Japan's FSA Standardizes Cyber Incident Reporting for Crypto Exchanges
Japan's Financial Services Agency (FSA) has announced plans to standardize cyber incident reporting across 17 sectors, including crypto exchanges. This revision follows amendments to the inter-ministerial agreement in May 2025 and aims to establish a unified reporting format for various types of cyberattacks.
The FSA will revise supervisory guidelines and introduce a new 'Common Template for Other Cyberattack Incidents' that addresses cases beyond DDoS attacks and ransomware. This template is expected to be implemented by the end of March 2027, after which businesses must use the standardized reporting format.
In addition to this measure, the FSA has requested crypto exchange operators to strengthen fraud prevention measures. The agency pointed out that cases involving social media-based investment and romance scams have increased, with crypto assets being used as a means of delivering fraud proceeds.
The FSA recommends several measures to prevent such incidents, including restrictions on withdrawals for a set period after fiat currency deposits are made or crypto assets are purchased. Exchange operators are also required to establish systems capable of responding promptly during nights and holidays, and to implement phishing-resistant multi-factor authentication for critical operations.