Key Points:
- Police reported a record 123 ransomware cases in the first half of the year, with manufacturing accounting for 37 incidents.
- Suspicious daily connection probes reached a record average of 13,687 attempts per IP address, up more than 4,000 from last year.
- Authorities recovered over 20.11 million encrypted files using an in-house tool shared globally with Europol.
- Business email scams caused 3.88 billion yen ($25 million) in losses across 127 cases, while unauthorized banking transfers hit 2.07 billion yen.
Corporate ransomware attacks surged to an all-time record of 123 cases during the first six months of the year, while daily cyber reconnaissance probes reached historic highs across public network connection points. Law enforcement agencies reported that automated scanning tools and malicious intrusion attempts averaged a record 13,687 suspicious access attempts per IP address every single day, jumping by more than 4,000 daily attempts compared to the same period last year. The unprecedented surge in malicious traffic highlights the escalating severity of digital extortion operations targeting critical industrial supply chains.
Small and medium-sized enterprises bore the brunt of extortion campaigns, accounting for 79 of the 123 confirmed ransomware incidents. Large multinational corporations suffered 31 attacks, while public institutions, hospitals, and educational facilities made up the remaining 13 cases. Cybercriminals frequently target mid-sized supplier networks because smaller contractors often maintain less sophisticated cybersecurity defenses while retaining privileged access credentials to the central enterprise databases of major corporate clients.
The manufacturing sector emerged as the primary industrial target, suffering 37 confirmed ransomware disruptions across automobile parts producers, machinery fabricators, and electronics component suppliers. Cybercrime investigators determined that unpatched virtual private network (VPN) gateways and remote desktop protocols served as the primary entry routes for malicious intruders. Hackers routinely scan internet IP address ranges to identify outdated enterprise networking appliances, exploit known firmware vulnerabilities, and deploy data-encrypting payloads across corporate networks within hours.
Recovering from these digital extortion incidents imposed severe financial and operational burdens on affected businesses. In the vast majority of cases, restoring encrypted servers, verifying clean offline backups, and rebuilding corrupted databases took companies more than a full month of operational downtime. To assist victimized organizations, national police cyber forensics teams deployed a proprietary data recovery software tool that has successfully decrypted and restored over 20.11 million compromised files. Law enforcement authorities shared the software tool with the European Union Agency for Law Enforcement Cooperation (Europol) to help international police units recover encrypted files worldwide.
Law enforcement authorities also intensified automated countermeasures against illicit online recruitment schemes known as “dark part-time jobs,” issuing 50,213 formal public warning replies to suspicious social media advertisements. That total represents an increase of 14,576 warnings compared to the prior year. Transnational crime syndicates use encrypted messaging apps and public social platforms to recruit impressionable young people for criminal tasks, including acting as financial money mules, physical cash couriers, and burglary accomplices. Police agencies are expanding their use of artificial intelligence algorithms to scan social feeds in real time and automatically post public warning notices on illicit job postings.
Phishing operations showed a notable volume decline while shifting toward more targeted credential theft. Total detected phishing emails designed to harvest online banking credentials and credit card details dropped to 731,000 messages, down by 465,000 from the previous year. Forensic tracing and server infrastructure analysis revealed that approximately 45% of all phishing campaigns originated from digital infrastructure located in China, making it the single largest geographic source of fraudulent messaging targeting domestic consumers.
Corporate finance departments faced severe losses from targeted Business Email Compromise (BEC) schemes, where sophisticated fraudsters impersonate corporate chief executives and business partners to authorize emergency wire transfers. Investigators confirmed 127 individual executive impersonation cases during the first half of the year, resulting in total corporate financial losses of roughly 3.88 billion yen ($25 million). Fraudsters typically use compromised executive email accounts and deepfake audio phone calls to convince accounting staff to transfer funds into overseas accounts.
Unauthorized online banking intrusions also drained substantial capital from consumer and business deposit accounts. Police recorded 253 cases of fraudulent online banking transfers during the six-month window, with stolen funds totaling approximately 2.07 billion yen. Cybercriminals utilized stolen mobile banking login credentials, automated SIM-swapping, and phishing-derived one-time verification passwords to transfer money into networks of disposable bank accounts operated by domestic money-laundering syndicates.
Law enforcement agencies took decisive legal action across the digital crime landscape, taking formal enforcement action in 7,607 cybercrime cases, an increase of 982 cases over the prior year. Money laundering investigations represented a massive portion of these enforcement actions, accounting for 1,945 prosecuted cases as specialized cybercrime units focused on seizing illicit crypto wallets, freezing fraudulent bank accounts, and dismantling underground cash-out networks that finance international criminal enterprises.
As cybercrime syndicates deploy automated scanning tools and artificial intelligence to discover software vulnerabilities, corporate organizations face mounting pressure to overhaul their digital security posture. Cybersecurity authorities urge businesses of all sizes to mandate multi-factor authentication with physical hardware keys, apply emergency firmware patches on all VPN gateway equipment, and maintain isolated, immutable offline backups. Establishing multi-layered cyber defenses remains essential to protect critical manufacturing supply chains and prevent debilitating ransomware disruptions.





