AIセキュリティ

Hit by a Cyberattack in Japan? First Steps for Individuals and Companies

Published2026-10-04Ryuta Hamamoto

In late September and early October 2026, several major South Korean banks disclosed cyberattacks. If the same happened in Japan, what should customers and companies do first? Working from primary sources, this article covers self-reporting to Japan's three credit bureaus, police and consumer hotlines, the deadlines for breach reports to the Personal Information Protection Commission, and reporting under Japan's new active cyber defense law.

Hit by a Cyberattack in Japan? First Steps for Individuals and Companies
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. Between September 30 and October 3, several of South Korea's largest banks disclosed cyberattacks one after another. Shinhan Bank reported that data on about 25,000 customers had leaked, and KB Kookmin Bank, Hana Bank and BNK Busan Bank confirmed leaks of their own. Woori Bank and NH NongHyup Bank were reported to have been targeted as well, and Korean newspapers ran headlines about "six banks." These are the banks people in Korea use every day for salaries and mortgages.

This piece asks one question: if the same thing happened in Japan, what should we do first? On September 30 I published Part 1 and Part 2, which covered prevention, from how companies should hold ID documents to how to protect PCs and endpoints. This time the focus is on what happens after an incident. I wrote it for two readers: individuals who use banks and online services, and owners, IT leads and general affairs managers at small and mid-sized companies.

The procedures and hotlines below are Japanese ones, described as they work under Japan's rules. If you live elsewhere, the order of steps still applies, but please look up the equivalent channels in your own country.

One more thing before I start. I am not writing this to criticize the Korean banks that disclosed these incidents. Publishing the facts and a compensation policy quickly, and contacting the people affected one by one, gives customers time to protect themselves. I describe the Korean government's and regulators' actions as they were announced.

Key points (as of October 4, 2026)

  • Since September 30, 2026, six Korean banks have been reported as targets. Four disclosed data leaks, and customer data was involved at three. On October 2 the Financial Services Commission held an emergency meeting and ordered a review of every system reachable from outside
  • For individuals in Japan, the first moves are to shut the money exits (call your bank and card issuer), change passwords and keep evidence. Hotlines include the police consultation line #9110, prefectural police cybercrime desks and the consumer hotline 188
  • If you are told your ID documents leaked, file a self-report (honnin shinkoku) with Japan's three credit bureaus, CIC, JICC and the Japanese Bankers Association's KSC, without delay. The bureaus share data, but CIC and JICC recommend registering with each one. Online, all three cost ¥2,200 in total
  • Companies must file a preliminary report with the Personal Information Protection Commission "roughly within three to five days" of learning of a reportable leak, and a final report within 30 days (60 days if the leak may have been caused by an act with improper intent). From October 1, 2026, critical infrastructure operators also have reporting duties under Japan's new active cyber defense law
  • What not to do: switch machines off and destroy evidence, pay a ransom on someone's own authority, or publish unverified information as fact

What happened at the six Korean banks

It started with Shinhan Bank. On October 1 the bank posted an apology from its CEO on its website, saying an unauthorized outsider had taken customer data from "some services" using abnormal methods. According to the apology as reported by Yonhap, the leaked data related to loan applications: names, phone numbers, connecting information (CI, an identifier used for identity verification in Korea), annual income and calculated loan limits, covering about 25,000 people. It included 66 resident registration numbers1. Reports said the target was a service for loan brokers2. The Financial Supervisory Service began an emergency on-site inspection the same day1.

On October 2 the damage spread. In an official notice, KB Kookmin Bank said that on September 30 it had confirmed a leak affecting 99 customers and 20 current and former employees. The source was a mobile work-support system for staff, which the bank said has nothing to do with internet banking or other customer transactions3. That afternoon Hana Bank announced a leak affecting 89 people and said it came from abnormal access attempted by an external "hacking agent" against its sales support system (ODS). At BNK Busan Bank, the names and phone numbers of 11 outsourced developers were found exposed on a web page2.

Bank Confirmed / disclosed Who was affected Main data leaked (per the bank) System targeted
Shinhan Bank Confirmed Sept 30, disclosed Oct 1 About 25,000 customers Name, phone number, CI, annual income, calculated loan limit and more; 66 resident registration numbers Service for loan brokers (reported)
KB Kookmin Bank Confirmed Sept 30, disclosed Oct 2 99 customers, 20 current and former staff For customers, up to 17 items including name, mobile number, encrypted unique ID data, income, loan and deposit balances Mobile work-support system for staff
Hana Bank Disclosed Oct 2 89 customers Resident registration number, name, address, email, phone numbers, employer Sales support system (ODS)
BNK Busan Bank Confirmed early Oct 2 11 outsourced developers Name, phone number, date of birth, email Staff mobile sales support system and others (presumed)
Woori Bank Reported Oct 2 No leak found None Blocked by intrusion prevention
NH NongHyup Bank Reported Oct 2 No leak found None Blocked by intrusion prevention

Sources: KB Kookmin Bank's notice3 and Yonhap12. Details for Shinhan, Hana, BNK Busan, Woori and NH NongHyup are the banks' announcements or officials' explanations as reported by Yonhap.

