Japan is currently facing an unprecedented wave of cyberattacks known as ransomware, targeting government institutions, companies, restaurants, retail stores, media groups, and research institutions. This has made 2026 the worst year on record for such attacks. Ransomware is a type of malicious software that encrypts a victim's files or locks their device, demanding a ransom, usually in cryptocurrency, in exchange for the decryption key or access restoration.
According to the Japanese National Police Agency, the latest attack targeted 53 companies in Japan, carried out by the internationally active ransomware group known as "Killin." This group has attacked approximately 4,000 companies worldwide since its inception in 2022. In recent years, common tactics used by scammers have included phishing, which aims to trick users into revealing sensitive information, and ransomware attacks that prevent data access until a ransom is paid.
However, the recent wave of cyberattacks in Japan has been overshadowed by incidents of unauthorized access, where a third party gains entry into a network or system without permission. Attackers obtain login credentials, infiltrate internal networks, and steal or encrypt data. The 53 Japanese victims span various sectors, including manufacturing, services, construction, hospitals, and schools. This has prompted Japanese authorities to urge companies to enhance their vigilance against cyber threats and address system vulnerabilities to prevent the misuse of leaked information.
A total of 604 cyber security incidents were reported between January 1 and October 1, 2026, compared to 593 incidents in 2025 and 644 incidents in 2024. The National Police Agency recorded a record 123 ransomware incidents in the first half of 2026, the highest number since tracking began. This reflects an unprecedented escalation of ransomware attacks in Japan this year.
Although there is no conclusive evidence that artificial intelligence caused the recent attacks in Japan, experts confirm that AI has contributed to an increase in cyberattacks on a broader scale. AI was responsible for a quarter of malicious breaches, a 56% increase from the previous year. The average cost of each breach was $6 million.
In response to the recent cyberattacks, Japanese Deputy Prime Minister Yoshiaki Nakanishi stated that the government is implementing a range of cybersecurity measures, in addition to traditional protective steps for infrastructure. He highlighted proactive measures known as "access neutralization" that can be taken to target and prevent electronic attackers from using their tools.
The new policy focuses on preventing and responding to cyberattacks, enabling the government to effectively collect and analyze communications with other countries to neutralize threats upon detecting signs of a cyberattack. This approach aims to bolster Japan's cybersecurity and protect against the increasing threat of ransomware attacks.
Key points
- Japan has experienced a record 604 cyber security incidents between January and October 2026.
- The National Police Agency recorded a record 123 ransomware incidents in the first half of 2026.
- Artificial intelligence has contributed to a 56% increase in malicious breaches in the past year.