The Vulnerabilities in Securities Firms' Security

2025/05/30 10:00 (Updated 2025/08/01 14:54)
Editors of Iolite
Written by Noriaki Yagi
SHARE
  • sns-x-icon
  • sns-facebook-icon
  • sns-line-icon
狙われる証券会社のセキュリティホール

The Sophistication of Cyber Attacks and the Fragility of Securities Firms' Security Systems

In the spring of 2025, a serious security incident shook the Japanese securities industry. Mr. Testa, a well-known individual investor, had his brokerage account hacked, which was then used to carry out large-scale fraudulent transactions.

This incident exposed the sophistication of cyber attacks targeting individual investors' assets and the vulnerabilities in securities firms' security systems that should counteract these threats. Furthermore, it has become clear that such damages are not isolated incidents but rather systemic issues affecting the entire industry.

This article will examine the reality of the security breaches in the securities industry, starting with the surge in account takeovers in 2025, exploring the background of these issues, and discussing the necessary measures moving forward.

The Reality of Unauthorized Access That Breached Security

Mr. Testa announced on X that his Rakuten Securities account was hacked on May 1. The incident began with a two-factor authentication confirmation email that he did not recognize. Suspecting something was amiss, he logged in and checked his transaction history, only to find numerous unfamiliar transactions already made.

Surprisingly, even while he was logged into the account, the fraudulent transactions continued, and it was only after he changed his password that the unauthorized activities finally ceased.

This situation cannot be solely attributed to individual negligence. According to the Financial Services Agency, from February to mid-April 2025, there was a sharp increase in unauthorized access incidents at domestic securities firms, with the number of cases exceeding 1,400 and the total amount of transactions affected reaching 95 billion yen.

It is undeniable that organized cybercrime is now widely spread, far beyond random incidents.

The article is for members only. Please sign up to continue reading.

SHARE
  • sns-x-icon
  • sns-facebook-icon
  • sns-line-icon
Side Banner
Side Banner
MAGAZINE
Iolite Vol.18

Iolite Vol.18

March 2026 issueReleased on 2026/01/30

Interview: Iolite FACE vol.18 Takeshi Chino, Representative Director, Binance Japan PHOTO & INTERVIEW: Mai Shin Special Features: “Future Money — The Current State of Value Transfer” “Upcoming Amendments to Japan’s Crypto Asset Regulations” “The Reality of IEOs” Crypto Journey Beyond a Treasury Company: Becoming an Ethereum Evangelist — The Essence and Determination Behind HODL1’s Digital Asset Treasury (DAT) Strategy Interview with Hiroki Tahara, Representative Director, Kusim Inc. (now HODL1) Series: “Expert Perspectives on Interpreting Volatile Crypto Markets” — Kasou NISHI Series Tech and Future — Toshinao Sasaki …and more

MAGAZINE

Iolite Vol.18

March 2026 issueReleased on 2026/01/30
Interview: Iolite FACE vol.18 Takeshi Chino, Representative Director, Binance Japan PHOTO & INTERVIEW: Mai Shin Special Features: “Future Money — The Current State of Value Transfer” “Upcoming Amendments to Japan’s Crypto Asset Regulations” “The Reality of IEOs” Crypto Journey Beyond a Treasury Company: Becoming an Ethereum Evangelist — The Essence and Determination Behind HODL1’s Digital Asset Treasury (DAT) Strategy Interview with Hiroki Tahara, Representative Director, Kusim Inc. (now HODL1) Series: “Expert Perspectives on Interpreting Volatile Crypto Markets” — Kasou NISHI Series Tech and Future — Toshinao Sasaki …and more