---
title: Security Expert Analyzes Surge in Unauthorized Access at Japanese Companies
url: https://www.elseif.net/security-expert-analyzes-surge-in-unauthorized-access-at-japanese-companies
published: 2026-10-08T14:05:33+00:00
language: en
section: Models
source: https://www.itmedia.co.jp/news/article/2610/06/2000002013/
organizations: LAC, Times Car Share, Yakiniku King
publisher: elseif
---

# Security Expert Analyzes Surge in Unauthorized Access at Japanese Companies

Several Japanese companies have announced unauthorized access and subsequent information leaks since late September. These incidents include the leak of driver's license images from Times Car Share and the loss of over 10 million records from Yakiniku King, with various prominent services and firms being targeted.

LAC Chief Technology Officer Hiroaki Kuramochi stated that available public information does not allow for a determination that these cases were caused by a single attacker or a single attack campaign, which is defined as a continuous and organized cyber attack with a specific purpose. He suggested that the concentration of announcements in late September may be due to the timing of company investigations and disclosures rather than a sudden spike in attacks.

Kuramochi noted that the timing of an attack's occurrence, detection, investigation, and public announcement does not always align. Some cases were disclosed in multiple stages as the full scale of the damage became clear. He added that the lack of public information regarding intrusion routes and attack methods, combined with differences in targeted industries, compromised systems, and the scale of affected information, makes it difficult to link the incidents to one actor.

However, a common structural pattern exists where attackers target consumer web services, apps, and shared software as a service platforms to efficiently obtain large amounts of personal data. By combining identity information such as driver's license numbers and face photos, recent behavioral data like hotel bookings, and contact details, attackers can maximize criminal value through precise phishing or fraudulent identity verification.

Regarding the potential role of artificial intelligence, Kuramochi stated that there is currently no public information confirming that AI agents or open AI models such as GLM-5.3 were used in these specific cases. He warned that in the medium to long term, AI may lower the required expertise and time for preparing and executing attacks.

He highlighted that open weight models with high cyber capabilities, such as GLM-5.3, have undergone evaluations for discovering vulnerabilities and developing attack code. Because the weights of these models are public and can be run locally, attacks that were previously possible only for a few highly skilled actors may become available to a wider range of entities.
