Phishing Attacks Against Japan Drop Over 70% During Lunar New Year Holidays
Article Content
- •Phishing attacks against Japan dropped over 70% during Lunar New Year holidays.
- •Proofpoint's analysis showed a decrease from 1.3 million to 350,000 phishing emails daily.
- •Attacks were more frequent on weekdays, indicating a structured operational schedule.
A recent analysis by Proofpoint revealed a significant decline in phishing attacks targeting Japanese companies and individuals during China's Lunar New Year holidays in February 2026. The number of phishing emails fell from an average of 1.3 million per day to approximately 350,000 per day between February 15 and 23. These phishing attempts, often disguised as communications from well-known companies like Amazon and Microsoft, are believed to have been systematically executed from China. The analysis indicated that phishing attacks were more prevalent on weekdays compared to weekends, suggesting a structured operational schedule among the attackers. The emails contained traces of the Chinese language, making it easier for Chinese hackers to target Japanese users. Experts noted that these organized phishing campaigns have historically caused significant damage in Japan. The current status indicates a temporary reduction in phishing activity during the holiday period.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…