So the "six banks" in the headlines counts the banks that were attacked. Leaks were confirmed at four, and customer data at three. By coincidence, six banks also attended the Financial Services Commission's emergency meeting on October 24. The damage reached beyond banks, too. On October 3 Yegaram Savings Bank disclosed a leak of names, dates of birth and contact details affecting an estimated 40,000 people, and Hyundai Capital was reported to have lost data on 146 mortgage brokers56.

The authorities moved quickly. At 3 p.m. on October 2, the Financial Services Commission's secretary general chaired an "emergency response meeting" with the Financial Supervisory Service, the Financial Security Institute, major banks and card companies, and industry associations, and gave three instructions. Review every system reachable from outside, whether or not it serves customers and whatever the service. Cut unnecessary exposure of information and check for any path that reaches internal data without authentication. Share attacker IP addresses and techniques quickly with KISA (the Korea Internet & Security Agency) and other bodies. The commission also said it would supervise the affected institutions to make sure consumer protection and compensation go ahead without delay4. The Korean National Police Agency's cyber terror response unit opened a preliminary inquiry on October 27, and the commission's chairman was reported to be convening an emergency meeting on October 4 with the heads of every financial industry association and the CEOs of the affected firms6.

On the method, Korean media have reported the possibility of attacks using AI agents. The Financial Services Commission's October 2 release does not mention AI, though, and an official said it will take time to confirm whether all of these attacks came from the same group6. Some have also suggested credential stuffing, where logins leaked elsewhere are tried again and again1. The accurate summary for now is that the method is still under investigation.

Two things stood out to me. First, the targets were not the customer-facing internet banking services but systems on the periphery: tools for loan brokers, staff and sales support. A bank official quoted by Yonhap put it this way: customer touchpoints have solid authentication, but there are too many satellite sites and their security is uneven2. Second, the way KB Kookmin Bank wrote its notice. It listed every leaked data item, warned about secondary harm such as identity theft and voice phishing, pointed people to services that block fraudulent use of their name, set up a dedicated helpline, explained how to claim damages or request mediation, and ended by saying the bank does not send text messages containing URLs or links about the leak3. That is almost a complete answer to what an individual in Japan should check after receiving a breach notice.

The first 30 days, for individuals and companies

In Korea, Shinhan Bank disclosed the leak one day after confirming it, and KB Kookmin Bank two days after. In Japan, too, users usually receive a breach notice several days after the company notices the problem. Put differently, by the time the notice arrives, the attacker is already several days ahead. To avoid panic, here is what to do in four windows: the first hour, the same day, three to five days, and 30 days.

When Individuals Companies
First hour If you see transfers or card charges you did not make, call your bank and card issuer to stop them. If you typed details into a fake site, change the password immediately. Save screens, emails and texts Disconnect infected devices from the network (do not power them off). Report to someone with authority. Start a timestamped log of what was noticed and when
Same day Change the password on any other service where you reused it, and turn on multi-factor authentication. Contact the police (#9110 or a cybercrime desk) Set up a response team. Report to the police and bring in JPCERT/CC or outside experts if needed. If you process data on behalf of a client, notify that client. Call your insurer
3 to 5 days If you were told your ID documents leaked, self-report to the three credit bureaus and complete the steps for each document File a preliminary report with the Personal Information Protection Commission (roughly within 3 to 5 days). Critical infrastructure operators file a preliminary report on ransomware and similar incidents (within 3 to 5 days). Decide on notifying individuals, public disclosure and telling business partners
Up to 30 days Keep checking statements. Request your credit file to see whether anyone applied in your name. Pursue compensation File the final report with the commission (within 30 days, or 60 days where improper intent may be involved). Critical infrastructure operators file a detailed report (within 30 days). Decide on measures to prevent recurrence

Individuals and companies protect different things. An individual's first concern is money and identity. A company has to stop the damage from spreading and keep evidence, and on top of that it has legal duties to report and notify. Here is the comparison on one page.

Aspect Individuals Companies
What to protect first Money and identity Stopping the spread, and evidence for the investigation
Legal duties No duty to report. But compensation for fraudulent transfers depends on telling the bank promptly and explaining the facts to the police Reports and notifications under the Act on the Protection of Personal Information, sector-specific reporting, critical infrastructure reporting
First call Bank, card issuer Internal decision-maker, police
Evidence to keep Screenshots, original emails and texts, statements, notes with times Network and access logs, records on affected machines, the ransom note, system diagrams
Where to get advice #9110, 188, IPA's security helpline Police cybercrime desks, JPCERT/CC, IPA, the supervising ministry

Building these tables, I realized how short the first-hour list really is for both sides. Stop, change, keep. If you remember those three verbs, you avoid most of the mistakes people make when they panic and do the opposite.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

What individuals should do first

In the first hour, shut the money exits

If you notice a transfer or card charge you did not make, call your bank and card issuer before anything else. Only you and the bank can freeze an account or a card. If you entered internet banking credentials on a fake site, Japan's Council of Anti-Phishing says to contact your bank right away. If you entered a card number, call the card issuer's lost-or-stolen line to stop the card and ask for a replacement if needed. If you entered an ID and password, change the password at once and check whether other services tied to the same email address use guessable passwords8.

