IPA Publishes 2026 Top 10 Information Security Threats; AI Risk Debuts

Overview

The Information-technology Promotion Agency, Japan (IPA; President: Yu Saito) announced on January 29, 2026, the information security threats that had the greatest social impact in 2025 as the “2026 Top 10 Information Security Threats.” For organizations, ransomware attack damage ranked first, attacks targeting supply chains and contractors ranked second, and cyber risks related to AI use ranked third. Cyber risks related to AI use were selected for the first time. For individuals, unauthorized use of internet banking was selected for the first time in four years. The IPA asks organizations to identify risks within their own organizations and across their supply chains, and individuals to check the latest methods and understand countermeasures. Detailed explanations are scheduled to be released sequentially on the IPA website from late February onward.

This summary was automatically generated by AI. Please refer to the original article for accuracy.

Key points

  • The IPA announced the “2026 Top 10 Information Security Threats.”
  • Cyber risks related to AI use were selected for the first time for the organization category.
  • Ransomware attack damage and attacks targeting supply chains and contractors ranked first and second, respectively, in the organization category.
  • In the individual category, unauthorized use of internet banking was selected for the first time in four years.

Overview

The “2026 Top 10 Information Security Threats” selects threats with significant social impact based on information security incidents, attacks, and related conditions that occurred in the previous year, and organizes them from the perspectives of organizations and individuals. The IPA publishes this initiative to raise public awareness of information security threats and promote the implementation of countermeasures.

The IPA has published the “Top 10 Information Security Threats” since 2006.

Threat candidates are selected by the IPA and finalized through voting by the “Top 10 Threats Selection Panel,” which consists of approximately 250 information security researchers, corporate practitioners, and others.

In the 2026 edition, cyber risks related to AI use, which became a threat candidate for the first time, ranked third in the organization category alongside attacks that have been covered previously.

The “2026 Top 10 Information Security Threats” was published on January 29, 2026.

Impact

Many companies and organizations were confirmed to have been infected with ransomware in 2025, including cases that seriously affected entire supply chains, including business partners. This situation is cited as the background for ransomware attack damage and attacks targeting supply chains and contractors ranking highly in the organization category.

Organizations using AI may face risks such as unintended information disclosure or infringement of others’ rights due to insufficient understanding of AI, problems caused by accepting AI-processed or AI-generated results without adequate verification, and the facilitation or increased sophistication of cyberattacks through AI misuse.

Individual threats target people who use digital devices such as computers and smartphones at home or elsewhere. Even when a threat has the same name, its methods continue to evolve and become more sophisticated, so the IPA states that it is important to check information on the latest methods and understand countermeasures suited to those changes.

Details

The organization category rankings are: first, damage from ransomware attacks; second, attacks targeting supply chains and contractors; third, cyber risks related to AI use; fourth, attacks exploiting system vulnerabilities; fifth, targeted attacks seeking confidential information; sixth, cyberattacks arising from geopolitical risks, including information warfare; seventh, information leakage and other incidents caused by insider misconduct; eighth, attacks targeting remote work and similar environments or mechanisms; ninth, DDoS attacks, or distributed denial-of-service attacks; and tenth, business email compromise.

In the organization category, the rankings of damage from ransomware attacks in first place and attacks targeting supply chains and contractors in second place had not changed for four consecutive years since 2023. Damage from ransomware attacks was covered for the 11th consecutive year and the 11th time, while attacks targeting supply chains and contractors were covered for the eighth consecutive year and the eighth time. Cyber risks related to AI use became a threat candidate for the first time in 2026 and entered the list in third place.

The individual category does not assign rankings; instead, it lists 10 items in Japanese alphabetical order. The items are theft of personal information from internet services; unauthorized logins to internet services; unauthorized use of internet banking; unauthorized use of credit card information; financial damage caused by support scams, including fake warnings; unauthorized use of smartphone payments; online defamation, abuse, and disinformation; theft of personal information and other data through phishing; harm to smartphone users caused by malicious apps; and demands for money through threatening or fraudulent methods using email, social media, and similar channels.

Unauthorized use of internet banking in the individual category had been outside the list since 2023, but it was selected in 2026 for the first time in four years and for the eighth time. The individual category does not show rankings, and all items require careful attention and countermeasures.

Cyber risks related to AI use include unintended information disclosure or infringement of others’ rights resulting from insufficient understanding of AI, problems caused by accepting AI-processed or AI-generated results uncritically without adequate verification, and the facilitation or increased sophistication of cyberattacks through AI misuse.

Organizations need to continuously collect information on security measures, implement appropriate security measures for the devices and services they use, and identify the risks each threat poses to their own organization’s business and structure. In addition, they should identify risks across their supply chains, including contractors, and confirm the status of countermeasures to the greatest extent possible.

Individuals should check information on the latest methods on the IPA website and understand countermeasures suited to changes in those methods. Although individual threats are listed without rankings in Japanese alphabetical order, all items require careful attention and countermeasures.

Detailed explanations of the 2026 edition are scheduled to be released sequentially on the IPA website from late February onward.

Related Articles