Information Security Consultation Desk: Q2 2026
Overview
The Information-technology Promotion Agency (IPA), an incorporated administrative agency, published statistics on consultations received from individuals by its Information Security Consultation Desk between April 1 and June 30, 2026. The desk handled 3,832 consultations, an increase of approximately 8.5% from the previous quarter and approximately 30.3% from the same quarter of the previous year. Fake virus-detection warnings were the most common issue, while unauthorized logins, phishing, spam emails demanding money in cryptocurrency, and one-click billing were also reported. The report presented a case in which a LINE account was hijacked after a social media voting request, followed by messages asking acquaintances and family members to send money through PayPay, as well as a case involving an order placed on a shopping site using a third party’s credit card. Recommended measures included changing passwords, using multifactor authentication, and checking registered cards for unauthorized use.
Key points
- The number of consultations handled for individuals is increasing.
- Fake virus-detection warnings were the most common consultation method.
- Damage from LINE hijacking originating with a social media voting request was confirmed.
- The report recommended avoiding password reuse and using multifactor authentication.
Overview
This report covers consultations from individuals handled by the Information Security Consultation Desk of the Security Center of the Information-technology Promotion Agency (IPA), an incorporated administrative agency.
The covered period was April 1, 2026, through June 30, 2026, and the publication date was July 22, 2026. Since April 2025, consultations from individuals have been handled by the Information Security Consultation Desk, while consultations from businesses and organizations have been handled by the newly established Cybersecurity Consultation Desk.
The quarterly statistics indicate an increase in consultation volume and the continued use of methods targeting individuals, including fake warnings, unauthorized logins, and phishing.
Key figures
- Covered period
- April 1, 2026, through June 30, 2026
- Publication date
- July 22, 2026
- Consultations handled this quarter
- 3,832
- Change from previous quarter
- about 8.5%
- Change from same quarter of previous year
- about 30.3%
- Consultations about most common method
- 1,428 (37.3%)
- Consultations about unauthorized logins
- 423 (11.0%)
- Consultations about phishing
- 146 (3.8%)
- Consultations about spam emails demanding money in cryptocurrency
- 30 (0.8%)
- Consultations about one-click billing
- 23 (0.6%)
Impact
Individuals should be alert to consultation cases involving fake warnings, unauthorized logins, and phishing when using social media, email, shopping sites, and other services.
When LINE is hijacked, money requests may be sent not only to the account holder but also to family members and acquaintances. For unauthorized use of a shopping site, users are advised to check registered cards for unauthorized transactions and contact support about suspending or changing services if anything suspicious is found.
The consultation service is operated with separate desks for individuals and for businesses and organizations, each reporting on its respective consultation status.
Details
The breakdown by consultation channel was 2,912 by telephone, 394 by email, 9 by fax or letter, 224 by SMS, 293 by chatbot, and 0 through outreach. By method, fake warnings increased by approximately 23.7% from the previous quarter, unauthorized logins by approximately 3.7%, phishing by approximately 5.0%, cryptocurrency-demand emails by approximately 42.9%, and one-click billing by approximately 64.3%.
Fake warnings impersonate virus detection to alarm users, make them call a telephone number, and direct them toward a support contract. For unauthorized logins, many users reported being unable to access services such as Facebook and Instagram. In phishing cases, emails impersonating services or companies direct users to fake sites and induce them to enter personal or credit card information.
Regarding spam emails demanding cryptocurrency, consultations continued about verifying the truth of false extortion claims, but no cases involving payment were confirmed. For one-click billing, consultations concerned screens displayed while browsing adult sites that showed registration as complete and demanded payment.
In one case, a social media voting request led the victim to a phishing site impersonating LINE authentication. After the victim entered a telephone number, password, authentication code, and other information, the LINE account was apparently hijacked, and messages asking acquaintances to send money through PayPay were sent. Recommended responses included completing LINE’s account recovery procedure, warning acquaintances, and never giving or sharing with third parties authentication codes received through links sent from social media or other internet services or by SMS.
In another case, an unauthorized login to a shopping site led to an order being placed with a third party’s card and sent to an unknown delivery address. Recommended measures included changing to a long, complex password that is not reused, enabling multifactor authentication, checking registered cards for unauthorized use, reporting the incident to the site, and providing information to the police when necessary.
Related Articles
2026-07-23 | 情報処理推進機構(IPA)
Open Data Spaces and Distributed Data Management
2026-07-23 | 情報処理推進機構(IPA)
Overview of the SCS Evaluation System for Supply Chain Resilience
2026-07-23 | 情報処理推進機構(IPA)
Guide Released for Safe AI Robot Deployment
2026-07-23 | 情報処理推進機構(IPA)
IPA Defines Data-Sharing Requirements for Stable Automotive Semiconductor Supply