Speed also affects compensation. In an agreement dated February 19, 2008, the Japanese Bankers Association said that individual customers whose deposits are fraudulently withdrawn through internet banking will be compensated in full if they were not at fault. The conditions include notifying the bank promptly, explaining the circumstances fully to the bank, and explaining the facts to investigators9. For forged or stolen cash cards, a 2005 law, the Depositor Protection Act, sets the compensation framework10. In both cases, protect yourself by leaving no room for someone to ask later why you waited.

Keep the evidence instead of deleting it

In a panic, people want to delete the suspicious email or text. I understand the urge, but leave deletion for later. Keep the screens of the messages you received, the fake site's URL and what it showed, statements with the transactions you did not make, and a note of when you noticed and what you did. That is what you will need to explain things to your bank and the police. On a smartphone, screenshots are enough.

On the same day, deal with passwords and get advice

Change every password you reused, the same day. Where a service offers multi-factor authentication (confirming it is you with an authenticator app or biometrics on top of a password), turn it on now. Where you can see login history, check for devices or locations you do not recognize.

Where to turn depends on the problem. For reporting harm and getting advice, go to the police. In Japan, #9110 is the nationwide number for non-emergency consultations, and it connects you to the general consultation desk of the police force covering your area11. For cybercrime, besides each prefectural police force's cybercrime desk, the National Police Agency runs a nationwide online form on e-Gov, the government's online application portal run by the Digital Agency, where you can file a report, ask for advice or provide information. To file a formal damage report, contact your nearest police station12. For disputes over compensation or contracts, the consumer hotline 188 connects you to a local consumer affairs center13. For technical questions about malware or unauthorized access, there is the Information Security Safety Consultation Desk run by IPA, the Information-technology Promotion Agency14.

Problem Who to contact Number or method
Fraudulent transfer from your account, or banking credentials typed into a fake site Your bank Your bank's own desk. If unsure, the FSA's Counseling Office for Financial Services Users at 0570-016811 (weekdays 10:00 to 17:00) or the Japanese Bankers Association counseling office at 0570-017109 (weekdays 9:00 to 17:00)15
Card number typed in, or charges you did not make Card issuer's lost-or-stolen line Number on the back of the card
Reporting harm or asking the police Police #9110 (non-emergency), prefectural cybercrime desks, the nationwide online form on e-Gov1211
Disputes over compensation or contracts Consumer affairs center Consumer hotline 18813
Technical help with malware or unauthorized access IPA Information Security Safety Consultation Desk 03-5978-7509 (weekdays 10:00 to 17:00)14
Found a phishing email or site Council of Anti-Phishing Japan Reporting page on its website8
ID documents leaked The three credit bureaus and the office for each document See the next section

Be suspicious of the breach notice itself

When a company sends you a breach notice, watch out for something else: fake emails and texts posing as that notice. Once a leak is in the news, fake messages about "compensation procedures" or "checking whether you were affected" tend to circulate. KB Kookmin Bank, mentioned above, stated that it does not send text messages containing URLs or links about the leak, that any such message citing the leak is fraud, and urged people not to tap addresses in messages of unknown origin3. Japan's FSA likewise says financial institutions never ask for IDs or passwords by text message15. Do not tap the links in a notice. Check through the official site you bookmarked yourself or the official app. That alone avoids a large share of secondary harm.

If ID documents leak, self-report to Japan's three credit bureaus first

When people are told that images of their driver's license or My Number card leaked, many think first about getting the license reissued. What I would like them to do before that is file a self-report (honnin shinkoku) with Japan's credit bureaus. The real damage from leaked ID data is someone applying for a loan or credit card in your name. A self-report puts a flag in front of whoever reviews that application, saying that this person has reported losing their documents or having their data leaked.

What a self-report is

Japan has three designated credit bureaus: CIC, whose members are mainly credit card and installment credit companies; JICC (Japan Credit Information Reference Center), whose members include consumer lenders and credit companies; and the Personal Credit Information Center run by the Japanese Bankers Association, referred to here as KSC16. All three let individuals register a report when their ID documents have been lost, stolen or leaked and their name may be misused.

Once registered, member companies see the report alongside your credit file when they review an application for credit or a loan. KSC says members that use the report as a reference can make their credit decisions more carefully17, and JICC says its members review more carefully as well18.

It is not a cure-all, though. KSC states that a report does not bind members' decisions, that it does not guarantee misuse will be prevented, and that because inquiries are limited to credit decisions, the center is not consulted when someone opens a bank deposit account17. CIC likewise says it does not guarantee the effect of a report19. A self-report alone will not stop a fraudulent bank account or a fraudulent phone contract.

