Tokyo, Oct. 7 (Jiji Press)–Japan has seen a spate of cyberattacks targeting companies that resulted in breaches of personal information. While affected companies are scrambling to pay compensation and prevent recurrences, corporate Japan faces mounting challenges as the widespread adoption of artificial intelligence may be contributing to the spike in cyberattacks. GMO Research & AI Inc., a subsidiary of GMO Internet Group Inc., has announced that unauthorized access hit its questionnaire website “infoQ” and that the names, telephone numbers and other information of 948,498 registered members were compromised. Reward points worth a total of 2.86 million yen held by some of the members were fraudulently exchanged for gift codes for the Amazon.com online shopping website. The GMO side plans to fully compensate the affected members. Discount store operator Mr Max Holdings Ltd. also fell victim to an attack, resulting in the breach of telephone numbers, email addresses and other data of up to 1,735,154 members registered with its apps and online stores. Unauthorized access may have also led to leak of information on about 110,000 Daiwa Securities Co. customers and some 100,000 Citizen Watch Co. customers. At Asahi Kasei Therapeutics Corp., a pharmaceutical unit of chemical maker Asahi Kasei Corp., personal data on roughly 558,700 people may have leaked from its website for medical professionals. Some have said that people are exploiting AI to launch cyberattacks with little human involvement. “Attackers are starting to actively use AI,” Akio Yamaguchi, chairman of the Japan Association of Corporate Executives, or Keizai Doyukai, told a press conference Tuesday. “We are not far from an era in which attacks are carried out by autonomous AI,” Shunsuke Fukuda, an executive at information security firm Trend Micro Inc., said. AI is helping reduce costs needed for cyberattacks, an expert cautioned. Companies face a growing need to ramp up their data management regimes as cyberattacks are increasingly becoming a threat. In an attack on the Times Car vehicle-sharing service, run by an affiliate of Park24 Co., about 6.6 million records of personal information on members over the past seven years, including former members, were compromised. Of the data, about 1.6 million records were identity verification documents. Concerns are growing that copy images of verification documents with facial photos, including drivers’ licenses, may be abused to issue credit cards. The damage at the Times Car service spread because the operator kept data on driver’s licenses and other identity verification documents for an extended period, despite Japan’s personal information protection law requiring businesses to delete personal data without delay once they are no longer necessary. Lists of personal information are actively traded on the highly anonymous dark web. Yuji Kakeya at Macnica Inc.’s security research center said that highly accurate personal information backed by public documents may be sold at higher prices. Corporate managers should lead the efforts to review their companies’ data management regimes, Kakeya said while calling on users to take measures such as checking firms’ privacy policies. “Cyberattacks are not just a problem of companies and organizations,” Japanese cybersecurity minister Toshiharu Furukawa said at a press conference Tuesday, adding, “Measures taken by each individual will help prevent damage.” Warning that not only names and addresses but also passwords, and credit card and driver’s license information may be breached in cyberattacks, he urged the public to use multifactor authentication systems and be careful about suspicious emails and social media information, and not to use the same passwords for multiple services. On Tuesday, Japan’s Financial Services Agency kicked off this year’s Delta Wall cybersecurity exercise for the financial industry. A record 181 financial institutions are taking part in the exercise, set to run until Oct. 22. The drill is aimed at improving financial institutions’ response capabilities at a time when the threat of cyberattacks is increasing due to the emergence of state-of-the-art AI models that are highly capable of detecting system vulnerabilities. Assuming a cyberattack hitting a computer system, participating institutions will confirm steps that need to be taken, including initial response, investigation and analysis of the attack, and work to restore the affected system. “In order to appropriately deal with threats, it is essential to not only strengthen defense measures but also enhance the effectiveness of responses and restoration work in the event of an attack,” Taku Nemoto, parliamentary vice minister at the Cabinet Office, said at the outset of the Delta Wall exercise. END [Copyright The Jiji Press, Ltd.]
