Japan urges companies to strengthen cybersecurity response
Japan’s government called on companies to strengthen IT security and overhaul how they respond to cyberattacks. It said the risks could be severe enough to halt business operations.

Key takeaways · 4
- 01
Make cybersecurity a management priority and review investment, specialist staffing and incident-response arrangements.
- 02
If an attack causes damage, the government wants companies to share relevant information quickly with the National Cyber Office or specialist security agencies.
- 03
Prepare technical measures to detect anomalies and limit damage spreading after a breach, before sensitive information leaks.
- 04
Times Car says identity-verification documents leaked from about 1.6 million accounts; it is contacting affected members and warns customers about impersonation attempts.
Cybersecurity becomes a management issue
Japan’s government called on companies to strengthen the security of their IT systems and overhaul their response frameworks.[1] It said a cyberattack could pose a risk severe enough to stop business operations.[1] Its requests included treating cybersecurity as a core management issue, expanding investment, and putting specialist staff and incident-response units in place.[1] These are calls for organizational readiness as well as technical safeguards: companies reviewing their plans can consider whether security responsibilities, dedicated expertise and incident response have clear management support.
Attacks and response priorities
Recent attacks resembled saturation attacks in which AI automatically repeated assaults at massive scale.[1] The evidence does not specify how many attacks occurred or quantify their frequency. The government said technical measures were needed to detect anomalies and stop damage from spreading after a system breach but before sensitive information leaked.[1] It also asked companies to quickly share relevant information with the National Cyber Office or specialized security agencies when an attack causes damage.[1] The stated goals were to prevent further harm and improve response capabilities.[1] For teams, the combined message is to plan for detection, containment and communication, rather than treating these as separate concerns.
Reported data leaks raise the stakes
Times Car said about 6.6 million pieces of user personal data were exposed to outside parties in a cyberattack.[1] In a separate report, the company said identity-verification documents had leaked from about 1.6 million accounts.[3] Those documents included driver’s-license images, address-verification documents, student IDs and family-verification documents.[3] Daiwa Securities and FamilyMart also reported data leaks.[1] Japanese security authorities are investigating the perpetrators and methods behind large-scale unauthorized-access cases.[2] The reported figures distinguish data pieces from affected accounts; they should not be treated as the same measure.
Customer communications and next steps
Times Car said it had begun emailing members whose identity-verification documents were confirmed leaked.[3] Its third report was dated September 29, 2026, and marked updated October 1, 2026.[3] The company said it would provide more details in about two weeks, after receiving results from an external specialist investigation.[3] It warned customers to be cautious of emails, texts and calls impersonating the company.[3] Times Car said it does not ask customers for passwords or credit-card information by email, text or phone.[3] Customers and support teams can use that stated warning when checking whether a message is genuine.
The government’s requests connect cybersecurity investment and staffing to business continuity, incident handling and information sharing. For professionals, the reported leaks also make it important to distinguish verified company communications from potential impersonation attempts.
Why it matters
Test yourself on this story — 1 question.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
11 October 2026
Japan urges companies to strengthen cybersecurity response
Sources
- Japan Urges Firms to Boost Cybersecurity as AI-Driven Attacks Surge - Seoul Economic Dailyen.sedaily.com
- Japanese firms hit by AI-exploiting cyberattacks as Tokyo orders security overhaul - The Herald Businessbiz.heraldcorp.com
- 「タイムズカーWebシステム」への不正アクセスに関する調査結果および今後の対応について(第3報)※追記あり | カーシェアリングのタイムズカー(旧:タイムズカーシェア)share.timescar.jp