The Financial Services Agency asked major banks to tighten timelines for reporting unauthorized transfer attempts after a spike in autumn phishing sites that cloned lender login screens and one-time-password flows.
Unlike the wholesale customer-data breaches roiling South Korean lenders this month, Japan’s immediate pain is social engineering: criminals send SMS links that resemble parcel-delivery notices, then harvest net-banking credentials. Regional banks in Kansai and Chubu reported double-digit weekly increases in call-center reports of unauthorized transfers compared with August baselines.
Reporting lag hurts recovery
Current guidance gives institutions up to several business days to file certain unauthorized-transfer aggregates to regulators. The FSA’s Monday circular, described in summaries circulated to compliance officers, pushes for same-day tallies on incidents above ¥1 million and faster handoffs to the National Police Agency’s cybercrime unit when attackers move funds through multiple domestic accounts within hours.
Consumer groups argue that faster reporting only helps if telcos simultaneously block freshly registered domains. Mobile carriers have cooperated on nuisance-call labeling, but SMS filtering remains inconsistent across budget handsets popular with elderly users.
What account holders should do
Banks reiterated that they never ask for card PINs via text and that genuine security upgrades route customers through official apps, not shortened URLs. Police advisories recommend freezing transfers through the nationwide transfer-stop hotline when a suspicious login occurs, even before balances are debited.
With the Diet debating consumer relief bills, lawmakers from both blocs asked whether phishing losses should qualify for an expanded guarantee fund. The FSA has not endorsed that step, warning it could blunt incentives for banks to harden authentication.
