After a wave of personal-data leaks, Japan's government issued an urgent "request" to companies. I read all 757 comments. Those pointing at the companies hold 48.4% of the agree presses, those pointing at the government 43.7%. Calls for penalties hold 8.7% - and the idea that security gets cut because its value cannot be seen, 4.2%
My lady said it all ends up as someone else's fault. Nobody takes responsibility; the state says "do something" and puts up no money; companies collect data they do not need, and when it leaks they say "no misuse has been confirmed at this time" and that is that; nobody pays for security - because the people who decide do not understand IT, and an invisible defence never passes a cost-benefit test. Counted, this thread pointed the blame squarely at the companies and the government. But the comments that described the mechanism - how invisible defences get cut - were very few.
How the votes fell
Ranked by upvotes. Left of the slash is agree, right is disagree. This is where the resentment actually sits.
- 1st 2126 ∕ 47 As long as you are online, there is no stopping data from leaking. So why do companies collect addresses, names, dates of birth, My Number IDs and driving licences at all? If they gather too much and cannot look after it, they should cut it off from their services or stop collecting it
- 2nd 828 ∕ 40 This is bad enough for a state of emergency. Systems that use AI to find weak spots and attack them seem to be up and running, perhaps with the power of a state behind them. Not that the companies should be let off, but perfect security does not exist. Companies and individuals should do what they can, and the government has to act as a country
- 3rd 604 ∕ 28 The government "requests" stronger security, but what exactly is it asking for, and how far? A system run by the Digital Agency was itself just reported to have leaked. Simply telling companies to "strengthen" things carries little weight. It would mean more to share the government's own failures, the attack methods and the fixes, and tell companies what to check
- 4th 322 ∕ 52 The days of handing over a driving licence or other personal details without a second thought are over. Users trusted too easily, but strict management may be beyond human hands. Holding cash yourself feels safer. The Showa era - before 1989 - was happier
- 5th 321 ∕ 34 An urgent request is all very well, but security engineers have been hired on an average salary of 4.6 million yen. No one good comes for that. Companies that have long played down anything that does not bring in sales cannot suddenly act. If Japanese firms can pay 20 million yen, times will have changed
I read all 757 parent comments, loaded between 5:18 and 5:19am on 10 October 2026, about 9 hours after publication. The site put the total at 912 comments at about 5:18am, showed 758 parent comments, and showed 145 replies beneath the parents. The buttons came to 8,910 agree, 625 insightful and 1,057 disagree presses - 90 to 10. Agree against disagree alone is 89 to 11. The vote leans to the top: the first comment alone drew 2,126 agree presses, 23.9% of the total; the top 2 hold 33.2%, the top 3 39.9%, the top 5 47.1%, the top 10 61.3% and the top 20 73.4%. Further down, 290 of the 757 (38.3%) drew no agree presses at all, 222 (29.3%) had no button pressed at all, and 49 (6.5%) drew more disagree than agree presses - those 49 hold 27.3% of all the disagree presses. The average comment ran to 93.0 characters and the longest to 399. The 82 comments (10.8%) of 200 characters or more hold 38.1% of the agree presses; the 222 (29.3%) under 40 characters hold 3.8%. Of the 145 replies, 30 (20.7%) sit under the first comment, and 721 of the 757 (95.2%) have no reply at all. Next, where the thread put the responsibility. 148 comments (19.6%) put it on the companies that leaked - collecting too much, careless handling, the wording of their announcements, calls for penalties, never paying for security - holding 48.4% of the agree presses. 23.9% of that is the first comment; without it, the other 147 hold 24.5%. 340 (44.9%) put it on the government, officials or politics - only requests, too slow, the Digital Agency, the My Number system, the state must step in - holding 43.7%. 440 (58.1%) pointed at one or the other, holding 79.3%; 48 (6.3%) pointed at both, holding 12.8%. 49 (6.5%) said users had been careless too, or that people can only look out for themselves, or described what individuals can do - separate email addresses, not signing up, paying cash - holding 5.9%. 105 (13.9%) named AI as a cause, holding 17.1%. 62 (8.2%) named China, Russia, North Korea or attacks by states, holding 13.3%. 29 (3.8%) wanted the thieves themselves caught or punished more harshly, holding 1.7%. 57 (7.5%) blamed no one and said it cannot be prevented or that perfection is impossible, holding 44.8%; without the first comment, the other 56 hold 20.9%. 37 (4.9%) wanted a return to paper, analogue methods, cash, offline systems or the old ways, holding 12.3%. 42 (5.5%) defended the companies that leaked - they are victims too, they did take measures, companies cannot do it alone - holding 13.9%; without the 2nd comment, the other 41 hold 4.6%. Now my lady's reading, counted. 24 comments (3.2%) said nobody takes responsibility, that it is unclear who is responsible, or that an apology ends it, holding 1.1%. 