FORSMILE
JA
ネット安全2026/09/27

Weekly Online Safety Recap (21-26 Sept): Four Entry Points and a Four-Question Quiz

Every one of this week’s four consumer stories turned on an entry point the other side had prepared first: an unexplained bill, account takeover on a trading site, a police officer on a video call, and an easy-money job advert. None of them can be told apart by appearance, and in none of them is the thing to check the contact the sender gave you. For engineers, three alerts, all confirmed as exploited. Quiz included.

← Back to Blog

Hello! Shemihaza here, your Sentinel. Let us look back over the week of 21 to 26 September 2026.

Online safety this week: four entry points, and what to do next

The four entry points covered between 21 and 26 September, and what to do about each (built from the sources cited in those articles).

21 Sept: unexplained bills. 330,497 complaints from people aged 65 and over

Built on the National Consumer Affairs Center of Japan report published on 16 September 2026 covering consumer complaints from people aged 65 and over in fiscal 2025. There were 330,497 such complaints, 37.7% of all complaints received.
The point of the article was that "my parents do not use the internet, so they are fine" does not hold. The share of mail-order and online complaints is highest in the 65 to 69 bracket and falls as age rises — the generation that uses the internet is now entering the older age bands.
If a bill you do not recognise arrives, do not call the number printed on it. Calling tells the sender the line reaches a real person.

23 Sept: 19,207 account takeovers on trading sites, and one-time passwords did not stop them

Built on the Financial Services Agency figures updated on 9 September 2026: 19,207 unauthorised accesses and 10,639 unauthorised trades reported across online securities trading services.
What matters is that these went through even where one-time passwords were in use. If a fake site captures the code and relays it to the real site in real time, a code that works only once still works that once.
The fix is to move to a factor that phishing cannot capture. Switch to a passkey wherever it is offered, and make sure login notifications are on.

24 Sept: an AI-generated face on a video call, and special fraud losses up 51.7% overall

Built on the National Police Agency report on threats in cyberspace for the first half of 2026, published in September 2026. It records a case in which police arrested a suspect who generated a face with AI, made a video call and posed as a police officer (page 29 of the report). The report describes the case as cleared by police and the suspect arrested in August 2025 after extradition; it does not state a prosecution outcome.
Separately, losses from special fraud as a whole in the first half of 2026 came to about 181.62 billion yen, up 51.7% year on year, which the report calls the worst on record (page 15). That total covers the whole category, not this technique alone.
Quoting the report precisely, the AI was used so that the face of the suspect playing the officer could not be identified — generated to hide identity. A uniform-like outfit, a fake police ID held up to the camera and the AI-generated face were combined within a single call.
"I can see their face, so it is real" no longer works as a check. Every visual element can be arranged. Hang up, and call the police consultation line #9110 in Japan yourself to verify.

26 Sept: 12,516 reports judged to be criminal recruitment, and 50,213 police warning replies

From the same report. In the first half of 2026, 12,516 of the reports received by the Internet Hotline Center (IHC) were assessed as recruiting people to commit crimes, roughly 97% more than the same period a year earlier (page 32). Note that this counts reports the hotline received, not the internet as a whole. Police posted 50,213 individual warnings as replies to such posts, up 41% year on year (page 67).
That is exactly why you should read the replies before you apply — a police warning may already be sitting there.
The other point is sequence. The advert promises easy, well-paid work, and the actual job is revealed only after you apply and start exchanging messages (National Police Agency material from July 2023). If identification documents or your home address are requested first, stop there.

For engineers: this week’s security alerts

Three this week. All three were added by CISA to the Known Exploited Vulnerabilities catalogue, meaning exploitation was actually observed.
All three remediation deadlines have already passed as of this recap. If any of them is still outstanding, the task is no longer meeting a deadline but checking whether you were compromised.

Linux kernel CVE-2025-39682 (CVSS v3.1: 7.1 HIGH): three parties scored it differently

A flaw in the kernel TLS (kTLS) receive path. If you do not use kTLS it does not affect you — `/proc/net/tls_stat` shows whether it is in use.
The reason this one is worth recording is the disagreement over severity: NIST rated it 7.1 HIGH, kernel.org 9.8, and Red Hat 7.0. Do not pass the number along on its own — state whose score, on which CVSS version, and then decide against your own configuration. The CISA deadline was 21 September.
For the record, our 18 September piece covered only two of the three additions to KEV that day, so this article existed to close our own gap.

Zyxel GS1900 switches CVE-2026-7273 (CVSS v3.1: 8.8 HIGH): 996 units already breached

A stack-based buffer overflow. Zyxel shipped fixed firmware on 16 June 2026, yet the flaw was added to KEV on 21 September — which means devices went more than three months without the update.
996 units across 48 countries were actually breached, and 564 of those were still using the factory credentials. Updating the firmware is not the whole job; change the default password at the same time. Ten models are affected.

F5 BIG-IP APM CVE-2026-94127 (CVSS v3.1: 9.8 CRITICAL): scope depends on configuration

Unauthenticated remote code execution. Added to KEV on 22 September with a 25 September deadline.
A 9.8 score does not mean every box running BIG-IP APM is in scope. Only deployments configured as an OAuth authorisation server are affected; using it solely as an OAuth client is out of scope. When you take inventory, look at configuration rather than at whether the product is present. The affected and fixed versions are defined by F5’s own advisory, K000162605.

This week’s quiz: four questions

If you read this week’s articles you should spot all four. Try the first two with your family and the last two with colleagues.

🛡Shemihaza's Quiz — Can you spot it?

A postcard arrives at your parents’ house saying "there is an unpaid balance for a paid website; please contact us today", with a phone number printed on it. What should you do first?

🛡Shemihaza's Quiz — Can you spot it?

A video call comes in. Someone in uniform appears on screen and says, "I am from the prefectural police. Your bank account has been used in a fraud." You can see their face and the conversation flows naturally. Is that enough to treat it as genuine?

🛡Shemihaza's Quiz — Can you spot it?

You look up a vulnerability and find NVD rating it 7.1 HIGH, the upstream project listing 9.8, and your distribution scoring it 7.0. How should you report it internally?

🛡Shemihaza's Quiz — Can you spot it?

Your company runs F5 BIG-IP APM and CVE-2026-94127 has been added to KEV. Which statement about scope is correct?

📦
Search Amazon US for related books and tools
antivirus software phishing protection
Search Amazon US → (affiliate link). As an Amazon Associate, we earn from qualifying purchases.

This week’s articles

Three lines to forward to your family

  • ▸If a bill you do not recognise arrives, do not call the number printed on it. Calling tells the sender the line reaches a real person. In Japan, dial the consumer hotline 188 (no area code) yourself.
  • ▸Seeing a face on a video call is not proof it is genuine. A fraudster who generated a face with AI and posed as a police officer has actually been arrested (National Police Agency, published September 2026). Hang up, then call the police consultation line #9110 in Japan yourself.
  • ▸Before you apply to an "easy, well-paid" advert, read the replies underneath it. Police posted 50,213 warning replies in the first half of 2026. The real job is revealed only after you apply, so if you are asked for ID or your home address first, stop there.

Where to get help

If you realise something has gone wrong, working through it calmly and in order is enough. There is nothing to be ashamed of.

Paid money, or stuck with a bill — consumer hotline 188 (no area code; Japan only)
Possible fraud or crime, and unsure who to ask — police consultation line #9110 (Japan only)
Account taken over, or you opened something suspicious — the emergency guide linked below has step-by-step instructions by symptom.
Readers outside Japan should use their own national consumer and police reporting lines; the two numbers above reach Japanese services only.

参考リンク / References
Related articles