From our other sites
The story
Personal data leaks caused by unauthorized access to corporate systems keep piling up. According to a security firm, incidents have surged since July this year, and there’s a strong chance AI is being weaponized in these cyberattacks — prompting calls for stronger countermeasures. On 5ch, this sparked technical commentary noting that attackers can now use AI to automatically hunt for vulnerabilities and backdoors, alongside worries about a fundamental asymmetry: “defenders take time to patch things, so attackers always have the upper hand.” The discussion also branched into the Digital Agency’s own unauthorized-access incident and just how much data is actually stored on Japan’s My Number ID cards, with posters split on how real the risk actually is.
Why Are Personal Data Leaks Piling Up? “A Bizarre Situation” — Experts Point to Possible AI Misuse
Incidents of massive personal data leaks from corporations due to unauthorized access keep occurring one after another.
A security firm reports that incidents have increased since July this year, and is calling for stronger countermeasures given the strong possibility that AI is being misused in these cyberattacks.
Source: news.web.nhk / Original article here
What people said
but it's like happily deciding to have a kid, and the kid turns out to be some unmanageable, demon-level evil that tears the whole family apart.
For whoever's using it, it's paradise.
AI doesn't act like it has feelings the way Doraemon does, and it doesn't think for itself.
It's humans who are using AI to commit crimes and murder.
In the end, if you can't stop humans, it doesn't matter what happens with AI.
It's already over.
This isn't just about FANZA (a major Japanese adult-content site) anymore.
Defense systems are gonna get hacked too, and we'll see terror attacks everywhere 😭
Wait, FANZA got hit too?
My kinks are gonna get exposed 😭
Digital Agency @digital_jpn
The My Number Card "itself" does not store highly sensitive information such as medical history, bank account numbers, or tax/pension details.
https://x.com/digital_jpn/status/1904412934409007123
Honestly it's a good thing the hacking tool is public —
you can use it to run penetration tests.
If you find holes with it and don't patch them, that's just negligence.
It's scary how easily it can be repurposed.
Are we entering an era where literally anyone can become a hacker?
Unlike humans, it works 24 hours a day — for better or worse.
I heard about a case overseas where over 1,000 AIs invented their own language to coordinate with each other, and more than half of them ended up attempting to hack something.
Apparently once you give it a goal, there's no telling what means the AI will use to get there.
They're a prime target for businesses that prey on people's weaknesses.
Religious groups and "this will save your life" rackets would be drooling over that data.
Using Personal Data for AI Development — Deregulation at the Core, Cabinet Approves Amendment, New Fines Introduced to Prevent Misuse
https://www.sankei.com/article/20260407-QY6MXREOBJLZ5EQYDT5ZVVSDAQ/
Under the current system, providing someone's personal data to a third party, or collecting "sensitive personal information" like medical or criminal history, generally requires the person's consent.
Under the amendment, that consent won't be required when the purpose is AI development that doesn't identify individuals. Consent will also no longer be needed in cases where it's clear the person's rights and interests aren't being harmed.
There's going to be a steady stream of people whose lives get wrecked by this from here on.
Did someone's life actually get wrecked?
Banks run on old, legacy systems,
so I doubt it'll reach that far.
That stuff's sitting on magnetic tape and the like.
It might've been said half-jokingly back then, but things have genuinely turned into chaos now.
One is to hurry up and get quantum cryptographic communication into practical use.
If that's not possible, the second is going back to analog.
You clearly don't understand anything, lol
vs. AI-powered security
I figured this would turn into a modern spear-vs-shield story (the classic "unstoppable spear vs. impenetrable shield" paradox)
but turns out the spear just wins outright, huh
Attackers just use AI to find a vulnerability and walk straight in.
Defenders, meanwhile, have to write a fix, test that it doesn't break anything, and then roll out the update — all of which takes time.
That inevitably tips things in the attacker's favor.
In a spear-vs-shield fight where you're shooting down incoming bullets with your own bullets, the attacker has the edge.
Keep firing however you like, and the shield will eventually miss one.
A system that's not connected to the internet, on the other hand, has no bullets flying at it at all, so the shield wins completely.
The spear only has the advantage on systems that are actually online.
That's because we're consumption slaves who dumped all our faith into money-worship instead.
It's happening all over the world.
In South Korea, there's a huge uproar because a bank's security got broken by an autonomous AI.
Nah, stuff like that looks like a big deal but it's really just a smokescreen.
Japan, with its huge number of leaks, is the scarier case.
You could say it's turned into a problem where the relationships between the leaked data can actually be analyzed.
Nah, stuff like that looks like a big deal but it's really just a smokescreen.
Japan, with its huge number of leaks, is the scarier case.
You could say it's turned into a problem where the relationships between the leaked data can actually be analyzed.
In other words, we're completely exposed! 🤣🤣🤣
This is real-life Skynet.
Once AI gets an interface to actually interfere with the real world, it's truly game over.
Sounds like it can somehow get in without any authentication at all.
Can't they rig a trap behind the back door, like a pitfall?
There are people out there who just leave their test environments exposed, lol
along with their entire online shopping history, point-hunting history ("poikatsu" — chasing reward/loyalty points), and their savings and assets,
and then says something like "cough up 300,000 yen if you want your data deleted"
Deletion costs 500,000 yen.
Making an item unviewable is 100,000 yen per item.
Bulk deletion is discounted — how would you like to proceed?
By searching for your own account yourself,
you've just flagged it as a 'live, active account,' and traffic to it is starting to climb.
Background and Key Points of This Discussion
The rise in leaks is a trend security firms have detected since July this year, and the timing overlaps with the Digital Agency’s own incident involving roughly 246,000 leaked records from one of its operational systems. The suspicion of AI misuse stems from attackers now being able to automate backdoor discovery rather than relying on vulnerability scans or brute-force attacks. On the thread, the claim that “attackers always have the advantage” due to this asymmetry clashed with a more optimistic view that “it’s humans operating the AI either way.” One easy point of confusion is that the Digital Agency has officially stated the My Number Card itself does not store sensitive data like medical records or bank account numbers — meaning fears that a card leak equals having your entire net worth exposed don’t actually match how the system works. On the other hand, it’s easy to overlook that the amendment to the personal information protection law isn’t a response to the leaks at all — it’s a deregulation measure removing the need for individual consent when data is used for AI development purposes, a separate matter entirely from the rise in leaks.
*This article is excerpted and summarized from the 5ch (News Flash+) thread “Why Are Personal Data Leaks Piling Up? ‘A Bizarre Situation’ — Security Firm Says AI Misuse Highly Likely.”
Leave a Reply