Japan’s Financial Services Agency warns that phishing sites impersonating securities firms can steal login credentials and enable unauthorized access and trading in online brokerage accounts. Users should avoid links in emails and SMS—even from familiar senders—access broker websites through bookmarked official URLs, enable available security features such as multifactor authentication and passkeys, use unique strong passwords, regularly check account activity, and promptly contact the broker and change credentials if suspicious activity or possible credential disclosure occurs. Keeping operating systems and security software updated also helps prevent malware-based theft. Unrecognized logins or trades should be reported to the brokerage, and the FSA’s consultation service is available on weekdays from 10:00 to 17:00. Reported incident figures are provisional, and transaction totals do not necessarily equal customers’ actual losses.
金融庁は、証券会社を装うフィッシングサイトなどによりログインIDやパスワードが盗まれ、インターネット取引口座への不正アクセス・不正取引が発生する危険を注意喚起している。利用者は、見覚えのある送信者からのメールやSMSでもリンクを開かず、証券会社の正しいURLをブックマークから利用し、多要素認証やパスキーなどのセキュリティ機能を有効にすることが重要である。パスワードを使う場合は使い回しを避け、推測されにくい長いものを使用し、口座を नियमित的に確認する。不審な入力や取引があれば、速やかに証券会社へ連絡してパスワード等を変更するほか、OSやセキュリティソフトを最新状態に保つことも推奨される。身に覚えのないログイン・取引は証券会社に相談し、金融庁の相談窓口も平日10時から17時まで利用できる。公表された被害件数は暫定値で、売買金額は実際の顧客損失額と一致しない場合がある。