You can file even if only images or data leaked and you still have the document. JICC accepts cases such as "I sent an image of my driver's license," where the original is in hand but the information got out, under its "preventing misuse of your name" category18. KSC says you can file when your ID information, including image data, may have leaked to a third party through fraud or a data breach17. KSC also notes that simply having sent an image to a business in an ordinary transaction is, in principle, not grounds for a report; what qualifies is a case where that image then leaked from the business17. If a company has notified you of a breach, this is exactly your situation.

How the three bureaus differ

Item CIC JICC KSC (Japanese Bankers Association)
Name of the scheme Honnin shinkoku (self-report) Honnin shinkoku komento (self-report comment) Honnin shinkoku (self-report)
Main members Credit card and installment credit companies Consumer lenders, credit and leasing companies Banks and other financial institutions
Online ¥1,000. Call a dedicated number from the phone number registered with CIC to get a reference number, then finish within an hour (8:00 to 21:45) ¥700 via smartphone app. Identity confirmed by credit card plus phone, or by photographing two ID documents ¥500. Identity confirmed online with your My Number card
By mail ¥1,000 (postal money order). Send the form and ID copies ¥1,111 including ticket fee. Send the form and ID copies ¥2,403 (¥2,060 fee plus ¥343 ticket fee). Send the form and ID copies
How it is accepted Online and mail only. Not by phone or email App and mail. No applications by proxy (the person themselves, aged 15 or over) Online and mail only. Not at the center's office, not at member banks, not by phone
Police report Not listed as a requirement Can register without one, but filing is recommended Not listed as a requirement
Registration period Five years from registration Five years from registration Deleted automatically five years after filing
Deletion Free, online or by mail Free, via the app (same device) or by mail Deletion request by mail
Sharing among the three Shared, but registering with each bureau is recommended Shared, but registering with each bureau is recommended Self-report data is exchanged via the three-bureau network (CRIN)

Sources: CIC1916, JICC18, KSC17. Fees are as published by each bureau as of October 4, 2026.

The last row matters most. The three bureaus exchange self-report data through a network called CRIN. Even so, CIC says "we recommend registering with each credit bureau"19, and JICC also recommends registering with each one, because member companies differ by bureau and members of another bureau will not necessarily use the shared information18. Do not assume that one bureau is enough because the data is shared. Online, all three cost ¥2,200 in total. Treated as insurance for your name, I think it is worth filing with all three.

One note on what is happening right now. Between September 29 and October 2, 2026, KSC posted a series of notices saying applications had risen far above normal levels: online applications were suspended and then resumed, phone lines were hard to reach, and processing was taking considerably longer than usual20. The notices do not give a reason for the surge. If the website is not taking applications, you can apply by mail, and you can file with CIC and JICC first while you wait.

Where to report each document

Alongside the self-report, deal with the documents themselves. The key distinction is whether you lost the physical document or had it stolen, or whether you still have it and only images or data leaked. If the document is gone, you need a police report and the procedure for that document. If only data leaked, the self-report is the main step.

Document If lost or stolen Primary source
My Number card Suspend it through the My Number toll-free line, 0120-95-0178 (option 2), open 24 hours a day, 365 days a year, free of charge. File a lost-property or theft report with the police, note the receipt number, and apply for reissue at your municipal office Japan Agency for Local Authority Information Systems (J-LIS)21
Driver's license File a lost-property or theft report with the police. Apply for reissue at a driver's license center (in Tokyo, the Fuchu, Samezu or Koto centers) Tokyo Metropolitan Police Department22
Passport Submit a report of a lost passport with a document from the police certifying that you reported the loss. The reported passport becomes invalid and cannot be used even if found later Ministry of Foreign Affairs23
Health insurance eligibility certificate The old health insurance cards are no longer issued; people now use an eligibility certificate or the My Number card. Ask your insurer (your employer's health insurance society, your municipality and so on) about issuance and questions Ministry of Health, Labour and Welfare24
Residence card Apply for reissue within 14 days of learning of the loss, including the police report receipt number Immigration Services Agency25

A lost passport report is for when the passport itself is gone. Once you file it, that passport can no longer be used, so if you still have it and only an image leaked, there is nothing to file.

A word on fraudulent mobile phone contracts. Japan's Mobile Phone Improper Use Prevention Act requires carriers to verify identity when signing contracts. On July 27, 2026, the Ministry of Internal Affairs and Communications promulgated amended rules that, in response to fraudulent contracts made with skillfully forged ID documents, require in-person identity checks at contract signing to read the IC chip of a My Number card or similar. The rules take effect on April 1, 202726. Until then, if you receive a notice or bill for a contract you did not make, contact that carrier right away. The ministry's Telecommunications Consumer Advice Center (03-5253-5900) also takes inquiries27. I could not find an official way to check, across all carriers at once, which lines are registered in your name.

Finally, within the first 30 days, request your own credit file. All three bureaus let you see what they hold on you, so you can check whether any applications or contracts you did not make have been recorded. Each bureau's data must be requested from that bureau separately28.

What company leaders should do first

In the first hour: disconnect, preserve, escalate

A ransomware extortion screen appears on an office PC, or someone outside calls to say your data is circulating. In the first hour, you can narrow the job down to three things.

