Cyberattacks targeting major corporations like Times Car and Keio Corporation are occurring one after another.
On September 28, Park24 announced that Times Car's web system suffered unauthorized access, leading to approximately 6.6 million account details being acquired by a third party. Keio Corporation also announced on September 26 that its group servers were hit by a ransomware attack, causing disruptions to some systems.
Meanwhile, there's a surge in CVEs (Common Vulnerabilities and Exposures), which indicate software vulnerabilities. According to Google Threat Intelligence Group (GTIG), the monthly number of disclosed vulnerabilities, which was 5,045 in January 2026, increased to 10,740 by August.
Is the advancement of AI behind this trend? We asked Professor Hiroki Takakura, Director of the Strategic Cyber Resilience Research and Development Center at the National Institute of Informatics (NII).

Hiroki Takakura, from his lab's website
Successive Corporate Incidents: "Caused by Insufficient Countermeasures Rather Than AI"?
Professor Takakura states, "I believe it's true that CVEs are exploding due to AI-driven vulnerability discovery."
However, not all discovered vulnerabilities lead to significant danger.
"While vulnerabilities certainly exist, there are too many that don't cause actual harm, or were previously discovered but whose remediation was postponed due to various circumstances. I believe we are no longer in an era where risk can be discussed solely based on the number of CVEs."
So, are the recent successive attacks on corporations also being caused by AI? Professor Takakura's view was slightly different.
"I believe AI was used for attack automation, but it didn't play a major role. In other words, I think the countermeasures were insufficient."
AI Accelerates Attacks, Multi-Layered Defense Becomes Crucial
On the other hand, there's no doubt that AI is accelerating the attacks themselves.
"Attack tools for disclosed vulnerabilities can be created in an instant."
In an evaluation by the AI Security Institute (AISI), Anthropic's Claude Mythos Preview completed a 32-step challenge simulating intrusion into a corporate network without human intervention. It successfully completed the entire process in 3 out of 10 attempts. However, AISI also cautioned that the environment was easier than a truly well-defended corporate network.
In real-world networks, the concept of "multi-layered defense," where one defense is breached but the next one stops the attack, becomes crucial.
"By slowing down the rate of intrusion with multi-layered defense, the defenders gain time to implement countermeasures. In such a scenario, it won't be fully automated by AI, requiring human involvement on the attacker's side as well."
Attack Tools Emerge "Before" Vulnerability Disclosure
According to Professor Takakura, it's not uncommon for attack tools to appear even before vulnerabilities are officially disclosed.
"Especially with open-source software, even though the remediation process is somewhat limited, it's public, so one can predict where vulnerabilities might lie. As this task shifts from humans to AI, I believe the time until attack tools emerge will become even shorter."
Furthermore, as AI agents evolve, there's a possibility that a series of attacks, including reconnaissance, vulnerability discovery, intrusion, and internal network exploration, could become autonomous.
In fact, the idea of fully automating cyberattacks already exists; in 2016, the U.S. DARPA held the "Cyber Grand Challenge," a competition where computers autonomously performed vulnerability discovery, attack, and defense.
"It wouldn't be surprising if it were put into practical use within 10 years."
"Humans Alone Can No Longer Cope"
If attacks operate at machine speed, then defenders will also be required to operate at machine speed.
"I believe it's already impossible for humans alone to cope."
According to Professor Takakura, "NII-SOCS," which protects national universities and other institutions, analyzes billions of pieces of suspicious attack information daily to identify a few high-risk attacks. A significant portion of this is already handled automatically.
At the same time, universities do not assume that they can prevent 100% of initial intrusions.
"We implement multi-layered defenses based on the premise that the first attack cannot be entirely prevented. Even if a ransomware intrusion is allowed, we take measures to minimize damage and ensure university operations do not cease."
Professor Takakura is currently also advancing research into "cyber resilience," which focuses on continuing critical services even after an attack, rather than completely preventing attacks.
"I believe it's necessary to introduce AI into these countermeasures to prevent the attacker's AI from reaching its target directly, while also securing time for humans to devise countermeasures."
What AI Changes is the "Time" of Attack and Defense
AI is rapidly accelerating vulnerability discovery and attack code creation. However, it seems premature to simply attribute recent corporate damages to "advanced AI attacks."
On the other hand, what is realistically changing might be the "time" aspect of attack and defense.
AI compresses the time humans spent researching vulnerabilities, devising attack methods, and writing attack code. Defenders also use AI to detect anomalies, slow down the attack's progress with multi-layered defense, and allow humans to make decisions during that time.
Cyberattacks appear to be transforming into a race to detect intrusions quickly and contain damage after a breach.