JPCERT/CC issued an alert Tuesday that cloned SoftBank corporate SIM provisioning portals are harvesting multifactor authentication tokens from logistics and manufacturing firms rushing October handset refreshes ahead of the extraordinary Diet session travel spike. The kits copy SoftBank’s color palette and Japanese microcopy but host on typosquatted domains registered last week through privacy proxies.

Attack chain

Phishing emails pose as SoftBank enterprise support, claiming “SIM profile updates” must finish before November price adjustments. Links lead to fake portals that request corporate IDs, one-time passwords, and authenticator app codes in a single form—violating real SoftBank flows that separate steps. JPCERT/CC said at least nine companies reported compromised admin accounts; two saw unauthorized eSIM profiles activated for numbers not on their asset lists.

After capturing tokens, attackers register new devices on mobile device management bypass routes meant for break-glass scenarios. SoftBank Corp confirmed legitimate portals never ask for authenticator codes via web forms; callbacks use registered numbers only.

Who is targeted

Mid-sized exporters with 300–800 lines appear most affected—large enough to have self-service portals, small enough to lack 24/7 security operations centers. Attackers scraped contact names from archived press releases and LinkedIn profiles of IT managers. JPCERT/CC noted overlap with fake My Number portal pages the National Police Agency flagged last week, suggesting shared hosting infrastructure.

SoftBank response

SoftBank Corp disabled self-service SIM swaps for accounts that had not enrolled hardware keys by Tuesday evening, forcing manual verification calls. The carrier published SHA-256 hashes of legitimate Android and iOS app builds and asked MDM vendors to block sideloaded clones. Enterprise clients with premium support tiers receive direct account manager calls before any bulk profile change—a step attackers tried to short-circuit with forged manager names.

Mitigation steps

IT teams should push FIDO2 keys to every mobility admin, rotate API keys used for automated provisioning, and search DNS logs for lookalike domains containing “softbank,” “sbiz,” or “sim-portal” strings. JPCERT/CC shared YARA rules for phishing HTML templates; IPA’s ACTIVE monitoring feed will include indicators within 24 hours.

Users must treat urgent SIM emails as suspect during Diet season; verify URLs against bookmarks, not message links. Report suspicious portals to police cyber units and SoftBank’s abuse desk with full headers preserved.

Broader pattern

Japan’s autumn political calendar concentrates travel and temporary line additions, giving criminals predictable pretexts. JPCERT/CC said similar kits impersonated NTT Docomo in August; defense in depth requires separating mobility admin roles from general help-desk resets. Insurers underwriting cyber policies for manufacturers may ask whether SIM portals sit behind zero-trust access after this campaign.