Japan's Financial Services Agency has quietly expanded the paperwork options for banks, insurers and securities firms reporting cyberattack-related data breaches. An amendment to the agency's Q&A on personal information protection at financial institutions, effective October 1, 2026, tells regulated firms they can now use a new standardized form to report personal-data leaks tied to cyberattacks that are neither ransomware nor a distributed-denial-of-service assault.
The change follows a September 15, 2026 revision to a separate inter-agency agreement on cyberattack damage reporting procedures, dated May 28, 2025. Before that revision, financial institutions already had two common forms: one for DDoS incidents (Appended Form 1) and one for ransomware incidents (Appended Form 2). The September revision added a third, the Other Cyberattack Incidents Common Form (Appended Form 3), for everything else.
| Form | Incident Type | Established |
|---|---|---|
| Appended Form 1 (DDoS Common Form) | DDoS attack incidents | Pre-existing, before September 2026 revision |
| Appended Form 2 (Ransomware Common Form) | Ransomware incidents | Pre-existing, before September 2026 revision |
| Appended Form 3 (Other Cyberattack Incidents Common Form) | Other cyberattacks; also usable for breaches caused by system failures | Added September 15, 2026 |
A newly inserted question in the FSA's Q&A, numbered V-8, lays out five practical points for firms filling out the new paperwork. Institutions use Form 2 for ransomware and Form 3 for other cyberattack incidents; a footnote specifies that financial-sector personal-information handlers can also use Form 3 to report breaches caused by computer-system failures, not just attacks. Firms whose incident does not trigger a reporting duty under the Personal Information Protection Act can skip the "type of report" section of the attached appendix. If the cause of a breach reported on Form 3 is not unauthorized access, filers can leave the "unauthorized access" checkbox blank and describe the actual cause in a detail field instead. Institutions with access to Japan's public-private information-sharing platform can file through that channel rather than sending reports separately to each supervisory destination.
The revision also renumbers several existing questions to make room for the new one, shifting the old Q&A V-8 through V-14 up by one slot, and updates a citation in the Q&A on "improper conduct" under the Banking Act, pointing to Article 35, paragraph 9 of the Banking Act Enforcement Regulation where the prior text cited paragraph 8. Reporting destinations themselves are unchanged: depending on which business law governs a given institution, filings go to the FSA Commissioner, a regional Finance Bureau director, a Finance Branch Bureau director, or the head of a local government, with parallel filings required if the FSA co-supervises the firm with another ministry.
The amendment does not disclose a specific breach or name an affected institution; it is a procedural update to an existing reporting regime. For compliance teams at banks, insurers and brokerages operating in Japan, the change clarifies which standardized form they may use when reporting a personal-data breach tied to a cyberattack, not whether a report is required in the first place. The revised Q&A applies from October 1, 2026, while the new form itself was established under the inter-agency agreement's September 15, 2026 revision.
