For as long as companies have been collecting users’ personal information, bad actors have endeavored to steal it. Bolstered by the use of tech like spoofing and deepfakes that allow fraudsters to obscure their true identities and AI agents that overwhelm security systems and speed up hacking operations, scammers have become extremely savvy at exploiting companies’ security vulnerabilities to access user data — including in Japan. According to the Digital Agency, these scammers have targeted not only identifying information such as names, addresses, phone numbers and email addresses, but in some cases are able to steal account login information and passwords, credit card numbers and drivers’ licenses.
At a Digital Agency news conference Tuesday, digital transformation minister Toshiharu Furukawa revealed three baseline measures citizens should take to protect themselves from undue cyberrisk. First, users should set unique passwords for each service and avoid reusing passwords across accounts. Furukawa also asked that users set up multifactor authentication, which could include approving a login via a smartphone prompt or inputting a one-time password.
This measure helps users prevent unauthorized logins. Finally, users should be cautious of suspicious emails and social media messages, as there has been a recent increase in phishing incidents in which scammers impersonate real companies or even government agencies. A 2025 survey by the National Police Agency of companies, educational institutions, medical institutions, local governments, independent administrative agencies and special corporations found that 40.6% of respondents had been sent suspicious emails, including phishing emails, over the previous year — the most common type of cyberattack reported.
However, by thoroughly implementing basic security measures, many of these incidents can be prevented,” Furukawa said.
Extract — continue reading at the source.