The first is to disconnect. Japan's National Police Agency asks victims to isolate infected PCs by unplugging the LAN cable and turning off Wi-Fi. In the same breath it says not to power off PCs or network equipment, because logs needed for the investigation may be lost29. Hands reach for the power button by reflex, but that is the fastest way to destroy evidence.

The second is to preserve. What did you notice, when, who did what? Start a timestamped log the moment you notice. Examples of what the police ask victims to provide include the ransom note, network logs, disk images, memory dumps and system diagrams2930. If you try to collect logs later, they may already have been overwritten.

The third is to escalate. The Personal Information Protection Commission's general guidelines say that when a leak or suspected leak is found, the first step is to "report immediately to a person in a position of responsibility" and to take the measures needed to keep the damage from growing beyond what it was when discovered31. If the person who found it keeps it to themselves, the company will miss the reporting deadlines explained next. For a company, the clock starts when any department learns of the incident31. Treat the day your IT staff noticed as the day the company knew.

Reporting duties that start running in three to five days

Under Japan's Act on the Protection of Personal Information, a company must report to the Personal Information Protection Commission and notify the affected individuals when personal data has leaked (including loss or damage), or may have leaked, in any of four situations: the data includes sensitive personal information such as medical history; misuse could cause financial harm; the leak may have been caused by an act with improper intent, such as unauthorized access; or more than 1,000 people are affected3233. Most leaks caused by cyberattacks fall under the third.

Reporting has two stages. First, a preliminary report "promptly" after learning of the incident; the guidelines put the rough target at "within three to five days"31. You report only what you know at the time, and not knowing the full picture is no reason to delay. Then a final report within 30 days of learning of the incident, or 60 days where improper intent may be involved33. Reports go through the commission's online form34.

Duty Who Deadline Legal basis
Preliminary report to the PPC Businesses with a leak in any of the four situations above Promptly after learning (roughly within 3 to 5 days) Act on the Protection of Personal Information, Art. 26(1); Enforcement Rules, Arts. 7 and 8(1); general guidelines
Final report to the PPC Same Within 30 days of learning (60 days where improper intent may be involved) Enforcement Rules, Art. 8(2)
Notice to affected individuals Same Promptly, as the situation allows Act, Art. 26(2); Enforcement Rules, Art. 10
Notice to the client (for contractors) Businesses handling personal data on behalf of a client Promptly (doing so relieves the contractor of its own reporting duty) Act, Art. 26(1) proviso; Enforcement Rules, Art. 9
Preliminary incident report Designated operators in 15 critical infrastructure sectors DDoS: as soon as possible after detection. Ransomware and other attacks: within 3 to 5 days of detection Active cyber defense law, Art. 5; ministerial ordinance, Art. 4(2)
Detailed incident report Same Within 30 days of detection Same
Sector rules (example) Telecom carriers (e.g., leaks of communications secrecy) Without delay, to the Minister of Internal Affairs and Communications Telecommunications Business Act, Art. 28

Sources: Act on the Protection of Personal Information32, Enforcement Rules33, general guidelines31, Cabinet Office et al., explanatory guide to the incident reporting system35, Telecommunications Business Act36

Two traps hide in this table. The first is where to report. In some sectors the commission has delegated its authority to the minister in charge of that industry, so reports go to that ministry instead. The commission publishes a list of reporting destinations by sector on its page about delegation of authority. It also notes that leaks of a company's own employee or shareholder data still go to the commission34.

The second is the law that took effect on October 1, 2026, usually called the active cyber defense law (its formal Japanese title translates roughly as the Act on the Prevention of Damage from Unauthorized Acts against Important Computers). Critical infrastructure operators in 15 sectors, including electricity, gas, water, railways, finance and credit cards, 258 in total, must report cyberattacks on their key systems to the minister in charge and the Prime Minister37. The deadlines are in the table, and the official guide explains that incidents on covered systems managed by a contractor are also reportable35. Small firms that do business with these operators should expect more requests to commit to notifying the client immediately when they detect an intrusion. That is my own reading, but I expect requests to revise contracts to arrive before long.

Notifying individuals and deciding whether to go public

Notice to individuals must be given "promptly, as the situation allows." The guidelines give examples where notice need not be sent at that moment: when notifying could make the damage worse, or when so little is known that individuals could not do anything to protect themselves and notice would only cause confusion. They stress, though, that the duty to notify promptly does not change31. Where some individuals cannot be reached, publishing the incident or setting up an inquiry line where people can check whether their data is affected can serve as an alternative31.

Public disclosure itself is not a legal requirement. Even so, the guidelines say it is "desirable to promptly publish" the facts and preventive measures, to prevent secondary harm and similar incidents31. I agree. As I wrote in Part 2, the Japanese companies that disclosed breaches this autumn released numbers as they confirmed them and warned users about fake messages. The Korean banks published the leaked data items and their compensation policies within a day or two of confirmation. Rather than staying silent for fear the numbers will change mid-investigation, separate "what we know now" from "what we are still investigating" and publish the first. Users can protect themselves sooner that way.

