Hello! Shemihaza here, your Sentinel. Let us look back over the week of 28 September to 3 October 2026.
Online safety this week: four places to stop
28 Sept: where the money leaves. 72.2% of transfer losses go through online banking
Built on the National Police Agency provisional figures for the first half of 2026 (January to June), published on 30 July 2026. Of the 103.34 billion yen lost through transfers the victim made, 72.2% went out through online banking; for social-media investment fraud it is 79.8%.
A cash machine or a branch counter means going out, and someone may speak to you there. The same document says that staff speaking to customers at convenience stores and financial institutions prevented 9,685 cases and 10.83 billion yen of losses. Online banking has no such step.
So the thing to do today is lower the transfer limit you do not use. How you raise it again, and how long that takes, differs between banks, so read your own bank’s instructions first.
29 Sept: being moved onto LINE. People meet scammers everywhere, but 96.0% of payments run on LINE
Same source. For social-media investment fraud, the place of first contact is spread thin, and the NPA itself writes that initial-contact tools are diversifying (even the most common, Instagram, is only 23.8%).
Yet by the time money is taken, LINE accounts for 5,658 cases, 96.0%, and 78.12 billion yen, 97.9% by value.
So the moment you are asked to move to LINE is the fork. To be fair, nothing here shows a problem with LINE; it is simply the most-used contact tool in Japan, so that is where cases gather. The statistic does not track whether the contact tool changed along the way.
When asked to move over, stop once, and the moment money is requested, tell someone.
30 Sept: the tax-office email. "Install the e-Tax app" means it is fake; genuine mail rarely has a URL
Built on the emergency alert the Council of Anti-Phishing Japan issued on 30 September 2026 about emails impersonating the National Tax Agency to push an Android app. The council confirmed the mailings were still going out as of 10:00 that day.
The tax agency itself publishes three tells. (1) Genuine e-Tax mail does not, as a rule, put a URL in the body. (2) It comes only from info@e-tax.nta.go.jp. (3) There is no smartphone app called the "e-Tax app" (the Android version ended on 4 January 2021). Point 1 says "as a rule", so a link does not make it fake by itself; treat it as a reason to be suspicious.
That does not mean no official app is ever needed: the route through the My Number portal requires the My Number app. But that one is reached through the tax agency’s own guidance and a store listing, which is not the same as an app a mail link tries to make you install.
Skip the link in the email and open e-Tax yourself.
3 Oct: when told to head to the ATM. Refund fraud fell 10.0% in cases and rose 7.2% in losses
Built on the National Police Agency provisional figures to the end of August 2026, published on 2 October 2026. Refund fraud cases fell 10.0% to 2,058, while losses rose 7.2% to 4.65 billion yen. Cases down, money up.
By my own calculation the average per case rose from about 1.90 million yen to about 2.26 million yen (approximate, because the published losses are rounded to 0.1 billion yen). The statistic does not say why.
The agency’s own line is: "Money is never returned to you at an ATM. Ever." If a caller says "take your phone and head to the ATM now", hang up without weighing what they say. To check, call back a number you looked up, never the one you were given.
For engineers: this week’s security alerts
Three this week. None of the three is in CISA’s Known Exploited Vulnerabilities catalogue (I checked all four CVEs against the catalogue version dated 2 October 2026).
Absence from the catalogue is not evidence that nothing is being exploited. Last week’s three were all in KEV, and the story was a deadline. This week’s three are decided not by KEV, but by your version, the path you use, and your model’s row.
Buffalo WSR-300HP and WEX-G300, CVE-2026-86530 and CVE-2026-95104 (CVSS v4.0: 8.6 HIGH and 8.7 HIGH): decide by version
Only two models are affected, the WSR-300HP router and the WEX-G300 range extender, and the fixed firmware is Ver. 2.55 for the WSR-300HP (released 25 August) and Ver. 1.71 for the WEX-G300 (released 3 September). Automatic updates are on by default, but there is older firmware that predates the automatic-update feature (before Ver. 2.30 on the WSR-300HP, before Ver. 1.30 on the WEX-G300). And the changelog for the fixed firmware does not mention a vulnerability fix. Do not decide by "I never turned auto-update off" or "the changelog only lists bug fixes"; decide on whether the installed version is the fixed one or later.
An update. My 28 September article said the CVEs were not yet in NVD; when I checked on 4 October, both were in NVD (status: Awaiting Analysis). The scores come from JPCERT/CC: 8.6 on CVSS v4.0 for CVE-2026-86530 and 8.7 for CVE-2026-95104 (both HIGH), matching the numbers in that article.
Authlib CVE-2026-96760 (CVSS v3.1: 9.8 CRITICAL, scored by CISA-ADP): no fix, and the reachable path is narrow
When I checked PyPI on 4 October 2026, the latest Authlib was still 1.8.0 (released 30 August), so there is no fixed release. The CVE records the affected range as 1.7.2 and below, but when I checked on 29 September the relevant file in 1.8.0 was byte-identical to 1.7.2 (I did not go on to demonstrate that an attack works).
The update is the CVSS score. My 29 September article said no score had been assigned; NVD now lists a CVSS v3.1 score of 9.8 (CRITICAL) assigned by CISA-ADP. NVD’s own analysis is still pending (Awaiting Analysis), and the CVE is not in KEV.