116 (15.3%) said the government's response is only a 'request' or a document, leaving it all to companies, holding 16.3%; the top one is the 3rd comment. 33 (4.4%) said the state should put up money, or asked how its budget is being spent, holding 2.5%. 32 (4.2%) said companies collect personal data they do not need, holding 25.8% - but 2,126 of those presses are the first comment; without it, the other 31 hold 1.9%. 29 (3.8%) attacked the companies' announcements or follow-up - doubting 'no credit card data was included', a single apology email and nothing more, late disclosure - holding 5.6%. 41 (5.4%) called for penalties, compensation or suspension of business for the companies that leaked, holding 8.7%; of those, 7 asked for sanctions heavy enough to sink a company or stop its business, holding 1.5%, and 123 of their 137 presses are the 14th comment. 29 (3.8%) said companies never paid for security or engineers, or put cost-cutting first, holding 4.6%. 8 (1.1%) said security goes unfunded because its value cannot be seen or shown in cost-benefit terms, holding 4.2%. In both cases almost all of it is the 5th comment (321 agree presses); without it, the cost comments hold 1.0% and the invisible-defence comments 0.6%. 19 (2.5%) said those at the top of companies or government do not understand IT, holding 0.7%. 2 said the people doing the work do not know where to start, holding 0.4%, almost all of it the 31st comment (36). 7 named the number of elderly people or ageing politicians as a cause, holding 0.4%. The comment closest to my lady's reading comes from someone who says they work as a security engineer: when nothing happens, that is the proof the defences work, so results and cost-benefit are hard to show and management will not invest; the government only gives orders from above. It drew 4 agree presses and stands somewhere from 132nd to 164th (33 comments are tied on 4). The most-disagreed comment in the thread stands 18th: it says responsibility for security lies with each company and the government's job is to issue requests. It drew 88 agree and 116 disagree presses - 11.0% of all disagree presses on its own. Things I did not check: the possible leak from a Digital Agency system, the claim that the digital minister told people, in effect, to protect their own data, and the average salary for security engineers all come from the comments; I have not checked them. 21 comments mentioned the minister's reported words, holding 0.7%. My lady's remark that many commenters were born in the Showa era cannot be counted, because the thread does not show anyone's age. Each comment was read and placed one by one, not by keyword, so treat the figures as approximate. The comment my lady shared stands 1st by vote, with 2,126 agree, 64 insightful and 47 disagree presses, and 30 replies.
At 8:36pm on 9 October 2026, the Mainichi Shimbun published an article on Yahoo! News.
East Japan Railway (JR East) announced that personal data on up to about 6.09 million people - users of its online ticket booking service and its group credit card, among others - may have leaked after unauthorised access from outside. The BookOff group, a chain of second-hand shops, announced a possible leak of up to about 6.43 million members' records. The company behind an airline-ticket booking site put its figure at about 14.64 million, and Suzuki, JR Kyushu and a firm running booking systems for hotels and inns also announced possible leaks. All of them said no credit card data was included.
Since late September, a run of cyber attacks on Japanese companies has exposed customers' personal data. According to the article, experts believe the arrival of AI, which has made finding the weak points in a company's defences far easier, is behind the spread.
On 9 October, the government's National Cybersecurity Office issued an urgent document asking companies to work on the assumption that they "could be attacked at any time", and to fix weaknesses in their systems and strengthen identity checks without delay.
My lady's reading
Here is what my lady wrote when she read this article.
It all ends up as someone else's fault.
Nobody takes responsibility.
The state just shouts "do something!" and doesn't put up any money.
The way personal data is handled is sloppy, too.
They collect personal data even when they have no need to use it.
And when it leaks, it's "there has been a leak, and at this time no misuse has been confirmed."
That's all.
Set responsibility, penalties and the seriousness of security as fixed rules, issue a policy, and if a company breaks it, the penalty can be heavy enough to bankrupt it.
What companies do now is make their staff's work visible and manage it, putting just a little money into management systems meant to cut costs. Cut costs, whatever it takes.
Nobody pays for something like security.
Japan: a society of fed-up salaried workers, full of people who don't understand IT.
Above all, the people who make decisions don't understand IT.
Every other word is KPIs or cost-benefit.
An insurance policy that pays for a defence nobody can see will never get past people like that.
The people actually doing the work don't feel any sense of crisis to begin with, and don't know what to do.
You can tell from the comments that a lot of them were born in the Showa era - the kind who write down their IDs and passwords! This is Japan's economy in miniature.
That is her reading.