Police, JPCERT/CC, IPA, partners and insurers

Think of contacting the police less as filing a complaint and more as getting help to limit the damage. The National Police Agency says it can sometimes support initial response to prevent the damage from spreading, and point victims to decryption tools. To the worry that reporting means having to go public, its answer is that the police never ask victims to disclose incidents and keep victim information strictly confidential. On recovery, it says that right after an incident it may only ask for logs to be preserved and hear the details later, taking care not to disrupt business29.

If you lack hands for the investigation, JPCERT/CC (the Japan Computer Emergency Response Team Coordination Center) accepts requests for support in the early stage, including investigation, response planning and identifying affected systems38. IPA's helpline, mentioned in the individuals section, is another entry point for technical questions14.

Tell business partners and clients early, legal duty or not; it preserves trust. If you handle personal data on a client's behalf, notifying that client is also a legal step33. If your email accounts have been taken over, partners may receive fake invoices. Reach them by another channel as well, such as phone, and ask them not to act on any email in your name requesting a change of bank details.

If you have cyber insurance, call the insurer at this stage. Depending on the policy, costs such as forensic investigators, notification to individuals and damages may be covered. What is covered and how incidents must be reported differ by policy, so it pays to read the terms before anything happens. Note also that fraudulent transfers from corporate accounts are treated differently from individual ones. In an agreement dated May 15, 2014, the Japanese Bankers Association kept its long-standing view that corporate and individual customers differ and said each bank decides individually whether to compensate. It also gave examples of measures companies should take, such as setting transfer limits as low as practical and using separate PCs for the person who submits a transfer and the person who approves it39.

Should you pay the ransom?

My answer up front: prepare on the assumption that you will not pay. The National Police Agency says it tells victims that paying raises concerns that the money will fund criminal groups and that payment does not guarantee the data will be decrypted29. Even if you pay, I do not think there is any way to confirm that the stolen data has really been deleted.

Even so, when the business itself is at stake, the debate may come up. What I want companies to avoid is a staff member or a few executives contacting the attackers and paying on their own authority. Make it a management decision taken after consulting the police and a lawyer. And make sure the debate never has to happen, by keeping offline backups and confirming you can restore them. In the end, it comes down to that.

What not to do

In a crisis, more damage seems to come from panicking and doing the opposite of what is needed than from doing nothing. Here are the moves to avoid, for companies and individuals.

Don't Why it hurts Do this instead
Power off, wipe or clear logs on affected machines (companies) Destroys the clues to how and how far the attacker got in Disconnect from the network, leave the power on and wait for experts29
Let one person handle it alone (companies) The reporting clock starts when anyone in the company knows Report immediately to someone in a position of responsibility31
Negotiate with attackers and pay on someone's own authority (companies) May fund crime, and decryption is not guaranteed Consult the police and a lawyer, and decide as management29
Publish unverified information as fact (companies) A string of corrections leaves users unsure what to believe Separate what is known from what is under investigation
Notify individuals by text or email with URLs (companies) Cannot be told apart from fakes and becomes a path to secondary harm Use notices on your official site and messages that state the sender address
Delete suspicious emails or texts right away (individuals) Leaves nothing to show your bank or the police Save the screens first, then clean up
Tap the link in a breach notice (individuals) It may be a fake site posing as the notice Check through a bookmarked official site or the official app15
Put off the credit bureau self-report to "wait and see" (individuals) Fraudulent applications may start before the notice reaches you Report to all three bureaus within the week you receive the notice

For companies, the hardest judgment is reconciling "don't publish unverified information" with "disclose quickly." I think you can do both by narrowing what you publish. Put out only the facts you are sure of (when you noticed, which system, what kinds of data may be involved) and what you want users to do (watch for fake messages, change passwords), then publish numbers and causes once confirmed. Shinhan Bank, too, presented its figure as the number "confirmed so far"1.

What to decide before anything happens

None of this works if you start looking it up after the incident. Here is what to settle in advance.

For companies, start with a one-page contact sheet: the decision-maker and a deputy, the IT lead, your outside lawyer, the police (your local station and the prefectural cybercrime desk), contractors and clients, your insurer, the supervising ministry, and where the commission's reporting form is. Write the phone numbers down and keep a paper copy. If ransomware stops your systems, you will not be able to open the contact list on the shared drive. The National Police Agency also recommends preparing a business continuity plan that assumes a cyberattack, with the response flow and police contacts written down, and running drills to check contact with stakeholders, reporting to the police, communications and restoring from backups29.

Next, know the reporting items in advance. A report to the commission covers nine items, including an overview, the data items affected, the number of people, the cause, the risk of secondary harm, steps taken for individuals, the status of public disclosure and preventive measures33. Decide who investigates what along those lines, and three to five days is plenty for the preliminary report. Prepare templates for the public statement and the notice to individuals, a plan for an inquiry line and the sender address you will use for genuine messages.

