Security Experts Note Abnormal Increase in Data Leaks and Potential AI Use
October 10, 2026 · 2 min read
A series of cyberattacks causing data leaks has increased since the summer, with intensity rising in October. On October 7, a ransomware attack targeted parts of the IDCF Cloud, a domestic cloud service operated by IDC Frontier, affecting approximately 500 organizations, including local governments.
Three cybersecurity experts have shared information through a blog by the Macnica Security Research Center, stating that an abnormal situation is occurring. The authors include a deputy center director from the Macnica Security Research Center, a chief cybersecurity analyst and CTO from Itochu Cyber and Intelligence, and a CTO and director from Secure Sky Technology.
An analysis of 81 cases since July identified various attack methods. Nine cases involved one specific method, four involved a second method, and three involved a third method, while 65 cases lacked sufficient explanation for classification. The experts noted a visible trend in the third method, where attackers search for flaws in specific sites or application programming interfaces. Other attacks involved the use of weak passwords for management screens or the exploitation of known vulnerabilities.
The experts described the reality as a process of trial and error, where attackers broadly search for any usable flaws or defects in a system to reach information rather than relying on a single method. Some cases showed commonalities in the source IP addresses, suggesting that successful methods may be deployed against other targets.
Regarding the use of artificial intelligence, the experts stated that no logs or traces have been confirmed to prove its use in these specific cases. They also noted that no evidence has been found of AI being used to discover and exploit zero day vulnerabilities. However, they argued that it is difficult to deny the use of AI because the scale and speed of the investigations into system flaws make manual human work unrealistic.
The experts expressed concern that AI has changed the speed of discovering security flaws to machine speed, which in turn changes the range and depth of targets that can be investigated. They stated that the fact that so many victims were affected so quickly is a serious matter.
Recommended countermeasures include organizing the web systems, mobile apps, and personal information held by an organization. Experts suggest checking access logs from the last month for anomalies, such as massive access to application programming interfaces from the same IP address, spikes in error responses, or extreme increases in normal responses. They also recommend replacing weak passwords, considering multi factor authentication, and conducting vulnerability diagnoses, ensuring that management screens are not excluded from such checks. Finally, they advise continuous monitoring of server resource loads and error logs, and reviewing the flow for reporting and investigating anomalies.