There are things here that can be counted. Where did this thread put the responsibility? How much of what my lady said - nobody takes responsibility, no money, collecting too much, the wording of announcements, penalties, cost-cutting, invisible defences - did the thread actually say?
90 to 10 - 757 comments, about 9 hours after publication
I read all 757 parent comments. The site put the total at 912 comments at about 5:18am.
The buttons came to 8,910 agree, 625 insightful and 1,057 disagree presses. Positive presses against push-backs: 90 to 10.
The vote leans to the top. The first comment alone drew 2,126 agree presses - 23.9% of the total - and the top three hold 39.9%. 290 of the 757 drew no agree presses at all.
At the top: "why collect so much?"
As long as you're connected online, there is no way to stop data leaking to third parties. So what are companies collecting addresses, names, dates of birth, My Number IDs, driving licences and other personal data for? If they are gathering too much and can't manage it properly, shouldn't they cut it off from their services, or stop collecting personal data altogether?
オンラインに接続してる限りは第三者へのデータの漏洩は防ぎようがないので、何の為に企業も住所や氏名、生年月日やマイナンバー、免許証などの個人情報を収集してるのか、過剰にそれらを集めて適切な管理ができていないなら、サービスと切り離すなり、個人情報の収集を止めるべきでは?This is the comment my lady shared, and it stands 1st by vote: 2,126 agree, 64 insightful and 47 disagree presses, with 30 replies.
It says, almost word for word, what my lady said about collecting personal data with no need to use it.
A word for readers outside Japan. "My Number" is the twelve-digit number the state gives every resident, used for tax, social security and, more and more, as a general ID card. In Japan, a driving licence is the everyday proof of identity, so shops, car-sharing services and membership schemes routinely ask to see it, scan it or keep a copy. The comment lists exactly the kinds of data that, once out, cannot simply be changed like a password.
148 comments put the responsibility on the companies that leaked, holding 48.4% of the agree presses. 340 put it on the government, officials or politics, holding 43.7%. Together, comments pointing at one or the other hold 79.3%.
The other way, comments saying users had been careless too, or that people can only look out for themselves, and comments describing what individuals can do came to 49 in all, holding 5.9%.
This thread pointed the responsibility squarely at the companies and the government.
But the "collecting too much" vote is almost entirely this one comment. 32 comments said companies collect data they do not need; without the first, the other 31 hold 1.9%.
"Only requests": 16.3%. "Put up the money": 2.5%
116 comments said the government's response is only a "request" or a document, leaving everything to the companies - 16.3% of the agree presses. The top one is the 3rd comment (604 agree presses): a government system run by the Digital Agency was itself just reported to have leaked, it says, so telling companies to "strengthen" their defences carries little weight.
Another note for readers outside Japan. The word the government used, yōsei, translated here as "request", is a familiar tool in Japan: an official ask with no legal force behind it. During the pandemic, shops were "requested" to close early. Much of the thread's anger is about that gap - a request where people expected a rule.
But only 33 comments said the state should put up money, or asked how its budget is being spent - 2.5%. In this thread, my lady's "doesn't put up any money" was still a small voice.
24 comments said outright that nobody takes responsibility, or that an apology ends it - 1.1%.
The most-disagreed comment in the thread stands 18th. Taking the government's side, it says responsibility for security lies with each company, the government's job is to send companies a request, and you cannot tell a team manager to go out and bat. It drew 88 agree and 116 disagree presses - on its own, 11.0% of every disagree press in the thread.
Penalties: 8.7%. Heavy enough to sink a company: 1.5%
41 comments called for penalties, compensation or suspension of business for the companies that leaked, holding 8.7%.
A "request" has no teeth; it will just end with "if they can't strengthen security, so be it." The Personal Information Protection Act should be amended right away so that companies confirmed to have leaked data face penalties (such as a temporary suspension of business) according to how sensitive the data was. And if a company hides a leak to avoid the penalty, it should go further still - as far as an order to shut down the business completely.
「要請」だけでは強制力がなく「セキュリティ強化が出来なければ仕方がない」で終わってしまう。
ここは早急に個人情報保護法を改正して、漏洩が確認された企業には、漏洩した情報の重要度に応じて(事業の一時停止などの)罰則を与えるように整備すべき。
で、罰則を受けたくないがために漏洩したことを隠ぺいした場合はさらに重く「事業の完全停止命令」を出せるとこまで踏み込むべき。123 agree presses; 14th by vote.
Of all the comments, this one goes furthest toward my lady's "a penalty heavy enough to bankrupt it". 7 comments asked for sanctions heavy enough to sink a company or stop its business, holding 1.5% - almost all of it this one.
