According to a May 22 report by The Nikkin, Japan’s Financial Services Agency appears to have called on financial institutions to review the practice of emailing password-protected ZIP files (so-called PPAP). This is because the recipient’s security software cannot detect malware (malicious programs), creating risks such as information leakage. The agency reportedly plans to confirm through future inspections and monitoring whether improvements are being made (!!).
During an exchange of views with regional banks on May, a senior FSA official reportedly stated unequivocally that “password-protected files should generally not be sent.” The agency is asking institutions to make encryption of the email transmission path the default and to use alternatives such as online storage when that is difficult. Shizuoka Bank and Bank of Kyoto have already switched to methods such as sending a dedicated URL rather than attaching files to email, and moves to abolish PPAP are progressing. However, many financial institutions still continue to use PPAP.
Many organizations have traditionally used a method called “PPAP”—a name coined by Mr. Otaishi of the PPAP Research Institute—in which a password-protected file is emailed and the password is sent separately afterward. Risks such as interception and malware infection have been pointed out. For example, the July 2020 issue of Information Processing, the journal of the Information Processing Society of Japan, highlighted the problem in a journal mini-feature titled “Goodbye, Meaningless Encrypted ZIP Email Attachments”.

After consulting with Koichiro Eto, then at AIST, we organized the feature as follows. (All articles can be viewed for free.)
- 0. Editorial Introduction — Ritual Security PPAP: Toward a Japanese Security Renaissance
- 1. What Is PPAP? — Its Dark History of Development
- 2. The Security Significance of PPAP
- 3. Why Did We End Up Using PPAP?
- 4. Roundtable: “How Can We Eliminate PPAP from Society?”
- Natsuhiko Sakimura, Akira Otaishi, Masanori Kusunoki, and Tetsutaro Uehara
This feature later won the 37th Telecom Interdisciplinary Research Award.
While we were preparing this feature, the coronavirus pandemic happened to strike. The roundtable was held online, among other things, and the authors never gathered together in one place. Consequently, even the roundtable photograph featured one participant appearing as a virtual female avatar.
Then, when this news broke, the “29th Shirahama Symposium on Cybercrime” happened to be taking place. Miraculously, all 4 authors were there together, so we took a commemorative photograph. It may have been the first time since the feature that all 4 had physically gathered together.

Related posts

IPSJ Magazine Special Feature: “Goodbye to Pointless Encrypted ZIP Email Attachments”
The special feature “Goodbye to Pointless Encrypted ZIP Email Attachments,” which we had been preparing since the end of last year for the Information Processing Society…

【October 27】 Online Talk Event: “Goodbye, Pointless Encrypted ZIP Email” (Commemorating the 37th Telecom Interdisciplinary Research Award)
The “Mini Special Feature: Goodbye, Pointless Encrypted ZIP Email Attachments” in the July 2020 issue of Information Processing received a Special Commendation at the 37th (2021)…
“We Didn’t Know” Is No Excuse: FSA Gets Serious About Strengthening Information Security at Financial Institutions
On July 13, the Financial Services Agency compiled the findings of its “Study Group on Information Security,” which discusses information security measures at financial institutions. Its…

You must be logged in to post a comment.