For individuals, keep your card issuer's lost-or-stolen number and your bank's contact details somewhere other than your phone. Then, if the phone itself is lost or hijacked, you do not lose the numbers with it. Stopping password reuse and turning on multi-factor authentication are the same preventive steps I covered in Part 2. For how well country-level blocking of foreign traffic works, and where it falls short, see Does Blocking Foreign Traffic Work?. For the export control angle when drawings or technical data are stolen, see Cyberattacks Are an Export Control Problem Too.

A contact sheet and a runbook do nothing by themselves. Once a year at least, walk through a scenario out loud, say "a ransom screen appears late on a Friday afternoon," and trace who you call, what you stop and what you record. If you want help designing that kind of drill or internal rules, our WARP SECURITY program can support you. It spends less time on attack techniques and more on approval flows and practicing the decisions you face when an incident is discovered.

Summary

  • Since September 30, 2026, six Korean banks have been reported as targets, and four disclosed leaks. The attackers hit peripheral systems for loan brokers and staff rather than customer-facing channels
  • Individuals: stop, change, keep. Call your bank and card issuer, change passwords and enable MFA, and save the evidence, all within the first hour
  • If ID documents leak, self-report to the three credit bureaus and complete the steps for each document within the week of the notice
  • Companies: disconnect, preserve, escalate. Preliminary report to the commission roughly within 3 to 5 days, final report within 30 days (60 if improper intent may be involved). Critical infrastructure operators also report under the active cyber defense law from October 2026
  • Plan on not paying a ransom, and prepare offline backups and a contact sheet in peacetime

Reading the Korean banks' announcements, the question I kept coming back to was this: if the same call came to my company, who would run the first hour? If your company cannot answer with one person's name, that is this week's homework. For individuals, simply copying your card issuer's lost-or-stolen number onto paper and bookmarking the three credit bureaus' pages will change the first ten minutes of a crisis. If you would like to talk through response planning or staff drills, get in touch.

References

The facts in this article are based on announcements and reports available as of October 4, 2026. The scope of the Korean leaks and the attack methods are still under investigation. The description of Japanese rules does not guarantee how they apply to any particular case; check with the relevant authority or an expert if in doubt.

Footnotes

  1. Yonhap News, "Customer data on 25,000 leaked at Shinhan Bank; regulators begin emergency on-site inspection" (in Korean), October 1, 2026. The content of Shinhan's apology, data items and counts, the FSS inspection and the credential stuffing theory are from this article ↩ ↩2 ↩3 ↩4 ↩5

  2. Yonhap News, "Kookmin, Hana and Busan banks hit too; hacking damage spreads across the financial sector" (in Korean), October 2, 2026. Explanations from Hana, BNK Busan, Woori and NH NongHyup, the systems targeted and the bank official's comment are from this article ↩ ↩2 ↩3 ↩4

  3. KB Kookmin Bank, notice on the leak of personal (credit) information (in Korean), October 2, 2026. Numbers and data items, the system involved, steps to limit secondary harm, the helpline, remedies and the statement that the bank will not send texts with URLs are from this notice ↩ ↩2 ↩3 ↩4

  4. Financial Services Commission and Financial Supervisory Service, press reference on the emergency response meeting (in Korean), October 2, 2026. Attendees (including six banks and three card companies), the three instructions, on-site inspections, threat information sharing and supervision of compensation are from this release. The same release is on the FSS website ↩ ↩2

  5. Yonhap News, "Yegaram Savings Bank also hacked; customer data on an estimated 40,000 leaked" (in Korean), October 3, 2026 ↩

  6. Yonhap News, "Regulators call emergency meeting of all financial sectors as hacking spreads to non-bank lenders" (in Korean), October 3, 2026. The October 4 meeting, the Hyundai Capital case and the official's comment on whether one group is behind the attacks are from this article ↩ ↩2 ↩3

  7. Yonhap News, "Police open immediate inquiry into sweeping AI hacking of banks" (in Korean), October 2, 2026 ↩

  8. Council of Anti-Phishing Japan, Reporting phishing (in Japanese). The steps for "if you entered information on a phishing site" are from this page ↩ ↩2

  9. Japanese Bankers Association, Response to fraudulent withdrawals of deposits (in Japanese), February 19, 2008. Scope, conditions and standards for internet banking compensation are in the attachment ↩

  10. Act on the Protection of Depositors from Unauthorized Machine Withdrawals Using Forged or Stolen Cards (Act No. 94 of 2005, e-Gov, in Japanese) ↩

  11. National Police Agency, Opinions, consultations and information (in Japanese). Guidance to use a local police station or #9110 for non-emergency consultations ↩ ↩2

  12. National Police Agency, Cyber incident consultation desks (in Japanese). The nationwide online form, filing damage reports at police stations, and the referrals to IPA's helpline and 188 are from this page ↩ ↩2

  13. Consumer Affairs Agency, Consumer Hotline 188 (in Japanese) ↩ ↩2

  14. IPA, Information Security Safety Consultation Desk (in Japanese). Phone number and hours (10:00 to 17:00, excluding weekends, holidays and the New Year period) are from this page ↩ ↩2 ↩3

