Information Security Consultation Desk: Q2 2026

Overview

The Information-technology Promotion Agency (IPA), an incorporated administrative agency, published statistics on consultations received from individuals by its Information Security Consultation Desk between April 1 and June 30, 2026. The desk handled 3,832 consultations, an increase of approximately 8.5% from the previous quarter and approximately 30.3% from the same quarter of the previous year. Fake virus-detection warnings were the most common issue, while unauthorized logins, phishing, spam emails demanding money in cryptocurrency, and one-click billing were also reported. The report presented a case in which a LINE account was hijacked after a social media voting request, followed by messages asking acquaintances and family members to send money through PayPay, as well as a case involving an order placed on a shopping site using a third party’s credit card. Recommended measures included changing passwords, using multifactor authentication, and checking registered cards for unauthorized use.

This summary was automatically generated by AI. Please refer to the original article for accuracy.

Key points

  • The number of consultations handled for individuals is increasing.
  • Fake virus-detection warnings were the most common consultation method.
  • Damage from LINE hijacking originating with a social media voting request was confirmed.
  • The report recommended avoiding password reuse and using multifactor authentication.

Overview

This report covers consultations from individuals handled by the Information Security Consultation Desk of the Security Center of the Information-technology Promotion Agency (IPA), an incorporated administrative agency.

The covered period was April 1, 2026, through June 30, 2026, and the publication date was July 22, 2026. Since April 2025, consultations from individuals have been handled by the Information Security Consultation Desk, while consultations from businesses and organizations have been handled by the newly established Cybersecurity Consultation Desk.

The quarterly statistics indicate an increase in consultation volume and the continued use of methods targeting individuals, including fake warnings, unauthorized logins, and phishing.

Key figures

Covered period
April 1, 2026, through June 30, 2026
Publication date
July 22, 2026
Consultations handled this quarter
3,832
Change from previous quarter
about 8.5%
Change from same quarter of previous year
about 30.3%
Consultations about most common method
1,428 (37.3%)
Consultations about unauthorized logins
423 (11.0%)
Consultations about phishing
146 (3.8%)
Consultations about spam emails demanding money in cryptocurrency
30 (0.8%)
Consultations about one-click billing
23 (0.6%)

Impact

Individuals should be alert to consultation cases involving fake warnings, unauthorized logins, and phishing when using social media, email, shopping sites, and other services.

When LINE is hijacked, money requests may be sent not only to the account holder but also to family members and acquaintances. For unauthorized use of a shopping site, users are advised to check registered cards for unauthorized transactions and contact support about suspending or changing services if anything suspicious is found.

The consultation service is operated with separate desks for individuals and for businesses and organizations, each reporting on its respective consultation status.

Details

The breakdown by consultation channel was 2,912 by telephone, 394 by email, 9 by fax or letter, 224 by SMS, 293 by chatbot, and 0 through outreach. By method, fake warnings increased by approximately 23.7% from the previous quarter, unauthorized logins by approximately 3.7%, phishing by approximately 5.0%, cryptocurrency-demand emails by approximately 42.9%, and one-click billing by approximately 64.3%.

Fake warnings impersonate virus detection to alarm users, make them call a telephone number, and direct them toward a support contract. For unauthorized logins, many users reported being unable to access services such as Facebook and Instagram. In phishing cases, emails impersonating services or companies direct users to fake sites and induce them to enter personal or credit card information.

Regarding spam emails demanding cryptocurrency, consultations continued about verifying the truth of false extortion claims, but no cases involving payment were confirmed. For one-click billing, consultations concerned screens displayed while browsing adult sites that showed registration as complete and demanded payment.

In one case, a social media voting request led the victim to a phishing site impersonating LINE authentication. After the victim entered a telephone number, password, authentication code, and other information, the LINE account was apparently hijacked, and messages asking acquaintances to send money through PayPay were sent. Recommended responses included completing LINE’s account recovery procedure, warning acquaintances, and never giving or sharing with third parties authentication codes received through links sent from social media or other internet services or by SMS.

In another case, an unauthorized login to a shopping site led to an order being placed with a third party’s card and sent to an unknown delivery address. Recommended measures included changing to a long, complex password that is not reused, enabling multifactor authentication, checking registered cards for unauthorized use, reporting the incident to the site, and providing information to the police when necessary.

Related Articles