Chino Yoshio Blog

Thoughts on the Recent Rise of Ransomware Attacks

Hello, this is Chino Yoshio, a composer based in Kyotanabe, Kyoto. Today I’d like to briefly write down some thoughts about the recent surge in ransomware…

Thoughts on the Recent Rise of Ransomware Attacks

Thoughts on the Recent Rise of Ransomware Attacks
Hello, this is Chino Yoshio, a composer based in Kyotanabe, Kyoto. Today I’d like to briefly write down some thoughts about the recent surge in ransomware-type cyberattacks.

Many news reports say, “Be careful not to open suspicious emails.” But recently, I feel that ransomware can enter through other routes as well, not just spam or phishing emails.

I’m not a security expert, but I sometimes feel that the well-known countermeasures we often hear about may no longer be enough.

Vulnerabilities in Old Apps — the Hidden Back Door

In many recent cases, attackers seem to focus less on email and more on:

Outdated versions of VPN software, NAS devices, and internal applications.

If these systems are left unpatched, vulnerabilities remain open. Attackers can scan the internet with automated tools, find those weak points, and enter without any email involvement at all.

Even if no one opens a suspicious message, a system that stays “old” can still be compromised.

Accounts Without Two-Factor Authentication More companies are using Microsoft accounts for Windows login, but surprisingly often, two-factor authentication (2FA) is not enabled.


If employees also use simple, predictable passwords, attackers may break in even without phishing emails.

So “We’re careful with suspicious emails” may no longer be enough.

Spam Emails Are Not the Only Attack Vector Email protection is still important, but attacks today often come from completely different routes.


Just as we sometimes remind ourselves to “see things from the other person’s perspective,” it might also help to consider how things look from a cybercriminal’s point of view.

In other words, we should check:

Are our apps and devices updated to the latest version? Do we still have legacy equipment connected to the network? Are our accounts protected with 2FA?

Focusing only on email filters creates blind spots. Looking at these “non-email vulnerabilities” is becoming essential for modern cybersecurity.

近ごろ増えているランサムウェア型サイバー犯罪について感じていること

こんにちは、京都・京田辺で作曲活動をしている Chino Yoshio です。 今日は、最近よく耳にする“ランサムウェア型のサイバー犯罪”について、感じていることを短く記録します。

ニュースではよく「不審なメールを開かないように」と注意されていますが、 最近は 迷惑メール以外のルートから侵入されるケースも増えているのでは? と感じています。

私はセキュリティの専門家ではありませんが、 今よく紹介されている対策だけでは十分ではないような気がして、 少し違和感があります。

古いアプリの脆弱性という“裏口”

最近のサイバー攻撃は、メールよりも VPN、NAS、社内アプリの“古いバージョン” を狙う傾向が強いように思います。

古いまま放置されたアプリには、脆弱性(セキュリティホール)が残っていることがあり、 攻撃者はそこを自動ツールで探して侵入してくる──そんな構造が増えているのでは、と推測しています。

メールを開かなくても、パソコンやサーバーが“古いまま”なら狙われる可能性があるわけです。

二段階認証を使っていないアカウント

会社ではWindowsログインに Microsoft アカウントを使うことも増えていますが、 二段階認証(2FA)が設定されていないケースも多い と感じています。

パスワードも「推測されやすい簡単なもの」が使われていれば、 メールを開かなくても不正ログインのリスクがあります。

「うちは迷惑メールに気をつけているから安心」ではもう足りないのかもしれません。

迷惑メール“だけ”が入口ではない

迷惑メール対策はもちろん必要ですが、 最近の攻撃はそれ以外の入口から来ることも多いように感じます。

物事を理解するときに「相手の立場に立つ」ことがありますが、 同じように、サイバー犯罪者の立場から見える“入口” を考えてみる必要があるのではないでしょうか。

つまり、

自分のパソコンやアプリは最新版か? 古い機器が社内に残っていないか? アカウントは二段階認証になっているか?

こうした “メール以外の弱点” に目を向けることが、 これからのサイバー対策ではますます重要になっていく気がしています。
Navigation

This article is part of the official Chino Yoshio Blog.