  15. Financial Services Agency, Surge in fraudulent internet banking transfers apparently caused by phishing (in Japanese). Helpline numbers and hours are from this page ↩ ↩2 ↩3

  16. CIC, What is a self-report (in Japanese), Self-report by mail and Deleting a self-report. The description of each bureau's main members and the exchange of self-report data via CRIN are from KSC, Information exchange (in Japanese) ↩ ↩2

  17. KSC (Japanese Bankers Association), Self-report procedures (in Japanese), by mail and FAQ on self-reports. Automatic deletion after five years is from the terms in the application form (PDF) ↩ ↩2 ↩3 ↩4 ↩5

  18. JICC, Self-report comment (in Japanese), applying via the app and applying by mail. The recommendation to register with each bureau is from its FAQ on exchange among the three bureaus, and registration without a police report from its FAQ on police reports ↩ ↩2 ↩3 ↩4

  19. CIC FAQ: If I register a self-report with CIC, do I need to register with other credit bureaus? (in Japanese). The statement that CIC does not guarantee the effect, the five-year retention, how to get a reference number and the fee are from CIC, Self-report online (in Japanese) ↩ ↩2 ↩3

  20. KSC notices (in Japanese): Sept 29, 2026, processing time, Sept 29, online applications suspended, Sept 30, resumed, Sept 30, phone lines, Oct 2, processing time ↩

  21. My Number Card portal (J-LIS), Loss, suspension and security (in Japanese). Suspension by a proxy, the police report and receipt number, and reissue are from its FAQ on lost cards ↩

  22. Tokyo Metropolitan Police Department, Reissuing a driver's license (in Japanese). Lost-property reports can also be filed through its online service. Locations differ by prefecture ↩

  23. Ministry of Foreign Affairs, Passport applications: report of loss (in Japanese) ↩

  24. Ministry of Health, Labour and Welfare, Eligibility certificates (in Japanese). The contact for a lost My Number card used as a health insurance card is on this page ↩

  25. Immigration Services Agency, Reissue of a residence card due to loss (in Japanese) ↩

  26. Ministry of Internal Affairs and Communications, Results of public comment on the amended enforcement rules of the Mobile Phone Improper Use Prevention Act (in Japanese), July 27, 2026. The purpose of the amendment is from the attachment with the ministry's responses ↩

  27. Ministry of Internal Affairs and Communications, Preventing criminal use of mobile phones (in Japanese) ↩

  28. CIC, Disclosure of credit information (in Japanese), JICC, Disclosure requests, KSC, Disclosure procedures ↩

  29. National Police Agency, Ransomware damage prevention (in Japanese). Isolation without powering off, reporting to the police, the explanation on ransom payments, not requiring disclosure, examples of information requested, and the recommendation of a BCP and drills are from this page ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

  30. National Police Agency, Cyber Police Agency Letter Vol. 4, "Report cybercrime damage to the police" (in Japanese) ↩

  31. Personal Information Protection Commission, Guidelines on the Act on the Protection of Personal Information (General Rules), as amended April 2026 (in Japanese). The measures to take when a leak is discovered (including the statement that publication is desirable), section 3-5-3-3 on preliminary reports (when the company "knows" and "roughly within 3 to 5 days") and section 3-5-4 on notice to individuals ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  32. Act on the Protection of Personal Information (Act No. 57 of 2003, e-Gov, in Japanese). Article 26 (reporting leaks) and Article 150 (delegation of authority) ↩ ↩2

  33. Enforcement Rules of the Act on the Protection of Personal Information (PPC Rules No. 3 of 2016, e-Gov, in Japanese). Article 7 (reportable situations), Article 8 (reports to the commission; paragraph 1 lists the items, paragraph 2 sets the 30- and 60-day deadlines), Article 9 (notice to clients), Article 10 (notice to individuals) ↩ ↩2 ↩3 ↩4 ↩5

  34. Personal Information Protection Commission, Responding to leaks (in Japanese). The reporting form and deadlines. Reporting destinations by sector, and the note that employee and shareholder data leaks go to the commission, are from the page on delegation of authority ↩ ↩2

  35. Cabinet Office et al., Explanatory guide to reporting of specified intrusion incidents by designated critical infrastructure operators (in Japanese), October 1, 2026. Section 6-2 on deadlines (Article 5 of the Act and Article 4(2) of the ministerial ordinance) and the treatment of covered systems managed by contractors are from this guide ↩ ↩2

  36. Telecommunications Business Act (Act No. 86 of 1984, e-Gov, in Japanese). Article 28 (reporting suspension of service and incidents) ↩

  37. National Cybersecurity Office and Cabinet Office, On the entry into force of the Cyber Response Capability Enhancement Act and related laws (in Japanese), September 2026. The 15 sectors and 258 operators, incident reporting from October 1 and the reporting destinations (the minister in charge and the Prime Minister) are from this document. The effective date is set by Cabinet Order No. 46 ↩

  38. JPCERT/CC, Incident response requests (in Japanese) ↩

  39. Japanese Bankers Association, Response to fraudulent withdrawals via corporate internet banking (in Japanese), May 15, 2014 ↩

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles