 industry groups to generate a wave of security self-assessments across the automotive and retail sectors well before the fiscal year turns over.

The FSA’s banking-sector push is likely to move faster, given that Minister Katayama’s October 9 request came with an explicit ask around IC-chip identity verification, a technical fix that banks can implement without waiting for new legislation. Watch for Japan’s megabanks to publish updated customer-verification procedures before the end of 2026.

5 Predictions for Japan’s Cybersecurity Push

  • Mandatory reporting under the October 1 standards will surface more incidents than Japan has historically disclosed publicly, since precursor events now have to be reported even without confirmed damage.
  • The fiscal 2027 threat-hunting program will find at least some dormant intrusions inside power and telecom networks, mirroring what similar hunts have found in other countries’ critical infrastructure.
  • METI’s 1,000-industry-group outreach will expose uneven security maturity between large manufacturers and their smaller suppliers, pushing large companies to impose stricter vendor security requirements.
  • Cyber insurance premiums for Japanese manufacturers and financial institutions will keep rising through 2027 as insurers price in the Asahi- and IDCF-scale business-continuity losses now on the record.
  • Debate over the Defense Ministry’s role in civilian network defense will intensify as the threat-hunting program scales, with privacy and civil-liberties groups pressing for clearer oversight rules.

Frequently Asked Questions

What took effect in Japan on October 1, 2026?
Japan’s Common Cybersecurity Standards for Critical Infrastructure entered into force, introducing notification requirements and mandatory short-window incident reporting for designated critical-infrastructure operators, according to the National Cybersecurity Office.

What is Japan’s Active Cyber Defense Law?
It is the common name for the Cyber Response Capability Strengthening Act, legislation that expands government authority to identify and act on serious cyber threats, working alongside Act No. 42 of 2025, which governs mandatory incident reporting for critical computers.

Why is Japan’s Financial Services Agency pressuring banks right now?
The FSA acted on October 9 after a series of customer-data breaches tied to unauthorized access, asking financial institutions to review cybersecurity and strengthen identity verification, including proper reading of IC chips on identification documents, according to Jiji Press.

How many ransomware attacks hit Japan in 2026?
Japan’s National Police Agency confirmed 123 ransomware attacks in the first half of 2026 alone, the highest half-year total since comparable statistics began in 2020, according to News On Japan.

Which companies are part of Japan’s public-private cyber working group?
The Financial Services Agency’s working group includes 36 organizations, including Japan’s megabanks, internet-only banks, the Bank of Japan, and the Japanese subsidiaries of Anthropic and OpenAI, according to reporting that cites Reuters.

What role will Japan’s Defense Ministry play in cyber defense?
The Defense Ministry is expected to offer direct assistance to critical-infrastructure operators that request it, including dispatching personnel with threat-hunting expertise drawn from Self-Defense Forces information systems work.

What is double extortion and why does it matter for Japanese companies?
Double extortion is when attackers steal data before encrypting a victim’s systems, then threaten to leak the stolen data regardless of whether ransom is paid or backups are restored. National Police Agency figures for 2024 found 111 of 134 identifiable ransomware payment cases involved this tactic.

When does Japan’s threat-hunting expansion for utilities and telecoms begin?
The government has outlined plans to expand joint threat hunting with power utilities and telecommunications companies starting in fiscal 2027, which begins in April next year, according to Jiji Press.

Related Coverage

Marcus Chen

Gaming & Consumer Tech Editor

Marcus Chen is a senior editor at Tech Insider, where he leads coverage of the US online gaming market, including sweepstakes and social casinos, alongside consumer technology. He evaluates operators on their published terms, licensing and RNG certifications, stated redemption policies, and corroborating independent reporting, and writes plainly about what the evidence supports. Tech Insider does not run first-party money tests and does not gamble with reader funds. Marcus has reported on the technology and online-gaming industries for more than a decade.

View all articles



Source link

...........