From our other sites
The story
Companies, universities, and government bodies like the Digital Agency have been hit by a string of cyberattacks one after another, with Times Car even suffering a leak of driver’s license data. According to a report by Kansai TV, Japan is reportedly targeted by cyberattacks once every 13 seconds, with AI cited as a driving force behind the growing automation and sophistication of these attacks. On 5channel, opinions split over how to respond — from praise for blocking overseas access and for “analog security” like fax machines and hanko stamps, to voices pinning the blame squarely on China or Russia, to real examples of attacks routed through domestic IPs used as stepping stones.
Image
Personal information leaks caused by cyberattacks have been hitting companies, universities, and even government bodies like the Digital Agency. At Times Car, driver’s license data was leaked.
What exactly is this threat bearing down on us?
Source: ktv.jp / Original article here
What people said
Even if they tunnel through a proxy, it'd still be better than now.
Even just blocking China, Russia, North Korea, and South Korea would cut the numbers down massively.
On top of that, they're hoarding hardware parts like crazy too.
It's pure nuisance.
Do you really want to read my diary that badly? Just read my blog like a normal person!
"Figure it out yourself.
Huh? What happens if your My Number leaks?
It's right there in the terms of service — the government isn't liable. Read it carefully, okay?"
I don't think you should lump together the My Number, which was forcibly assigned to every citizen, with the My Number Card — a voluntary card people applied for after handing over their own photo and personal info (lured in by a few coins of reward points) and agreeing to the Digital Agency's liability waiver.
Even if something like that got bypassed, it's within the bounds of the API spec, so no problem at all.
And this against a country where the Japanese government, under a certain administration, once pushed the outrageous policy of 'promoting technology exchange.'
This isn't ancient history either — that policy dates from the 2000s onward.
That '13 seconds' figure was 'last year's' rate.
It's obviously many times higher by now.
If they left the deposit data untouched but wiped out every trace of corporate loan and mortgage records, they'd probably get hailed as a white-hat hacker lol
Using a VPN to spoof your country before attacking is standard practice.
If it's VPNs, just blocking the VPN providers should take care of it.
The real problem is the machines being used as stepping stones.
When I traced the IP, the suspicious address behind the unauthorized access turned out to be from inside Japan.
That's all I could tell, though — no idea which region, or which company's IP it was.
Tokuryu crew: "Heard you had some gold bars, so here we are~" (tokuryu: Japan's loosely networked, anonymous crime gangs recruited via social media)
Most things don't actually need to be connected to the internet 24/7 anyway.
Digital keys that can't be cracked by brute computing power already exist, you know.
A SoftBank subsidiary's data center got hit, so even companies that market themselves on security get beaten despite using AI.
Worldwide, roughly 10 million IoT devices (security cameras, routers, etc.) are said to be perpetually infected by some botnet (like Mirai) and used as the attackers' bots.
It's China and Russia, so identifying them doesn't mean anything anyway.
Build our own Great Firewall.
Well, Japan basically runs fine on fax machines alone.
Honestly, we could probably get by without cell phones too.
People kept dissing fax-based number verification as inefficient, but since it barely ever leaks, it's come full circle to being the safe option — and not even a waste of time.
Not numbers — hanko (personal name stamps).
Well, embassies around the world still use fax machines, after all.
Background and Key Points of This Debate
The “once every 13 seconds” figure was reported as last year’s data, and several commenters in the thread pointed out that “it must be even higher by now” — a reminder that it’s easy to mistake an annual statistic for the current rate. Most cyberattacks are carried out via IoT devices infected with botnets like Mirai, or through domestic servers used as stepping stones, which means the source IP alone can’t reveal an attacker’s nationality or affiliation. Given this stepping-stone structure, the simple fix floated in the thread — “just block China, Russia, North Korea, and South Korea” — would have limited effect. It’s also worth noting that the My Number system and the My Number Card are two different things: the former is a number compulsorily assigned to every citizen, while the latter is an optional card that individuals apply for and consent to create, with different liability implications in the event of a leak. The thread showed some confusion between the two.
*This article is excerpted and summarized from the 5channel (News Speed+) thread “Japanese Companies and Government Agencies Hit by a Cyberattack Every 13 Seconds — AI Blamed for It.”
Leave a Reply