FORSMILE
JA
ネット安全2026/09/23

Two-Step Verification Is Not Enough: 19,207 Brokerage Account Break-Ins

Japan's FSA updated its figures on 9 September 2026: 19,207 unauthorised logins and 10,639 unauthorised trades in online brokerage services. Here is how real-time phishing defeats one-time codes, and what to do today.

Back to Blog

Two-step verification is not saving brokerage accounts. "I use a one-time code, so I am fine" is currently the most dangerous assumption you can hold.
On 9 September 2026 Japan's Financial Services Agency updated its warning and published the numbers for unauthorised access and trading in online brokerage services.

For January 2025 through August 2026 the totals are: 19,207 unauthorised logins and 10,639 unauthorised trades. Roughly 436.8 billion yen of holdings were sold without permission, and roughly 383.7 billion yen was spent buying other securities with the proceeds.

What actually happens inside the account

The FSA describes the typical pattern plainly: the intruder operates the account, sells the securities held in it, and uses the proceeds to buy small-cap stocks in Japan or overseas. What is left in the victim's account is those small-cap shares.
In other words money is not withdrawn — the assets are swapped for something else. Watching your cash balance alone will not reveal it.

How two-step verification gets bypassed

Real-time phishing relays what you type straight to the genuine site
  • 1. An email or SMS impersonating a real broker arrives and you open the link
  • 2. A convincing replica of the site loads. It is built so that appearance alone will not give it away
  • 3. You enter your ID and password. At this moment the attacker has them
  • 4. The attacker immediately uses them to log in to the genuine site
  • 5. The genuine site asks for a one-time code, so the fake site shows the same field. The digits you type flow straight through

The fact that a one-time code works only once is no defence here. All the attacker needs is the few dozen seconds between you typing it and it expiring.
That is why the FSA is pushing phishing-resistant multi-factor authentication such as passkeys. A passkey will not authenticate at all unless the site you are on is the correct domain, so there is no opening to hand it to a fake.

The recent numbers are falling — read them carefully

Month by month, the peak was April 2025: 5,490 unauthorised logins, 3,033 unauthorised trades, about 162.5 billion yen sold. The latest months are far lower, at 18 cases in July 2026 and 39 in August.
But the FSA states explicitly that these are provisional figures based on incident dates as reported so far by the firms, and that unauthorised access and trading not yet identified may exist. The more recent the month, the more room it still has to grow. Reading this as "it is over" is premature.

One more caveat. The FSA also notes that the "sold" and "bought" amounts do not equal customers' losses. The 436.8 billion yen figure is not a loss total. If you pass these numbers on, pass the caveat on with them.

What to do today

  • Check whether your broker or bank offers passkeys, and set one up today. The FSA asks users to enable stronger authentication "promptly once it is offered"
  • Bookmark the correct URL and only ever enter from there. Never log in from a link in an email or SMS
  • Enable multi-factor authentication and notifications not just for login but for trades, withdrawals and changes to the withdrawal bank account. The swap pattern happens without any withdrawal at all
  • Check the contents of your account regularly — not the balance, but whether the securities you hold have changed
  • Do not reuse passwords. Where a password is unavoidable, make it as long as possible and avoid anything guessable

IPA lists unauthorised login every single year

In IPA's "Top 10 Information Security Threats 2026", published on 29 January 2026, the individual-facing list includes "unauthorised login to internet services" for the 11th consecutive year, "theft of personal information through phishing" for the 8th consecutive year, and "fraudulent use of internet banking" for the 8th time, returning after four years.
Note that the individual-facing list is not ranked. It is ordered phonetically, so "number N, therefore more urgent" is not a valid reading. If you see a ranked version elsewhere, check IPA's original.

🛡Shemihaza's Quiz — Can you spot it?

You opened a link in an email from your broker, entered your ID and password on a page that looked genuine, and now it is asking for your one-time code. What is the safest thing to do?

Three lines to forward to your family

  • Never log in to a brokerage or bank from a link in an email or SMS. Go in from a bookmark
  • There is a technique that defeats one-time codes. If you entered details on a fake site, change the password and call the firm immediately
  • In Japan, call 188 (Consumer Hotline) for payment trouble and #9110 (police consultation line) if you suspect fraud. Both work without an area code

Where to get help

If you see a login or trade you do not recognise, contact your broker first. Japan's FSA also runs a Financial Services Users' Consultation Office (navi-dial 0570-016811, or 03-5251-6811 from IP phones, weekdays 10:00–17:00).
If you suspect fraud, the Japanese police consultation line is #9110. For payment and contract trouble, the Consumer Hotline is 188, both dialled without an area code. If you are in immediate danger, call 110.
If an account has already been taken over, the guide linked below covers how to recover it.

Related articles