
东京/首尔——根据《日经亚洲》的统计,仅自9月以来,全球范围内的数据泄露事件就已经泄露了至少3.2亿人的个人信息,其中至少部分案件被认为涉及人工智能。
TOKYO/SEOUL -- Data breaches globally have leaked personal information for at least 320 million people just since September, according to a Nikkei tally, with at least some cases thought to involve artificial intelligence.
《日经亚洲》审查了全球范围内受害者人数至少达到10万人的公开事件。数据来源包括公司和政府公告,以及研究机构等第三方的消息。
Nikkei examined disclosed incidents worldwide that involved at least 100,000 victims. Sources include company and government announcements as well as information from third parties such as research firms.
攻击者的认领声明也被纳入其中,但前提是相关企业已经承认了这些数据泄露事件。
Claims of responsibility by attackers also were included, though only when the breaches were acknowledged by the companies affected.
总部位于美国的身份盗窃资源中心(Identity Theft Resource Center)报告称,2026年前六个月估计有4.712亿条数据泄露受害者通知。尽管无法进行直接对比,但《日经亚洲》对9月及以后的估算可能表明此类案件正呈急剧上升趋势。
The U.S.-based Identity Theft Resource Center reported an estimated 471.2 million data breach victim notices for the first six months of 2026. Although it is impossible to make a direct comparison, Nikkei's estimates for September onward may point to a sharp increase in such cases.
身份验证公司IDScan.net泄露了1.53亿份美国驾照的数字扫描件,一家美国安全博客报道称,这些扫描件正在暗网的一个俄罗斯网络犯罪论坛上被兜售。IDScan随后表示,第三方在4月4日至9月2日期间未经授权访问了其部分系统。
Digital scans of 153 million U.S. driver's licenses were leaked from identity verification company IDScan.net, with an American security blog reporting they were being marketed on a Russian cybercrime forum on the dark web. IDScan later said a third party gained unauthorized access to part of its systems between April 4 and Sept. 2.
总部位于哈萨克斯坦的跨国比萨连锁经营商Dodo Brands有68万名客户的数据在一次黑客攻击中被盗。该公司于9月下旬向俄罗斯和土耳其当局报告了这起事件。
Kazakhstan-based multinational pizza chain operator Dodo Brands had data for 68 million customers stolen in a hack. The company reported the incident to Russian and Turkish authorities in late September.
在调查的35起数据泄露事件中,日本占了20起,受害者总数达到5700万人。受影响的企业包括烤肉连锁经营商Monogatari和共享汽车服务商Park24,分别有1078万和660万客户受到影响。
Japan accounted for 20 of the 35 breaches examined, with a total of 57 million victims. Companies affected include barbecue chain operator Monogatari and car-sharing service provider Park24, with 10.78 million and 6.6 million customers hit, respectively.
与过去专注于关闭公司系统或利用勒索软件将其扣为人质的网络攻击不同,目前窃取个人数据的企图似乎正在激增。
In contrast to past cyberattacks that focused on shutting down company systems or holding them hostage with ransomware, there appears to be a surge in efforts to steal personal data.
人工智能被认为是其中的一个因素。韩国总统李在明周二表示,人工智能可能参与了最近针对该国金融机构的一系列网络攻击,导致至少65,000名客户的记录泄露。韩国电力公社和多所大学也发生了类似事件。
AI has been cited as a factor. South Korean President Lee Jae Myung said Tuesday that AI may have been involved in a recent string of cyberattacks targeting financial institutions in the country, exposing records for at least 65,000 customers. Korea Electric Power Co. and universities have seen similar incidents.
日本科技公司麦克尼卡(Macnica)安全研究中心的濑山丰(Yutaka Sejiyama)表示:“随着人工智能被用于支持攻击,原本从事诈骗等活动的团伙有可能发动了网络攻击。”
"It's possible that with AI being used to support attacks, groups that had engaged in activities like fraud have launched cyberattacks," said Yutaka Sejiyama at the security research center of Japanese tech company Macnica.
罪犯现在更容易接触到强大的人工智能程序。美国推进超级智能创新与标准中心(U.S. Center for Advancing Innovation and Standards for Super Intelligence)的数据显示,中国智谱AI(Z.ai)于8月发布的GLM-5.3模型触手可及,其性能与Anthropic公司4月推出的Mythos Preview模型相似。
Criminals now have an easier time accessing powerful AI programs. The GLM-5.3 model released in August by China's Z.ai, which is widely available, showed performance similar to that of Anthropic's Mythos Preview model that came out in April, according to the U.S. Center for Advancing Innovation and Standards for Super Intelligence.
一家遭受数据泄露的科技公司的网络安全工程师观察到了一波接一波的攻击,其速度超出了人类所能及的极限,同时又没有自动化工具所具备的那种规律性。
A cybersecurity engineer at a tech company hit by a data breach observed a relentless stream of attacks faster than anything humans could do yet without the regularity that would be the hallmark of an automation tool.
这位工程师说:“这是一种我从未见过的攻击方法。令人感到不安。”尽管该技术可用于发现和修复漏洞,但利用人工智能进行防御会受到更多限制,从而让攻击者占据优势。
"It was a method of attack I've never seen before," the engineer said. "It was unsettling." Using AI for defense comes with more constraints, giving the attacker an edge, though the technology can be used to find and fix vulnerabilities.
提供人工智能驱动的未授权系统访问检测服务的ChillStack公司首席执行官伊藤通昭(Michiaki Ito)表示:“很难利用人工智能实时中断攻击。”
"It's hard to use AI to interrupt an attack in real time," said Michiaki Ito, CEO of ChillStack, which provides AI-powered services to detect unauthorized system access.