Japan's government has called on companies to strengthen the security of their information technology systems and overhaul their response frameworks, following a string of artificial intelligence-driven cyberattacks and large-scale data breaches.
The government warned that the repeated unauthorized access incidents and personal data leaks of recent months go beyond simple security failures and represent a management risk that can halt business operations, Kyodo News reported on the 9th.
"We ask companies to treat cybersecurity as a core management issue, expand related investment, and put in place specialist staff and response units prepared for incidents," the government said. "When damage from a cyberattack occurs, companies should quickly provide relevant information to the National Cyber Office (NCO) or specialized security agencies to prevent further harm and improve response capabilities."
The ruling Liberal Democratic Party also held a meeting of its national cybersecurity strategy headquarters the same day and urged the government to reinforce joint public-private response systems.
Masaaki Taira, who heads AI policy for the party, said recent cyberattacks have taken on the character of so-called saturation attacks, in which AI is used to automatically repeat assaults on a massive scale. "We need technical countermeasures that can automatically detect anomalies and block the spread of damage after an IT system is breached but before sensitive information is actually leaked outside," he said.
Japan has seen a series of cyberattacks and data breaches targeting major companies in recent months. At Times Car, the country's largest car-sharing operator, about 6.6 million pieces of user personal data were exposed to outside parties in a cyberattack, while Daiwa Securities and convenience store chain FamilyMart also reported data leaks.
Japanese security authorities are investigating who was behind the large-scale unauthorized access cases, the specific methods used and any links between the incidents.