The Information-technology Promotion Agency said Thursday it will expand Product Security Incident Response Team coordination for Japan’s animation and game supply chain after a string of cloud-credential thefts—including the Visual Arts breach that leaked unreleased master data for the title anemoi—showed how studio portals can become pivot points for wider credential reuse attacks.
What studios reported
Visual Arts disclosed in June that attackers likely stole authentication keys to cloud storage linked to its internal portal, then exfiltrated anemoi assets that appeared on overseas file sites on April 19. The company filed an initial report with the Personal Information Protection Commission on May 11 and warned that customer, applicant, and employee records might also have been exposed.
IPA officials told InfoHandle that at least four other midsize animation subcontractors contacted JPCERT/CC in August with similar patterns: long-lived API keys embedded in legacy wiki pages, shared contractor accounts without step-up authentication, and render-farm schedulers that cached object-storage tokens in plain configuration files.
PSIRT lane the agency is adding
IPA’s existing PSIRT program focused on vendors selling software to government and finance. The new “creative supplier” track adds bilingual intake forms, a 72-hour advisory window for credential-rotation sequencing, and optional bridge calls with cloud providers when keys cannot be revoked without halting active renders.
Participation remains voluntary, but IPA said three platform holders—two domestic cloud resellers and a global CDN—agreed to honor IPA-coordinated rotation tickets when studios supply a police or PPC reference number. That does not guarantee takedowns of leaked assets overseas, but it shortens the window in which stolen keys remain valid.
Why credentials, not zero-days, dominated
Forensic summaries IPA reviewed pointed to password-spray and session hijacking against contractor VPN accounts rather than novel exploits in compositing software. Several studios still allowed password-only logins to asset browsers left over from pandemic remote work.
Attackers reportedly chained portal access to Git mirrors and ticketing systems, then harvested additional secrets—exactly the lateral movement pattern IPA documented in manufacturing PSIRT cases last year. The difference is contractual: animation pipelines involve dozens of freelance vendors with overlapping access to the same episode folders.
Exposure beyond master files
Visual Arts paused new orders on its VA STORE site while it rebuilt monitoring. Other studios told IPA that payroll and casting spreadsheets sometimes sat beside render assets in the same buckets because producers reused folder templates.
IPA is urging producers to segregate personally identifiable information into separate tenants with different keys and to disable legacy SFTP gateways that bypass single sign-on. Insurance underwriters attending an IPA briefing this week said policies are beginning to ask whether studios maintain asset-class inventories—something many still treat as informal spreadsheets.
What vendors must do next
IPA will publish a checklist in October covering multifactor authentication on portals, maximum token lifetimes for render nodes, and logging requirements compatible with the government’s CSIRT taxonomy. Studios that export dailies to overseas partners must document which foreign staff retain keys after a show wraps.
JPCERT/CC will continue to be the primary public-facing coordinator for incidents, but IPA’s PSIRT desk will own vendor outreach when a leak implicates packaged software or managed services sold to multiple studios.
Limits IPA acknowledges
The agency cannot compel overseas hosts to remove leaked footage, and it does not investigate criminal attribution. Its role is operational: help victims rotate credentials without bricking production schedules, and feed anonymized indicators to ISAC peers.
Coordination with police and insurers
IPA said it will not share victim identities publicly but will route cryptographic indicators to the National Police Agency’s cybercrime liaison when studios file criminal complaints. Several insurers now require a PSIRT ticket number before extending business-interruption riders for post-production delays; IPA’s desk will issue those numbers once basic containment steps—key revocation, contractor access reviews—are documented.
Studios that refuse multifactor authentication on asset portals may find coverage limits reduced, according to brokers who attended IPA’s briefing. That market pressure may matter more than fines in a sector where many firms operate on thin margins between hit franchises and delayed seasons.
Timeline for smaller vendors
Freelance compositing houses with fewer than thirty staff can join the creative track through industry associations in Tokyo and Osaka starting in November. IPA will subsidize two hours of remote configuration review per member, focusing on separating dailies from HR folders and on logging exports to personal drives—a habit forensic teams keep finding in incident reports.
For Japan’s creative exporters, the lesson is blunt: the next breach is less likely to be a flashy exploit than a stale key in a contractor wiki. IPA is betting faster coordination beats another summer of master files on anonymous upload sites.