A 9.8 does not mean every use of Authlib is exposed. Only the path that accepts the JSON serialisation of a JWS is affected, and `jwt.decode()` is not. First look for any place where `deserialize()` is handed a string from outside, and consider calling `deserialize_compact()` explicitly (this is not a vendor workaround; it is derived from how the code behaves).
Fujifilm and Sharp MFPs, CVE-2026-78249 (CVSS v4.0: JVN 6.9, Fujifilm 6.8, both MEDIUM): the fixed version depends on your model’s row
Fujifilm lists 28 rows; Sharp lists only two North America models, the BP-1360M and BP-1250M. For Fujifilm, 19 rows are fixed at 1.50.6 but nine series use other numbers (the Apeos 3061 series is 1.0.4, the C3061 series 1.2.0, and so on), so remembering "just go to 1.50.6" will mislead you. For Sharp, the Japanese and global pages describe the affected versions differently, so do not decide for yourself; ask the service contact.
The attack presupposes a login to the admin interface. If you cannot update yet, change the admin password from its default and keep the MFP off the direct internet. Fujifilm says no attack exploiting this had been observed as of its notice.
On the score: NVD now lists CVSS v4.0 6.8 (MEDIUM) assigned by Fujifilm (status: Deferred). The difference from the 6.9 in JVN, which my 30 September article used, is one character of the attack-vector metric, and both are MEDIUM.
This week’s quiz: four questions
If you read this week’s articles you should spot all four. Try the first two with your family and the last two with colleagues.
📦This week’s articles
- An ATM Never Pays Money Back: Japan’s Refund Fraud Fell 10.0% in Cases but Rose 7.2% in Losses↗
- Do Not Open the Link in That Tax-Office Email: Japan’s NTA Is Being Impersonated to Push an Android App↗
- Fujifilm and Sharp MFP CVE-2026-78249: Update the Firmware and Change the Admin Password↗
- Scattered Entry Points, One Exit: 97.9% of Social-Media Investment Fraud Losses Run Through LINE↗
- Authlib CVE-2026-96760: A JWS With No Signature Comes Back Verified, and 1.8.0 Is Not a Fix↗
- Where Fraud Money Now Leaves From: 72.2% of Transfer Losses Go Through Online Banking↗
- Buffalo WSR-300HP and WEX-G300: CVE-2026-86530 and the Firmware That Was Already Out↗
Three lines to forward to your family
- ▸If you are told "head to the ATM", "move to LINE" or "install this app", stop right there. This week’s four tactics each had one place to stop.
- ▸If you use online banking, lower the transfer limit you do not use. 72.2% of transfer losses went through online banking (National Police Agency, first half of 2026). Raising it again differs by bank, so check your own bank’s instructions first.
- ▸If in doubt, consult someone yourself rather than a number the other side gave you. In Japan, the police consultation line is #9110, and for payment or contract trouble the consumer hotline is 188 (no area code).
Where to get help
If you realise something has gone wrong, working through it calmly and in order is enough. There is nothing to be ashamed of.
Paid money, or stuck with a bill — consumer hotline 188 (no area code; Japan only)
Possible fraud or crime, and unsure where to turn — police consultation line #9110 (Japan only)
Account taken over, or opened something suspicious — the emergency guides below walk through each situation.
- Emergency guides by symptom (this site; six situations)↗
- National Police Agency: police consultation line #9110 (list of prefectural contacts)↗
- National Consumer Affairs Center: consumer affairs centres nationwide (hotline 188)↗
- National Police Agency: where to report cyber incidents↗
- National Police Agency: special fraud cases and arrests to the end of August 2026, provisional (published 2 October 2026; refund fraud cases and losses)↗
- National Police Agency: special fraud in the first half of 2026, provisional (PDF; online-banking share of transfer losses, contact tools in social-media investment fraud)↗
- Council of Anti-Phishing Japan: phishing email impersonating the National Tax Agency to push a malicious app (30 September 2026)↗
- National Tax Agency e-Tax: beware of suspicious emails impersonating e-Tax↗
- National Tax Agency e-Tax: about the e-Tax app (the Android version ended on 4 January 2021)↗
- CISA: Known Exploited Vulnerabilities catalogue (KEV; all four CVEs confirmed absent in the 2 October 2026 version)↗
- JVNVU#94863997: multiple vulnerabilities in Buffalo Wi-Fi products↗
- JVNVU#99151548: signature verification bypass in the Authlib library↗
- JVNVU#90160989: path traversal in Fujifilm Business Innovation and Sharp multifunction printers↗
- NVD: CVE-2026-86530 (JPCERT/CC scored CVSS v4.0 8.6 and v3.1 7.2; status Awaiting Analysis)↗
- NVD: CVE-2026-95104 (JPCERT/CC scored CVSS v4.0 8.7 and v3.1 7.5; status Awaiting Analysis)↗
- NVD: CVE-2026-96760 (CISA-ADP scored CVSS v3.1 9.8 CRITICAL; NVD’s own analysis is Awaiting Analysis)↗
- NVD: CVE-2026-78249 (Fujifilm scored CVSS v4.0 6.8 MEDIUM; status Deferred)↗
- PyPI: Authlib (latest is 1.8.0, released 30 August 2026; checked on 4 October 2026)↗
