After running for 3 days, the Shirahama Symposium on Cybercrime #SCCS2024 has concluded. The closing session was a panel discussion by the following 4 people, coordinated and moderated by Professor Uehara.
- Coordinator: Tetsutaro Uehara
- Panelists:
I am a novice in this field, and the following was reconstructed from a few lines of notes and my memory. It likely contains inaccuracies and omissions, so I hope members of the Shirahama group will point them out as appropriate. Please also forgive the many places where my own impressions are mixed in. Material clearly not discussed by the panel is shown in italics. I have also tried to incorporate the Q&A at the end of the session into the main text.
Summary
This panel discussed the development and challenges of generative AI, the impact of the shift to the cloud, and recent large-scale ransomware incidents. It noted that while generative AI improves efficiency, it increases the risk of generating and disseminating inappropriate information; that cloud migration reduces costs but makes vendor management difficult; and that ransomware damage has become severe and entered a new phase, requiring countermeasures.
The Development and Challenges of Generative AI
Generative AI is expected to make work more efficient, while the risk of information leakage was initially highlighted. Subsequent contractual and other controls have made major leakage less likely. Meanwhile, however, the risks of weakening rights in content and creating inappropriate content or malware are increasing.
For example, someone was recently arrested for allegedly using generative AI to create smartphone ransomware. Creating and distributing functional smartphone ransomware with AI is extremely difficult1, and it appears not actually to have been used. The offense of creating malware was applied here, but its casual application inevitably raises concerns including a chilling effect. (The offense can apply when malware is created with intent, but proving intent and bringing a case is difficult. This may have been an exceptional case.)
The panel also noted the problem of generative AI creating inappropriate content, such as nude images and information usable for crimes, as well as fake news.
Regarding the former, some argue that generative AI simply should not be taught such “inappropriate” content, but:
- To control “inappropriate” output, the system must be taught what is “inappropriate,” so simply not teaching it is difficult.
- To make it useful, one sometimes must also teach it things one does not want it to output.
- Example: To draw the human body well, either a person or a machine must study nude models.
For these reasons, not teaching it is difficult. Such “discipline” is therefore generally imposed at the prompt level. With open AI models, however, enforcement is difficult and misuse is possible. Balancing use and regulation of generative AI is a challenge. We must assume that generative AI will mass-produce malware and inappropriate content, and countermeasures will likewise need to use AI. Deeper discussion is needed on regulations and ethical guidelines for AI use.
Impact of the Shift to the Cloud
As cloud migration advances, managing cloud vendors is becoming difficult. It offers cost reductions and short-term security improvements, but obscures the vendor’s actual situation and makes risks harder to estimate. Long-term risks of excessive dependence on cloud providers were also noted, including difficulty retaining internal expertise, cloud supply-chain risks, and price increases.
Cloud vendors, meanwhile, work to ensure safety by obtaining audit-based third-party certifications and disclosing information. Certification schemes include ISMS and SOC2, and for government agencies, the US government’s FedRAMP and the Japanese government’s ISMAP. It was also noted, however, that obtaining such certifications, especially SOC2 and ISMAP, is very costly and difficult for small and medium-sized providers. In response, procuring organizations sometimes seek to cover gaps that smaller providers cannot address by supplementing them2.
It was also noted that when disclosure is requested following an incident, attention must be paid to how much information a cloud vendor can disclose. Audit trails and third-party audit reports can be presented, but technically separating and disclosing an individual customer’s data may be difficult. Full disclosure may have limits.
Organizations adopting cloud services must weigh these points when assessing the advantages and disadvantages of cloud migration.
Large-Scale Ransomware Incidents and Countermeasures
Recently, large-scale ransomware incidents have continued. They have shifted from random attacks to targeted, high-value operations, with increasing sophistication and larger impacts. Examples include effects on critical infrastructure, epitomized by the Colonial Pipeline incident3, and more recently the cases of Company K4 and Company I5.
In several senses, these incidents show that the phase of the damage has changed.
First, the monetary damage has become extremely large.
Second, they can affect a person’s entire life, including life and death. If energy supplies stop in an extremely cold region, people may immediately freeze to death; if a celebrity’s address becomes known, it could lead to murder by a stalker6.
The Company I case also has major consequences through damage to social trust mechanisms. Although Company I had ISMS and PrivacyMark certifications, underwent proper audits, and essentially separated its networks, information was stolen. This resulted from information that should have existed only on the business network being copied to and left lying around on the information network, and from data certified to municipalities as deleted not actually having been deleted. The certification schemes failed to detect this, producing the social impact of reduced trust in certification itself.
Regarding certification schemes such as ISMS, the panel also said:
- They can easily become checklist exercises, but that is not their essence; executive leadership and risk awareness are crucial;
- Obtaining certification itself must not become the objective;
- Certification schemes specialized for particular operations are needed, and understanding the role and limits of certification must lead to more effective measures;
These and other points were raised.
This section also emphasized how information should be disclosed following an incident and the importance of managing contractors. It further noted that stronger monitoring and a review of management systems are indispensable ransomware countermeasures.
Footnotes
- Creating ransomware that operates on a smartphone is considered extremely difficult. Installing apps presents a high barrier, and an app can access only data in its own sandbox or, at most, photos, so it is likely capable only of limited functions such as encrypting those files. The reports may not reflect the facts.
- Example: the Digital Agency’s startup bonus
- Piyolog: A Summary of the Cyberattack on a US Oil Pipeline Company
- Author’s note: KADOKAWA, KADOKAWA Suspends “Niconico” Following Ransomware Attack
- Author’s note: Piyolog: A Summary of Iseto’s Ransomware Infection
- Professor Sunahara and I discussed this while listening to the panelists’ preparatory meeting in the speakers’ lounge.
Related posts

〔Presentation Announcement〕 Building Trust in the Post-Coronavirus Era (2021-05-21)
At the 25th Shirahama Symposium on Cybercrime, themed “Now Is the Time to Consider 'Trust' in Cyberspace: Cloud Security and Zero Trust Networks,” I will give…

Authorized Push Payment (APP) Fraud and the Impact of Digital ID Wallets
I wrote this report several months ago, but I think it is important, so I am publishing it here. In A4 format it runs to 28…

Japan’s Financial Services Agency Calls on Financial Institutions to Review the Practice of Emailing Password-Protected ZIP Files (So-Called PPAP)
According to a May 22 report by The Nikkin, Japan's Financial Services Agency appears to have called on financial institutions to review the practice of emailing…
