Japan declares cyber space emergency as attacks soar

Japan’s financial services regulator has warned banks not to accept driving licences as proof of identity to open new accounts as the country reels from a series of cyber attacks that have hit rail operators, car manufacturers, karaoke chains and even the police.

The spiralling crisis prompted the ruling Liberal Democratic Party to convene an emergency meeting of the National Cybersecurity Strategy Headquarters on Friday, following reports of hacks at dozens of the country’s leading brands from car rental operator Times Car to convenience store chain Lawson as well as hospitals and other government facilities.

More than 20 major companies from barbecue chains to discounters have reported cyber attacks in recent weeks, warning that tens of millions of pieces of customer data may have been leaked.

The increasing frequency of the attacks has prompted alarm at the highest levels of the Japanese government. Masaaki Taira, head of the NCSH, declared that Japan was in “a state of emergency in cyber space”. Japanese cyber security minister Toshiharu Furukawa said the situation was “extremely critical”.

The spate of attacks followed years of warnings from cyber security experts that Japan’s defences were deficient and that, to cybercriminals, its companies could represent an irresistible trove of poorly defended but highly valuable financial and personal information.

The Financial Services Agency urged lenders on Friday to shift as quickly as possible to accepting only forms of identification containing ID chips such as passports or MyNumber national identity cards, following a data leak at Times Car, whose app held a massive store of digital photos of driver licences.

Experts estimate those images may now be on sale on the dark web for as little as ¥25 ($0.15) each.

Train operator JR East also reported that 1.67mn customer email addresses may have been leaked from its booking system. Data leaks at JR East, local governments and hundreds of other businesses were linked to a ransomware attack disclosed on Thursday by IDC Frontier, a SoftBank Corp subsidiary that provides cloud services.

Cyber security experts believe that Japan is more vulnerable to hackers because its ageing population has led to poor security practices, while companies have lagged behind in digitising their systems.

On a global scale, cyber attacks are rising in frequency and scale as AI lowers the barriers and costs for hackers to carry out more sophisticated attacks. South Korea’s president said this week that there was evidence that AI was used in cyber attacks on banks.

Recommended

Masaki Hiraoka, managing director for north-east Asia at cyber security group Blackpanda, said that while the latest wave of attacks in Japan had not been clearly linked to AI, the technology was making it much easier to carry out attacks that once required considerable time and expertise.

Previously, attackers had to carry out time-consuming investigations prior to launching a full-blown attack, said Hiraoka.

“With AI handling parts of that process, a small number of attackers could examine many more systems. Smaller services that previously weren’t worth the effort could become viable targets,” he said.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论