According to a May 22 report by The Nikkin, Japan’s Financial Services Agency appears to have called on financial institutions to review the practice of emailing password-protected ZIP files (so-called PPAP). This is because the recipient’s security software cannot detect malware (malicious programs), creating risks such as information leakage. The agency reportedly plans to confirm through future inspections and monitoring whether improvements are being made (!!).

During an exchange of views with regional banks on May, a senior FSA official reportedly stated unequivocally that “password-protected files should generally not be sent.” The agency is asking institutions to make encryption of the email transmission path the default and to use alternatives such as online storage when that is difficult. Shizuoka Bank and Bank of Kyoto have already switched to methods such as sending a dedicated URL rather than attaching files to email, and moves to abolish PPAP are progressing. However, many financial institutions still continue to use PPAP.

Many organizations have traditionally used a method called “PPAP”—a name coined by Mr. Otaishi of the PPAP Research Institute—in which a password-protected file is emailed and the password is sent separately afterward. Risks such as interception and malware infection have been pointed out. For example, the July 2020 issue of Information Processing, the journal of the Information Processing Society of Japan, highlighted the problem in a journal mini-feature titled “Goodbye, Meaningless Encrypted ZIP Email Attachments”.

After consulting with Koichiro Eto, then at AIST, we organized the feature as follows. (All articles can be viewed for free.)

This feature later won the 37th Telecom Interdisciplinary Research Award.

While we were preparing this feature, the coronavirus pandemic happened to strike. The roundtable was held online, among other things, and the authors never gathered together in one place. Consequently, even the roundtable photograph featured one participant appearing as a virtual female avatar.

Then, when this news broke, the “29th Shirahama Symposium on Cybercrime” happened to be taking place. Miraculously, all 4 authors were there together, so we took a commemorative photograph. It may have been the first time since the feature that all 4 had physically gathered together.

At #sccs2025: from left, Mr. Kusunoki, Sakimura, Professor Uehara, and Mr. Otaishi

Related posts