FORSMILE
JA
ネット安全2026/09/19

Phishing Reports Jumped 24.5% in August — the Sender Field Proves Nothing

Japan's Council of Anti-Phishing published its August figures on 18 September 2026: 82,338 reports, up 24.5% on July. Five impersonated brands account for about 70%, and a real-looking sender domain is no longer something you can decide on.

Back to Blog

Good evening. This is Shemihaza, your sentinel.

On 18 September 2026 Japan's Council of Anti-Phishing published its figures for August.

82,338 reports — 16,219 more than July, an increase of about 24.5%.

The number is not the point. This is: you can no longer tell by looking at the sender.

From the same report: of the phishing mails that arrived at one research mailbox during August, about 32.3% carried a real, existing service's mail domain in the From field — a share that rose from the previous month.

That is a count from a single monitoring address, not a share of all phishing mail, and it describes what was written in the From field rather than where the mail actually came from.

What it does show is that the sender field is not something you can decide on. "Check the sender address" no longer carries the weight it used to.

Which brands were used in August

As a share of all reports. The top five brands alone accounted for about 69.9%.

  • Amazon, about 26.1% — the largest, though the Council describes it as declining
  • Apple, about 16.1%rising
  • ANA, about 12.5%rising
  • Saison Card and the Statistics Bureau — the next two most reported
  • Ten brands each drew over 1,000 reports, and together those ten made up about 83.8% of the total

By sector: e-commerce about 43.3%, credit and consumer finance about 29.0%, airlines about 13.3%, government bodies about 5.2%, banking about 2.4%.

The line worth noticing is that credit, airline and government impersonation are all described as having surged. E-commerce remains the largest but is declining — the weight of the attack is shifting. If your mental model is "watch out for fake Amazon mails", an airline or a government agency is exactly where you will be caught.

How it unfolds

The four steps of a phishing attempt, with the brands most reported in August 2026. Figures from the Council of Anti-Phishing Japan's monthly report, published 18 September 2026.

The destination domain is no better a guide

The same report is equally blunt about where the links go.

About 17.0% of the reported phishing URLs used a hostname on amazonaws.com — Amazon's legitimate cloud domain. Others sat on docs.google.com and sendgrid.net, also legitimate services.

So "does the domain look suspicious?" fails as a test on its own. Put a fake page on a large cloud or form service and the domain in the address bar is one you have seen a hundred times.

One more figure: URLs whose hostname was reused ten or more times made up about 52.0% of all reports.

The report explains the pattern as the same hostname with only the parameters changed.

Separately from that figure, the Council works with JPCERT/CC to pass reported phishing URLs to member companies that provide blocking software and services. So reporting still beats "I didn't fall for it, so never mind".

What you can do today

  • Never enter through a link in a mail or SMS. It is the most reliable defence available, because it depends on neither the sender nor the domain. If the company genuinely wants something, open their app or your own bookmark — and if you cannot find the same notice there, ask through their official contact channel.
  • Do not treat a genuine sender domain as proof. Among the phishing mails reaching one research mailbox in August, about 32.3% carried a real existing service's domain in the From field. The From field is not evidence.
  • A familiar destination domain is not proof either. About 17.0% of reported URLs were hostnames on amazonaws.com. Fake pages get hosted on legitimate services.
  • Be alert to airlines, card issuers and government bodies. Those three sectors all surged in August (credit about 29.0%, airlines about 13.3%, government about 5.2%). Watching only for e-commerce leaves that gap open.
  • Do not reuse passwords. Give one away and the damage stays in one place.
  • Report suspicious mail before deleting it. The Council of Anti-Phishing accepts reports.

If you opened it, or typed something in

  • If you entered nothing and downloaded nothing, harm is unlikely. Clicking a link does not empty your account. That is not the same as "opening it is always safe": if a file downloaded on its own, or you were prompted to install an app or grant a permission and did, update your OS and apps and run a security scan. Otherwise the items below are enough.
  • If you entered an ID and password — change that password, reaching the service through its app or your own bookmark. Change it everywhere else you used the same one.
  • If you entered a card number — call the card issuer to freeze and reissue. The number is on the back of the card or in the issuer's official app.
  • If you entered or replied with a one-time code — move quickly. Those codes are used within minutes. Change the password and contact the service.
  • If unfamiliar charges or login alerts appear — in Japan, contact a police cybercrime desk or #9110; for payment disputes, 188.
  • Keep the mail and take screenshots. What you entered and when is what makes a consultation useful.
🛡Shemihaza's Quiz — Can you spot it?

A mail arrives from ANA. The sender domain is ANA's real one, and the link points at a familiar major cloud domain. What should you do?

Three lines to forward to your family

  • Phishing reports rose 24.5% in August. Amazon is still the most impersonated but declining, while Apple and ANA are both rising. A genuine-looking sender domain is not something you can rely on.
  • Do not enter through links in mail or SMS. Open the app or your bookmark and check there instead — and if the notice is not there, use the company's official contact channel.
  • If you typed something in: change the password and call your card issuer. In Japan, #9110 for suspected crime, 188 for payment trouble.

#9110 is Japan's police consultation line for non-emergency matters — the right call for suspected fraud or cybercrime, along with the prefectural cybercrime desks.

188 is the consumer hotline, routing to your local consumer affairs centre, and is the right call for payment and contract disputes.

One last thing. What makes this hard is that "look carefully and you'll spot it" is running out of road.

A real sender domain, a link on a well-known cloud, natural wording. The closer you look, the fewer tells there are left to find.

So narrow your defence to one rule. Do not enter through the link in the message. Open the app or the bookmark yourself. A genuine-looking sender and a famous domain do not weaken that habit — and if the notice is not there, the official contact channel settles it.

Related articles