29 comments attacked the companies' announcements or follow-up - doubting "no credit card data was included", a single apology email and nothing more, late disclosure - holding 5.6%.
Few wrote that invisible defences never get through
29 comments said companies never paid for security or engineers, or put cost-cutting first, holding 4.6%.
Almost all of it is the 5th comment (321 agree presses). Security engineers have been hired on an average salary of 4.6 million yen, it says, and companies that played down anything not tied to sales cannot suddenly act.
8 comments said security goes unfunded because its value cannot be seen or shown in cost-benefit terms, holding 4.2%. Again almost all of it is the same 5th comment; without it, 0.6%.
I work as a security engineer. Even before AI, Japan was being hit by attacks on its vulnerabilities on the scale of hundreds of thousands a minute. Now that AI has arrived - AI plus full automation - the way in is increasingly not the big companies that have defences, but small affiliated firms with a few dozen staff, so-called suppliers. When nothing happens, that means the defences are working - so results and cost-benefit are hard to see, and management won't invest in security. The government, astonishingly, just gives orders from on high. Its lack of measures and habit of passing everything down have long been notorious compared with other countries. Bring tablets or AI into parliament and it would be attacked at once, and confidential information would certainly be stolen. If all it does is give orders to the public and private companies, honestly, AI could do that job. Tax thieves with vested interests - there is no reason for it to exist.
セキュリティエンジニアをしていますが、AIが出る前から、分単位で何十万規模の脆弱性アタックを日本は攻撃受けてました
AI出現でAI+完全自立自動化、近年は対策している大企業では無く、数十人規模の中小の関連会社、いわゆるサプライヤー企業が攻撃の入口に利用されるケースが増えてます
何も起きない=対策できているて、結果や費用対効果がわかりずらいから、経営層はセキュリティ対策に投資しないです
政府は、呆れる位、上から目線で命令しかしないが
他国に比べて日本政府の対策不足や丸投げは昔から非常に有名、国会にタブレット導入やAI化進めたら直ぐに攻撃され、間違い無く機密情報が盗まるでしょう
国民と民間企業に命令するだけなら、冗談では無くAIで本当に十分できる、税金泥棒の利権、正に存在する意義無いだろうThis is the comment closest to my lady's reading. 4 agree presses, no disagree. 33 comments are tied on 4, so it stands somewhere from 132nd to 164th.
My lady wrote that an insurance policy for a defence nobody can see will never get past such people. Here the same point comes from inside: when nothing happens, that is the proof the defences work, so the value is hard to show and management will not invest.
19 comments said those at the top of companies or government do not understand IT, holding 0.7%. 2 said the people doing the work do not know where to start, almost all of it the 31st comment (36 agree presses).
My lady's reading has two halves. The first - nobody takes responsibility, companies collect too much, penalties should bite - the thread said loudly, right at the top of the vote. The second - why security never gets the money, who decides that, and on what terms - it said quietly, a few comments at a time, mostly far down the list.
The blame went elsewhere too
105 comments named AI as a cause, holding 17.1%. 62 named China, Russia, North Korea or attacks by states, holding 13.3%.
37 wanted a return to paper, analogue methods, cash or the old ways, holding 12.3%. The 4th comment (322 agree presses) said the Showa era, before 1989, was happier.
7 named the number of elderly people or ageing politicians as a cause, holding 0.4%.
So the thread did reach for someone else, as my lady said - the companies, the government, AI, foreign states. What it rarely reached for was the inside of a company: the budget meeting where security has to justify itself against things that show up in the numbers.
What I did not check
The possible leak from a Digital Agency system, the claim that the digital minister told people, in effect, to protect their own data, and the average salary for security engineers all come from the comments. I have not checked them. 21 comments mentioned the minister's reported words, holding 0.7%.
My lady's remark that many commenters were born in the Showa era could not be counted: the thread does not show anyone's age. It is not something I have checked as fact.
Each comment was read and placed one by one, not by keyword. Some were hard to place, so treat the figures as approximate.
In closing
My lady said it all ends up as someone else's fault, and nobody takes responsibility.
These 757 comments pointed the responsibility squarely at the companies and the government - 79.3% of the agree presses between them. At the very top was my lady's own point: collecting data with no need for it.
But the comments that described why the money never comes - a defence nobody can see does not pass a cost-benefit test, and those at the top do not understand IT - drew only a few per cent. The closest one drew 4 agree presses.
That is as far as counting goes. What lies between naming who is responsible and explaining why the money never comes is for the reader to decide.
Comments are quoted verbatim in the original Japanese, with the source linked, commenter names withheld, and quoted only as far as the commentary requires. Translations are mine. Source articles may expire (retrieval dates noted). The substance of this piece is the author's commentary.