National Police Agency Commissioner Yoshinobu Kusafuka used his Thursday briefing to press companies and households on password hygiene after a compromised Nikkei employee account blasted out roughly 9,000 phishing messages and car-sharing service Times Car disclosed a leak affecting up to 6.6 million members.
Two incidents, one warning
Nikkei said an unauthorized party accessed a Microsoft 365 mailbox and mailed malicious links to staff and outside sources on Sept. 30. Times Car, meanwhile, lost driver-license images and other personal data in a breach that has regulators asking whether identity checks at financial institutions held up.
Kusafuka said police are advancing investigations but cannot yet link the cases. He asked lenders and fintech apps to tighten know-your-customer steps so stolen licenses cannot open accounts.
Basics the NPA wants repeated
Software updates, unique passwords, and the agency’s recommended call-blocking apps featured in the talking points. For individuals, the message was blunt: do not follow links in messages that mimic breached companies, especially when they ask for card numbers.
Corporate Japan’s year
Early 2026 statistics already showed record ransomware reports and internet-fraud losses. Security vendors say generative tools lower the cost of convincing phishing, making employee mailboxes a priority target. Media and mobility firms are only the latest entries on a long incident list that keeps chief information security officers in permanent incident mode.
Regulator follow-through
The Personal Information Protection Commission has asked both Nikkei and Times Car for timelines on user notification and credit monitoring offers. Financial Services Agency staff joined the chorus on identity verification, reminding banks that driver-license images from the car-sharing leak could surface in synthetic account-opening kits.
