The Moat Was the Language
For years Japan's quietest defence was not a firewall. It was the language: a rich target, held back by a script most foreign attackers never learned. On the 9th of October the government decided awkwardness is no longer armour.
Key · companies amber, places red
Japan's National Cybersecurity Office issued a nationwide warning on the 9th of October. Digital transformation minister Toshiharu Furukawa convened an interministerial meeting the day before. His summary was blunt: the methods are growing more sophisticated, and the impact is no longer hypothetical.
More than twenty companies have reported breaches. Reuters names Lawson, Daiwa Securities and SoftBank; other outlets add BookOff and Times Car, whose leak exposed about 6.6 million accounts. What walked out was ruinous: licence details, addresses, contact records.
The numbers have stopped being flat
TrendAI data reported by Reuters put Japan at 86 incidents in September, up about 18 per cent on August and 37 per cent on July. In nine months it has logged more incidents than in all of 2025. I ran the numbers the headline hides: 473 incidents last year is about 39 a month, so September ran at a little over twice the norm.

The wall was the language
Nobuo Miwa, who runs the Tokyo security firm S&J Corp, gave the wave its image. "AI doesn't get tired," he told Reuters. "My view is that Japan is essentially being subjected to carpet bombing." No clever zero-day required. A machine scans for open doors and drafts phishing in fluent Japanese faster than any human team can answer, and it does not stop for the weekend.
The one concrete case sits next door, in South Korea. CrowdStrike assessed that a suspected 26-year-old, likely in Guangdong province and chasing money, ran a campaign against bank customers with a Chinese pen-testing tool, ARTEX, large language models, and Anthropic's Claude Code. "It allows one human to target many customers in a very short period of time," said Adam Meyers, CrowdStrike's senior vice president of counter-adversary operations.
Interactive · 防壁 · the wall
The moat was the language.
Flip the era. The wall was people; AI changed what a person costs.
Incidents per month3986
A wall of foreign script.The tide learned Japanese.
Illustrative. 39 is Japan’s 2025 monthly average; 86 is September 2026, both from TrendAI via Reuters. Attribution unproven.
What is confirmed, and what is not
Here the story runs ahead of its evidence. Japan has not named an attacker, and in most of these breaches AI is an inference drawn from the shape of the campaign, not a proven fact. The one firm attribution, with named tools and a stated confidence, is South Korean, and even there CrowdStrike says "moderate confidence". AI may also be taking blame for poor patching. What would change my mind is one attributed Japanese case, with the tooling named, not inferred.
The attackers did not get cleverer. They got tireless. The wall was made of people, and people get tired.
The response, and its cost
The advice is basic because the failure is basic: stop reusing passwords, turn on multi-factor authentication, distrust spoofed messages. South Korea's Financial Services Commission ordered a twelve-point self-assessment across its banks. Karen Wu of Fitch expects "regulatory penalties, customer compensation costs, and a sector-wide increase in cybersecurity spending".
The lesson is not that Japan was careless. It is that the wall was never technology. It was effort: translators who were rarely needed, code no machine read quickly, a language that made small jobs too costly to try. AI cut the price on both sides of it. If your firm assumed its language, its size or its distance made it unattractive to attack, that assumption expired this month. The hardening is overdue: email brandon@kreostudio.co.uk.
Readout: what is confirmed, and what is not
- Confirmed (Reuters, the 9th of October 2026): Japan recorded more cybersecurity incidents in the first nine months of 2026 than in all of 2025. September reached 86 incidents, about 18 per cent above August and 37 per cent above July, per TrendAI data.
- Confirmed (AP via The Washington Post, the 9th of October 2026): Japan's National Cybersecurity Office issued a nationwide warning for increased vigilance, days after breaches at major companies.
- Reported (Reuters, the 9th of October 2026): Daiwa Securities, SoftBank Corp and the Lawson chain were among Japanese firms hit; specialists link the wave to AI-automated scanning and phishing.
- Reported (India Today, the 11th of October 2026): BookOff and Times Car reported leaks, the Times Car incident exposing data tied to about 6.6 million accounts. I did not read Times Car's own notice.
- Confirmed (CrowdStrike, via Reuters and The Register, the 8th of October 2026): the suspect in the South Korean bank breaches is likely a 26-year-old in Guangdong, using the Chinese pen-test agent ARTEX with large language models and Anthropic's Claude Code; CrowdStrike states moderate confidence.
- Not confirmed: any attribution for the Japanese breaches, and whether AI was used in most of them. Japan has not named an actor; every claim of Japanese AI use here is inference from the pattern.
Sources & references
- South Korea, Japan buffeted by hacks as AI lowers bar for cybercriminals, Reuters (via The Economic Times), the 9th of October 2026.
- Japan warns for increased vigilance against rising cyberattacks, AP via The Washington Post, the 9th of October 2026.
- South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says, Reuters, the 8th of October 2026.
- CrowdStrike finds possible bank hacker’s CV among exposed AI logs, The Register, the 8th of October 2026.
- Japan declares cyber emergency after hackers expose data of millions of citizens, India Today, the 11th of October 2026.
- South Korea bank hack suspect may be 26-year-old in China, U.S. firm says, The Japan Times, the 8th of October 2026.
Reader signal
Was this useful?
Work with KREO Studio
AI engineering, data science and design architecture, from Plymouth to the wider UK.
Next Article
