Corporate Cybersecurity Consultations: Q2 2026

Overview

The Information-technology Promotion Agency, Japan published statistics and case studies for 302 consultations handled by its corporate cybersecurity consultation desk from April through June 2026. Consultations increased by approximately 6.7% from the previous quarter, and incident-response cases included unauthorized access and ransomware infections. The agency presented a scam involving impersonation of the National Tax Agency and the combined use of telephone calls, email, and remote-operation software, and recommended initializing the device. However, when conducting a forensic investigation, it advises preserving the device without initializing it and keeping it powered off. It also recommends changing authentication information, checking for unauthorized use, providing internal training, and conducting cross-checks.

This summary was automatically generated by AI. Please refer to the original article for accuracy.

Key points

  • Consultations for corporate organizations increased from the previous quarter.
  • A scam combining telephone calls, email, and remote-operation software was confirmed.
  • In addition to technical measures, separation of authority and cross-checks were considered important.

Overview

The Security Center of the Information-technology Promotion Agency, Japan, an incorporated administrative agency, published statistics from its cybersecurity consultation desk for corporate organizations.

The covered period was from April 1, 2026, through June 30, 2026, with 302 consultations handled, an increase of approximately 6.7% from the previous quarter.

The breakdown was 65 incident-response cases, 21 cases involving routine measures, 68 support scams, and 148 other cases; the other cases included 16 scam emails impersonating company presidents and others.

The 65 incident-response cases involved 36 other cases, 11 unauthorized-access cases, 6 ransomware infections, 5 malware infections, 4 spoofed-email transmissions, 3 business email compromise cases, and 1 website defacement case.

Key figures

Publication date
July 22, 2026
Statistical coverage period
From April 1, 2026, through June 30, 2026
Consultations handled in Q2 2026
302 cases
Increase from the previous quarter
Approximately 6.7% increase
Scam emails impersonating company presidents and others
16 cases
Incident-response consultations
65 cases
Consultations from April through June 2025
Total 244 cases
Consultations from July through September 2025
Total 162 cases
Consultations from October through December 2025
Total 224 cases
Consultations from January through March 2026
Total 283 cases

Impact

At companies, harm may expand when employees judge communications impersonating public agencies or business partners to be legitimate and are induced to complete authentication procedures themselves. When they are directed to environments such as telephone calls or chats where consulting third parties is difficult, organizational checks are less likely to function.

If actions taken during remote operation cannot be identified, change passwords, check for unauthorized use of services, and consult the card company or bank. If personal information was stored, consultation with the Personal Information Protection Commission and other measures may be necessary because a reporting obligation may arise.

Because employees' decisions and business processes are targets in many cases, companies need to strengthen operational measures, including separation of authority, cross-checks, and checking systems, in addition to technical measures.

Details

Since April 2025, the consultation desk has been separate from the information security consultation desk for individuals and has handled consultations for corporate organizations. In the case presented, an employee received an automated voice call claiming to be from the National Tax Agency, pressed a number provided as part of an e-Tax update, and gave an email address.

The received email had a sender display suggesting e-Tax, natural Japanese, a URL with a jp domain, and a signature claiming to be from the National Tax Agency. At the link, an automatic file download began from a site made to look like e-Tax. After the employee installed the file, another staff member noticed something suspicious, turned off the device, and ended the call.

If it is unclear which software was executed, initializing the device is recommended. However, when conducting a forensic investigation, do not initialize it; preserve it while powered off and follow the security vendor's instructions. Delete the relevant email.

As a response, change the passwords used on the device and the authentication information for internet services saved for automatic entry, and check for unauthorized use of the services. If a credit card or online banking was used, promptly consult the card company or bank.

As preventive measures, inform the entire organization about the case and provide awareness training, including how to respond to suspicious telephone calls and emails. Establish internal rules and business processes that prevent matters from being handled based on individual judgment alone, while keeping up to date with the latest incident information.

Scams targeting companies provoke urgency or anxiety through email, websites, telephone calls, and chats, while impersonating real organizations or members of management. In recent years, schemes combining remote-operation software with telephone calls and inducing victims to complete procedures themselves, including two-factor authentication, have increased. Hokuriku Bank also confirmed a suspected case in which a perpetrator impersonated e-Tax and induced a corporate internet-banking user to register a transfer destination.

Related Articles