Japan Whitepaper Warns of Smishing Risks

The Anti-Spam Mail Promotion Council of Japan released the Whitepaper on Junk Mail 2022–2024, summarizing the status, typical tactics and countermeasures of email and SMS fraud in Japan. The report notes that while traditional spam emails have been partially contained, smishing attacks via SMS are on the rise. Phishing, commercial email scams, malware distribution and social media account hijacking are major cybersecurity threats to individuals and businesses.

According to statistics in the whitepaper, spam emails accounted for approximately 39% of inbound emails handled by Japanese ISPs in March 2023. Advertisement spam remains prevalent, with product sales spam making up around 74% of this category. However, threats that cause direct financial and data losses mostly come from phishing messages impersonating banks, e-commerce platforms, courier services and telecom operators. Phishing reports surged from roughly 480,000 cases in 2021 to about 1.2 million in 2023, demonstrating rapid expansion of malicious attacks.

In SMS fraud, perpetrators often send messages from regular mobile numbers starting with 090, 080 or 070. They may also spoof corporate identities or use international numbers. Malicious apps installed on mobile devices can send text messages from genuine subscriber lines, meaning users cannot verify message authenticity merely by checking the sender number. Starting April 2024, Japanese mobile operators banned legitimate enterprises from sending two-way commercial SMS via ordinary mobile numbers to reduce confusion between corporate messages and fraudulent texts.

The whitepaper also warns enterprises against using unregulated bulk SMS tools such as SIM farms or SIM boxes. These solutions leverage unlimited SMS plans and bulk SIM cards to relay messages. Operators lack visibility into end users, use cases and message content. Such tools can be exploited by fraud rings, and services may be terminated if operators revise their terms. Companies and government bodies should adopt traceable, managed official SMS services and publish sender numbers or identities on official websites.

For defence, the whitepaper advises users to avoid clicking links embedded in emails or SMS; instead, access services via official apps, bookmarked websites or manually typed URLs. Organisations should implement authentication protocols including SPF, DKIM, DMARC and BIMI, combined with multi-factor authentication, malicious website takedowns and security awareness campaigns to reduce phishing success rates.