On May 18, 2026, the Utilization Working Group of the Japan Smartphone Security Association (JSSEC) released its latest report, 'TOP 10 Smartphone Utilization Scene Threats 2026'.
Since JSSEC's founding in 2011, smartphones have become essential to daily life. However, fraud and exploitation methods continue to evolve. This 2026 edition was selected through workshops with member companies and public voting at the Cybersecurity Symposium Dogo 2026.
### TOP 3 Threats and Key Trends
1. **Generative AI-based Fake Video and Audio** Generative AI can now recreate a person's voice and face in a short time, significantly increasing the persuasiveness of scams. This technology is being used in romance scams, investment fraud, and 'recruiting' scams on SNS. It also targets corporate and family impersonation to force urgent transfers or bypass KYC (Know Your Customer) processes.
2. **Phishing and Fake Emails (Real-time Phishing)** Traditional phishing has evolved into 'Real-time Phishing,' where attackers steal not just login credentials but also authentication codes in real-time. This makes even two-factor authentication (2FA) vulnerable. AI is also used to create more natural and convincing messages in emails and SNS DMs.
3. **QR Code Fraud (Quishing)** The rise of QR payments and contactless ordering has led to 'Quishing.' Since QR links are hard to verify visually, users may be led to malicious sites. Scammers often place fake QR codes on flyers, posters, or delivery notices to lure victims.
### Recommendations for Service Providers
JSSEC emphasizes that user vigilance alone is reaching its limit. Therefore, providers of SNS, financial, and payment services are urged to implement the following: - **Strengthen Countermeasures Against Impersonation Ads:** Stricter screening of ads and faster response to reporting fraudulent accounts. - **Transition to Phishing-Resistant Authentication:** Moving away from SMS codes to phishing-resistant methods like 'Passkeys'. - **Multi-layered Security Design:** Implementing anomaly detection for logins and context-aware additional authentication.
FACT BOX
- Source: PR TIMES
- Category: Survey