Local Chorus
Noticias locales de fuentes locales, en tu idioma.

Translating into Español. The English version is shown until it is ready.

Disputada

Experts divided on AI's role as Japanese firms report wave of data breaches

🇯🇵 Japón 08:53 TI y software Tecnología2 Comunidad actualizado hace 21 h primera información de Yahoo!ニュース

En breve

Since late September, Japanese companies have announced a run of unauthorised access and data-leak incidents, including Times Car Share and Yakiniku King. Cybersecurity experts told tech outlets that AI's role in the attacks themselves appears limited, while one says the clustering of disclosures may reflect reporting timing rather than a single campaign. Researchers also report a sharp rise in published software vulnerabilities.

Leer la noticia completa 2 min de lectura

Since late September, Japanese companies have announced a run of unauthorised access and data-leak incidents. ITmedia AI+ and Yahoo News cited leaked driver's licence images at Times Car Share and more than 10 million records leaked at Yakiniku King among the well-known services affected, and said many people may have had their own information exposed. [ 1 , 2 , 3 ]

Two of the incidents were described in detail. Park24 said on September 28 that Times Car's web system was subject to unauthorised access and that information on about 6.6 million accounts was obtained by a third party, ASCII.jp reported. Keio Electric Railway said on September 26 that a group server was hit by a ransomware attack and that some systems suffered outages. [ 1 ]

ASCII.jp also reported a separate trend in software flaws: Google Threat Intelligence Group data showed monthly published vulnerability counts rising from 5,045 in January 2026 to 10,740 in August. Hiroki Takakura, a professor and director of the Strategic Cyber Resilience Research and Development Center at the National Institute of Informatics, told the outlet that AI-driven vulnerability discovery is indeed causing an explosive rise in CVE counts, but that many of the flaws either cause no real harm or were already known and left unaddressed, so risk can no longer be judged by CVE numbers alone. [ 1 ]

On the attacks themselves, Takakura said AI was probably used to automate attacks but did not play a major role, adding that the countermeasures in place were insufficient. [ 1 ]

ITmedia AI+ reported a different emphasis from Hiroaki Kuramochi, director and senior executive officer and CTO at the security firm LAC. Kuramochi said public information does not allow the incidents to be judged as the work of a single attacker or a single attack campaign, and that the concentration of announcements at the end of September largely reflects the timing of companies' investigations and disclosures rather than a sudden surge in attacks. He added that intrusion routes and methods, industries targeted, systems compromised and the scale of damage all differ between cases. [ 2 ]

Kuramochi nevertheless pointed to a common structural change: consumer-facing web services and SaaS platforms used by multiple operators accumulate large amounts of personal data, making them efficient targets, and attackers are combining identity information such as licence numbers and photographs with recent behavioural and authentication data to raise its criminal value. On speculation that advances in AI agents are behind the incidents, he said no public information currently confirms that AI agents or the open model GLM-5.3 were actually used, though he warned that over the medium to long term AI could lower the time and expertise needed to prepare and carry out attacks. [ 2 ]

The Yahoo News item carried the same expert-view summary, attributed to FNN Prime Online, and framed the topic around questions for readers, including what to check when a company announces a breach and which countermeasures matter most. [ 3 ]

Por qué importa

The incidents involve widely used consumer services and shared cloud platforms, so leaked identity documents and personal data could feed fraud and phishing against ordinary users. The expert commentary suggests companies' disclosure timing, not only attacker behaviour, shapes how the wave looks, and that AI may lower the skill barrier for attacks over the medium term rather than driving this run.

Datos clave

  • Park24 said on September 28 that Times Car's web system was subject to unauthorised access and information on about 6.6 million accounts was obtained by a third party. [ 1 ]
  • Keio Electric Railway said on September 26 that a group server was hit by a ransomware attack and some systems suffered outages. [ 1 ]
  • ITmedia AI+ and Yahoo News both cited leaked driver's licence images at Times Car Share and more than 10 million records leaked at Yakiniku King among incidents announced since late September. [ 2 , 3 ]
  • Google Threat Intelligence Group data cited by ASCII.jp showed monthly published vulnerability counts rising from 5,045 in January 2026 to 10,740 in August. [ 1 ]
  • NII professor Hiroki Takakura said AI-driven vulnerability discovery is behind the surge in CVE counts, but not every vulnerability is serious and risk can no longer be judged by CVE numbers alone. [ 1 ]
  • LAC CTO Hiroaki Kuramochi said public information does not allow the incidents to be attributed to a single attacker or a single campaign. [ 2 ]
  • Kuramochi said no public information confirms that AI agents or the GLM-5.3 model were used in these cases. [ 2 ]

Confirmado por varias fuentes

  • Since late September, Japanese companies have announced a series of unauthorised access and data-leak incidents involving well-known consumer services. [ 1 , 2 , 3 ]

Aún sin aclarar

  • Whether AI is driving the recent wave of attacks on companies Experts cited by the two technology outlets are sceptical: professor Takakura said AI's role was limited and the problem was insufficient countermeasures, while LAC's Kuramochi said no public information confirms AI agents or specific AI models were used.
  • Whether the incidents share one attacker or one campaign LAC's Kuramochi said on the basis of currently public information no material shows a single attacker or campaign, and intrusion routes and methods have not been disclosed; this is a single-source assessment, and Kuramochi said public information alone is insufficient to judge.
  • The full scale of the wave, including how many companies and individuals are affected The documents describe individual incidents and say the overall picture emerged gradually, but give no consolidated total.
  • Driver's licence images were among the data leaked from Times Car Share. Reported by a single source so far
  • More than 10 million records were leaked at Yakiniku King. Reported by a single source so far

Qué dicen los medios locales

Medios tecnológicosThe two technology outlets framed the issue as an expert question-and-answer: they listed the recent corporate incidents, then asked researchers whether AI is the cause. ASCII.jp emphasised the surge in published vulnerabilities and professor Takakura's view that countermeasures, not AI, are the weak point; ITmedia AI+ gave prominence to LAC CTO Kuramochi's caution that the incidents cannot be tied to one attacker and that disclosure timing explains the late-September clustering. [ 1 , 2 ]
Comunidad y redesThe Yahoo News item reproduced the expert-view summary, attributed it to FNN Prime Online, and turned it toward readers with questions about what to check after a breach announcement and which countermeasures matter most. [ 3 ]

Cronología, hora local

  1. Keio Electric Railway announces a ransomware attack on a group server that caused outages in some systems. [ 1 ]
  2. Park24 announces that Times Car's web system was subject to unauthorised access and about 6.6 million accounts' information was obtained. [ 1 ]
  3. ASCII.jp publishes an interview with NII professor Hiroki Takakura on the rise in CVEs and the recent attacks. [ 1 ]
  4. ITmedia AI+ publishes LAC CTO Hiroaki Kuramochi's assessment of the incidents. [ 2 ]
  5. Yahoo News carries the expert-view summary, sourced to FNN Prime Online. [ 3 ]