JPCERT/CC coordinated a voluntary sweep this week asking Japan’s regional brokerages to prove on-premise Microsoft Exchange clusters are patched against the September cumulative update, after two midsize firms reported suspicious PowerShell activity in mail gateways that still route customer bonus notices. The request stops short of a binding FSA order, but compliance officers at Monex Group, Rakuten Securities, and SBI Neo Trade told InfoHandle they uploaded attestation forms by Thursday’s deadline because insurers now tie cyber riders to JPCERT checklists.
What triggered the sweep
Neither brokerage named customers affected, and JPCERT has not attributed the activity to a known ransomware crew. What is confirmed: both firms still operate hybrid mail—cloud spam filters in front of legacy Exchange boxes that handle internal routing for settlement desks. Forensic vendors retained by the firms found Web shell paths consistent with unpatched proxy modules Microsoft flagged in August, plus scheduled tasks that would export mailbox rules if left running.
JPCERT’s English advisory page lists the CVE bundle and asks members to run Microsoft’s health checker scripts, then file a one-page summary through the Financial ISAC portal. The sweep explicitly targets firms below the mega-bank tier that lack 24/7 SOCs but still move retail wire instructions during autumn bonus season.
Who is exposed
Retail customers are not being told to change passwords unless their broker sends a direct notice; the immediate risk is internal—compromised mail rules that silently forward wire-change forms to attackers. FSA guidelines already require callback verification for beneficiary changes, but several regional shops still accept scanned PDFs from “branch managers” when call centers are short-staffed on Silver Week shifts.
Cloud-only brokers are outside the sweep, yet many keep one Exchange instance for compliance journaling. IPA’s alert hub mirrored JPCERT’s language for credit unions that share the same architecture through IT vendors.
Retail account holders numbering in the low millions at affected firms are not receiving blanket breach letters because investigators have not tied the PowerShell tasks to confirmed data exfiltration. The FSA nevertheless reminded CEOs that delayed disclosure can trigger administrative letters if logs later show mailbox access; that pressure is why both firms self-reported before completing root-cause analysis.
Patching realities
Exchange patching in trading shops is never a Tuesday-night click. Maintenance windows must avoid T+2 settlement batches and month-end NAV runs. One Kyushu-based firm said it will defer reboots until Sunday after negotiating with a vendor that hosts its journaling VM on the same cluster.
Microsoft’s build-number page shows supported versions; firms on extended support contracts must still prove proxy mitigations if they cannot upgrade before October. JPCERT said it will publish anonymized failure reasons—missing backups, unsigned scripts, or flat network segmentation—so peers can compare without naming victims.
Legal and insurance tail
FSA examiners have not announced onsite visits, but cyber insurance renewals this quarter already ask whether firms participate in JPCERT sweeps. A missed attestation does not void coverage automatically, yet brokers reported underwriters demanding pen-test letters within thirty days if they skip the file upload.
Lawyers caution that voluntary sweeps can become discovery fodder if lawsuits follow a later breach. Still, silence is worse: the two firms that reported logs did so under FSA incident templates that protect good-faith disclosure timelines.
Vendor and MSSP role
Several regional brokers outsource Exchange administration to domestic MSSPs that also serve credit unions. JPCERT asked those providers to submit a single attestation covering all tenants, after one MSSP reported it could not distinguish which customer owned a compromised journaling rule. Providers that missed the Thursday cutoff must file by Monday or face removal from the Financial ISAC’s preferred vendor list—a soft sanction, but one procurement committees notice.
Microsoft’s health checker output is being archived in ticket systems so auditors can compare September results with January’s ProxyLogon-era drills. Security staff said the exercise duplicated work from spring, but bonus season justified a second pass because new hires in settlement desks had not run the scripts themselves.
What customers should do
Until your broker confirms patching, treat any email asking you to “confirm bonus deposit account details” as hostile even if the sender name matches your adviser. Use the phone number on your contract PDF, not a link in the message. JPCERT’s bottom line matches every autumn campaign: attackers know payroll dates; systems must be patched before social engineering starts, not after.








