Japan Expands Bank Cyber Oversight to Data Partners
Japan’s financial regulators are significantly expanding their cybersecurity oversight. The Financial Services Agency (FSA) now expects banks to manage risks extending beyond their direct vendors, encompassing a broader ecosystem of data partners. The move aligns Japan with tightening regulations already seen in the United States, the European Union, and the United Kingdom.

The FSA’s new directive requires institutions to scrutinize a wider network of entities, including fintech and telecommunications companies that exchange data even without formal outsourcing agreements. It’s a recognition of just how interconnected modern banking has actually become.

Why the Old Vendor List Isn’t Enough Anymore

Japanese banks moved away from purely in-house operations years ago. Their services now depend on extensive partner ecosystems, and that shift has multiplied the number of external connections quietly running through their systems. Takanori Nishiyama, Senior Vice President at Keeper Security, points to this reality directly: every data connection is a potential entry point for cybercriminals, whether or not it shows up on a traditional vendor contract.

Advanced AI models are compounding the problem by helping attackers find and exploit software weaknesses far faster than before. What used to be a months-long window to patch a vulnerability has shrunk to minutes in some cases. Japan’s National Police Agency recorded 4,677 cases of fraudulent internet banking transfers in 2025, a record high, resulting in roughly 10.2 billion yen in losses. Phishing remains the primary method behind the credential theft driving these attacks.

What Banks Are Now Expected to Do

Financial institutions must treat every connected identity, human or non-human, as part of their attack surface. That starts with a full inventory of every data-linked partner, weighted by what a disruption at each point would actually cost.

  • Security expectations written into contracts as enforceable obligations, including encryption baselines and audit rights
  • Least-privilege access applied to every connection, rather than broad standing permissions
  • Just-in-time access that expires automatically once a task concludes
  • Multi-factor authentication and privileged access management at every point where credentials or tokens grant entry, including AI agents operating inside banking systems

What a Breach Actually Costs a Bank’s Reputation

Trust in Japanese banking was built on decades of reliability, and that trust now extends to every fintech integration, API connection, and AI agent touching a customer’s data. Regulators, like customers, won’t distinguish between a breach at the bank itself and one at a partner three steps removed. Extending rigorous security to every connected identity is how institutions hold onto that reputation going forward.

Hashlytics Take

The real shift in this directive isn’t the technology requirements, it’s the redefinition of “attack surface” itself. Most banks have historically drawn that line at formal outsourcing agreements, the vendors they’ve signed contracts with. Japan is telling them the line no longer exists there. If a fintech app pulls transaction data through an API with no formal agreement in place, that connection is now the bank’s problem too. That’s a much harder inventory to build than a vendor list, and it’s the part most institutions will underestimate.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates