TOKYO –
Japan is facing a sharp increase in cyberattacks, with experts warning that artificial intelligence is making it easier for criminals to steal and exploit personal information, while the growing sophistication of online fraud is exposing weaknesses in the country’s cybersecurity defenses.
An international hacking group known as Qilin has described Japan as “one of the countries with the weakest computer security in the world,” a claim that reflects growing concerns over the frequency of attacks targeting Japanese businesses and organizations.
Research by Yutaka Sejiyama, assistant director of the Macnica Security Research Center, shows that the number of publicly disclosed incidents involving information leaks caused by cyberattacks in Japan has been increasing since July.
By October 9, the country had already recorded 25 such incidents during the month. If the current pace continues, the monthly total could exceed 70, highlighting the accelerating threat to corporate networks and personal data.
Sejiyama believes AI is playing a significant role in the increase. “Judging from the circumstances, there is no doubt that AI is being extensively used,” he said.
However, the technology being exploited by cybercriminals may differ from familiar consumer AI services such as ChatGPT and Gemini.
According to Sejiyama, attackers are likely using AI models described as “open-weight,” which allow users considerable freedom to customize their operation.
Open-weight models provide access to the underlying parameters that determine how an AI system functions, making it possible to modify or adapt the technology for a wide range of purposes. Although this flexibility supports legitimate research and commercial applications, it can also be exploited to develop tools for cyberattacks.
By contrast, commercial AI services such as ChatGPT generally place greater restrictions on how their systems can be customized and used, providing safeguards intended to limit malicious applications.
The expanding threat is not limited to the initial theft of information. Experts warn that AI is also increasing the value of stolen personal data by making it easier for criminals to combine separate pieces of information and identify opportunities for fraud.
Recently disclosed leaks involving images of driver’s licenses illustrate the risks. Criminals who obtain such information may be able to impersonate victims, apply for loans from consumer finance companies without their knowledge, or make expensive purchases using their identities.
Stolen personal information is also bought and sold on the dark web, a part of the internet accessible through specialized software and frequently associated with illicit marketplaces.
Even information that appears relatively harmless when considered on its own can become valuable when combined with other leaked records.
For example, a criminal who obtains a person’s name and email address may initially have limited opportunities to exploit the information. However, if those details can be connected to another database containing the same person’s name and credit card number, the potential for fraud increases considerably.
Additional records showing travel reservations, booking dates, and passwords for reservation websites can provide criminals with an even more detailed picture of a victim’s activities.
AI is particularly effective at identifying connections among large volumes of fragmented data, allowing attackers to assemble individual records into more comprehensive personal profiles.
This capability also makes it possible to analyze victims’ behavior and determine when fraudulent communications are most likely to appear legitimate.
Rather than sending indiscriminate phishing emails, criminals can tailor messages to match a person’s actual activities and circumstances, increasing the likelihood that the recipient will respond without suspicion.
In September, for example, people who had made genuine accommodation reservations received fraudulent emails containing their actual booking information. The messages instructed recipients to reenter their credit card details or make urgent payments.
Because the emails included legitimate reservation details, recipients could have mistaken them for authentic communications from accommodation providers or booking platforms.
Such incidents demonstrate how stolen information can be used not only for direct identity theft but also to create highly convincing scams that exploit the trust people place in familiar commercial transactions.
With cyberattacks becoming more frequent and personal information leaks increasingly difficult to prevent, experts say individuals need to strengthen the security of their online accounts.
Sejiyama recommends avoiding the reuse of passwords across different services and actively enabling multifactor authentication wherever it is available.
“Naturally, people should not reuse passwords, but it is also effective to actively use multifactor authentication, such as biometric verification or authentication apps, on websites that support it,” he said.
Multifactor authentication requires users to provide an additional form of verification beyond a password, such as biometric identification or confirmation through a dedicated authentication application.
Once enabled, a password alone is no longer sufficient to access an account. Even if login credentials are exposed in a data breach, the additional security requirement can significantly reduce the risk of unauthorized access.
The measure is particularly important as criminals become increasingly capable of linking information obtained from multiple breaches and using it to target individuals through personalized attacks.
The rapid growth of AI-assisted cybercrime is creating a new challenge for Japan’s digital economy, where the security of personal information depends not only on the defenses maintained by companies but also on the precautions taken by individual users.
As attackers adopt increasingly sophisticated technology, experts emphasize that traditional password protection alone is no longer enough, making stronger authentication and greater awareness of information security essential defenses against online fraud.
Source: TBS
Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: newsonjapan.com










