Skip to main content
BilgeQor

Verified reported cyber incident context · Japan / JPCERT/CC

Cyber incident reports received by Japan’s JPCERT/CC

Market context — not industry-specific evidence

JPCERT/CC received 74,096 incident reports in fiscal year 2025, 61% more than the previous fiscal year’s 46,038 reports. From 1 January to 31 March 2026, it received 15,345 reports containing 10,262 incidents. These figures describe reports received by Japan’s coordination centre for incidents occurring domestically and overseas; they are not the percentage of Japanese businesses identifying or experiencing attacks, and they are not industry-specific findings for the sector shown on this page. The same quarterly report also shows 9,293 reported phishing sites, including 7,112 reports involving domestic brands, and highlights financial-related sites for domestic-brand phishing reports and e-commerce sites for overseas-brand phishing reports as leading spoofing contexts.

Japan coordination-centre context · JPCERT/CC reported incidents · domestic and overseas incident reportsFiscal year 2025 annual comparison · Category context: 1 January – 31 March 2026

Increase in incident reports received

Fiscal year 2025 compared with previous fiscal year
61%
Unit
percent
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC

Incident reports received by JPCERT/CC increased from 46,038 in the previous fiscal year to 74,096 in fiscal year 2025.

Official JPCERT/CC incident-report volume change only; this is not the percentage of Japanese businesses identifying or experiencing cyber attacks and not industry-specific evidence.

Selected reported incident categories

Phishing sites
90.6%
Unit
percent
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC
Scans seeking system weaknesses
1.5%
Unit
percent
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC

From 1 January to 31 March 2026, JPCERT/CC received 15,345 reports containing 10,262 incidents, including 9,293 phishing-site incidents and 156 scan incidents.

Direct reported-category context from JPCERT/CC only. These values are not Japanese-business incident rates and not sector-specific threat findings.

Reported phishing sites by brand context — counts

All reported phishing sites
9,293
Unit
reported phishing sites
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC
Domestic brands
7,112
Unit
reported phishing sites
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC
Overseas brands
899
Unit
reported phishing sites
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC
Unknown brand
1,282
Unit
reported phishing sites
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC

Selected phishing-brand category shares

Financial sites among domestic-brand reports
69.1%
Unit
percent
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC
E-commerce sites among overseas-brand reports
65.3%
Unit
percent
Period
Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scope
Incident reports and selected incident categories received by JPCERT/CC

JPCERT/CC phishing-brand reporting context only. Financial-site and e-commerce-site labels describe spoofed brand categories in reported phishing sites; they are not finance-sector or e-commerce-sector incident rates.

Source: JPCERT/CC, Quarterly Report, January–March 2026

Scope: Official JPCERT/CC reported-incident context. JPCERT/CC accepts incident reports concerning incidents occurring domestically and overseas and coordinates with relevant organisations where required. These figures describe report volume and selected reported-incident categories; they do not measure the percentage of Japanese businesses identifying or experiencing cyber attacks, do not establish incidents limited to Japanese organisations, and do not provide industry-specific performance, compliance, certification or security-outcome evidence.

Methodology: Official JPCERT/CC reported-incident context. JPCERT/CC accepts reports concerning computer-security incidents occurring domestically and overseas and coordinates with relevant organisations as Japan’s point of contact where coordination or support is required. In the source report, report count means the total number of reports submitted through forms or email; incident count means the number of incidents contained in those reports, with multiple reports relating to one incident treated as one incident; coordination count means cases in which JPCERT/CC requested investigation or problem resolution from site administrators or other relevant parties. The admitted indicators describe incident reports received by JPCERT/CC and selected reported-incident categories only. They do not measure the percentage of Japanese businesses identifying or experiencing cyber attacks, do not establish incidents limited to Japanese organisations, and do not provide industry-specific performance, compliance, certification or security-outcome evidence.

Accessible data table
Verified Japan JPCERT/CC reported cyber incident context data from JPCERT/CC, Quarterly Report, January–March 2026, reporting period Annual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31..
MetricValueSourceScopeReporting period
Fiscal year 2025 compared with previous fiscal year61% percentJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Phishing sites90.6% percentJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Scans seeking system weaknesses1.5% percentJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
All reported phishing sites9,293 reported phishing sitesJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Domestic brands7,112 reported phishing sitesJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Overseas brands899 reported phishing sitesJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Unknown brand1,282 reported phishing sitesJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
Financial sites among domestic-brand reports69.1% percentJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.
E-commerce sites among overseas-brand reports65.3% percentJPCERT/CC, Quarterly Report, January–March 2026Incident reports and selected incident categories received by JPCERT/CCAnnual statistics for fiscal year 2025, together with quarterly category statistics for 2026-01-01 to 2026-03-31.

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Fraud
  • Data Theft
  • Regulatory Non-Compliance

Digital surfaces in scope

Banking AppsWealth PortalsTrading APIs

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.