According to a May 22 report by The Nikkin, Japan’s Financial Services Agency appears to have called on financial institutions to review the practice of emailing password-protected ZIP files (so-called PPAP). This is because the recipient’s security software cannot detect malware (malicious programs), creating risks such as information leakage. The agency reportedly plans to confirm through future inspections and monitoring whether improvements are being made (!!).
During an exchange of views with regional banks on May, a senior FSA official reportedly stated unequivocally that “password-protected files should generally not be sent.” The agency is asking institutions to make encryption of the email transmission path the default and to use alternatives such as online storage when that is difficult. Shizuoka Bank and Bank of Kyoto have already switched to methods such as sending a dedicated URL rather than attaching files to email, and moves to abolish PPAP are progressing. However, many financial institutions still continue to use PPAP.
Many organizations have traditionally used a method called “PPAP”—a name coined by Mr. Otaishi of the PPAP Research Institute—in which a password-protected file is emailed and the password is sent separately afterward. Risks such as interception and malware infection have been pointed out. For example, the July 2020 issue of Information Processing, the journal of the Information Processing Society of Japan, highlighted the problem in a journal mini-feature titled “Goodbye, Meaningless Encrypted ZIP Email Attachments”.

After consulting with Koichiro Eto, then at AIST, we organized the feature as follows. (All articles can be viewed for free.)
- 0. Editorial Introduction — Ritual Security PPAP: Toward a Japanese Security Renaissance
- 1. What Is PPAP? — Its Dark History of Development
- 2. The Security Significance of PPAP
- 3. Why Did We End Up Using PPAP?
- 4. Roundtable: “How Can We Eliminate PPAP from Society?”
- Natsuhiko Sakimura, Akira Otaishi, Masanori Kusunoki, and Tetsutaro Uehara
This feature later won the 37th Telecom Interdisciplinary Research Award.
While we were preparing this feature, the coronavirus pandemic happened to strike. The roundtable was held online, among other things, and the authors never gathered together in one place. Consequently, even the roundtable photograph featured one participant appearing as a virtual female avatar.
Then, when this news broke, the “29th Shirahama Symposium on Cybercrime” happened to be taking place. Miraculously, all 4 authors were there together, so we took a commemorative photograph. It may have been the first time since the feature that all 4 had physically gathered together.

Related posts

IPSJ Magazine Special Feature: “Goodbye to Pointless Encrypted ZIP Email Attachments”
The special feature “Goodbye to Pointless Encrypted ZIP Email Attachments,” which we had been preparing since the end of last year for the Information Processing Society…

I Will Appear on the Okinawa Open Days Panel “Current and Future OSS Initiatives in Economic Security”
It is already the day of the event—in fact, I am writing this now (12/4 9:45) at my desk while preparing for the panel—but I will…

The “DS-511 Guidelines for Handling Digital Identity in Identity Verification for Administrative Procedures, etc.” Have Been Published
After 3 years of development, the Digital Identity Guidelines, to which I had the privilege of contributing as an expert (Expert Meeting on the Revision of…

You must be logged in to post a comment.