Finance & EconomyWeb3.0

The Vulnerabilities in Securities Firms' Security

2025/05/30 10:00
Editors of Iolite
Written by Noriaki Yagi
SHARE
  • sns-x-icon
  • sns-facebook-icon
  • sns-line-icon
狙われる証券会社のセキュリティホール

The Sophistication of Cyber Attacks and the Fragility of Securities Firms' Security Systems

In the spring of 2025, a serious security incident shook the Japanese securities industry. Mr. Testa, a well-known individual investor, had his brokerage account hacked, which was then used to carry out large-scale fraudulent transactions.

This incident exposed the sophistication of cyber attacks targeting individual investors' assets and the vulnerabilities in securities firms' security systems that should counteract these threats. Furthermore, it has become clear that such damages are not isolated incidents but rather systemic issues affecting the entire industry.

This article will examine the reality of the security breaches in the securities industry, starting with the surge in account takeovers in 2025, exploring the background of these issues, and discussing the necessary measures moving forward.

The Reality of Unauthorized Access That Breached Security

Mr. Testa announced on X that his Rakuten Securities account was hacked on May 1. The incident began with a two-factor authentication confirmation email that he did not recognize. Suspecting something was amiss, he logged in and checked his transaction history, only to find numerous unfamiliar transactions already made.

Surprisingly, even while he was logged into the account, the fraudulent transactions continued, and it was only after he changed his password that the unauthorized activities finally ceased.

This situation cannot be solely attributed to individual negligence. According to the Financial Services Agency, from February to mid-April 2025, there was a sharp increase in unauthorized access incidents at domestic securities firms, with the number of cases exceeding 1,400 and the total amount of transactions affected reaching 95 billion yen.

It is undeniable that organized cybercrime is now widely spread, far beyond random incidents.

The article is for members only. Please sign up to continue reading.

SHARE
  • sns-x-icon
  • sns-facebook-icon
  • sns-line-icon
Side Banner
Side Banner
MAGAZINE
Iolite Vol.14

Iolite Vol.14

July 2025 issueReleased on 2025/05/30

Interview Iolite FACE vol.14 Charles Hoskinson, founder and CEO of Cardano/Input Output Global PHOTO & INTERVIEW Mariko Mabuchi Special feature: "Considerations on cryptocurrency-related policies in Japan and the US", "Blockchain guide from Japan", "Huge position liquidation occurs at Hyperliquid! A new, unanticipated crisis in decentralized finance", "Sakana AI, a generative AI startup from Japan that is attracting a lot of attention", "Prepare for a recession: correlation between finance and anomalies" Crypto Journey: "Web 3.0 from the perspective of the 'King of Debate'" Interview with Hiroyuki Special series: Virtual Nishi: "Cryptocurrency market trends and key points for interpreting them" Series: Tech and Future Toshinao Sasaki, etc.

MAGAZINE

Iolite Vol.14

July 2025 issueReleased on 2025/05/30
Interview Iolite FACE vol.14 Charles Hoskinson, founder and CEO of Cardano/Input Output Global PHOTO & INTERVIEW Mariko Mabuchi Special feature: "Considerations on cryptocurrency-related policies in Japan and the US", "Blockchain guide from Japan", "Huge position liquidation occurs at Hyperliquid! A new, unanticipated crisis in decentralized finance", "Sakana AI, a generative AI startup from Japan that is attracting a lot of attention", "Prepare for a recession: correlation between finance and anomalies" Crypto Journey: "Web 3.0 from the perspective of the 'King of Debate'" Interview with Hiroyuki Special series: Virtual Nishi: "Cryptocurrency market trends and key points for interpreting them" Series: Tech and Future Toshinao Sasaki, etc.