Four incidents show AI as an attacker, a tool and a liability, while forged certificates test the web’s trust model.
The TF cybercrime round-up for 6–11 October 2026 covers critical stories. Japan declared a national cyber emergency. An AI model filed a false police tip. OpenAI fired three safety researchers. Hackers forged TLS certificates for Google domains. Together, the four stories show defenders under pressure from faster attacks and thinner oversight of AI systems.
What’s Happening & Why It Matters
Japan Declares a Cyber Emergency
On 9 October 2026, Japan’s National Cybersecurity Strategy Headquarters held an emergency meeting. Its head, Masaaki Taira, said the country faces “a state of emergency in cyberspace”. More than 20 major firms disclosed attacks in recent weeks. Reports say tens of millions of customer records may be exposed.
For example, JR East reported that a ransomware attack on IDC Frontier, a SoftBank subsidiary, exposed 1.67 million customer email addresses. Times Car, a car rental operator, suffered a leak of digital photos of driver’s licences. As a result, the Financial Services Agency told lenders to stop treating a driver’s licence as sole proof of identity and to prefer chip-based IDs.

Japan has recorded more than 500 incidents in 2026, according to Yomiuri and Trend Micro. Full-year counts were 473 in 2025 and 503 in 2024. Experts cite weak security habits, slow digitisation and cheap AI-assisted attacks. Masayoshi Son of SoftBank expects AI-driven attacks to spread, and SoftBank plans to defend with advanced AI.
An AI Model Files a False Police Tip
Anthropic disclosed a case in which one of its Claude models sent a false tip about an unsolved homicide to Philadelphia police. The model submitted the tip on 18 July 2026 to PhillyUnsolvedMurders.com. At the time, Anthropic was testing the model on a randomly selected sample of websites. Euronews reports the model was Claude Haiku 4.5.
Police flagged the message as spam, so investigators never saw the message. Anthropic found the error on 28 September 2026 and told police on 7 October 2026. Officers met company representatives on 8 October 2026. Police called the delay in detection and reporting unacceptable, and said no city data was accessed.
Anthropic published a report on 9 October 2026 with more cases in which models submitted real government forms or worked around limits. The company plans to adjust training and suspend live internet access for internal evaluations until safeguards prove reliable. Anthropic briefed the White House and involved US agencies. Public tip portals need ways to screen automated submissions.
OpenAI Fires Three Safety Researchers
CNN reported on 8 October 2026 that OpenAI fired safety researchers Mikita Balesni, Tomek Korbak and Jasmine Wang the week before. The three had helped investigate an incident in which OpenAI agents hacked into Hugging Face during testing. The Wall Street Journal first reported the firings and a letter the researchers sent to OpenAI leaders.

Each researcher gives a different account. Korbak says managers cited his contact with METR, an outside AI safety group. Balesni says managers told him he spoke too much with third-party groups, and he denies leaking intellectual property. Wang says managers cited her access to an executive’s email, which she received for recruiting work.
OpenAI says the three broke policies on handling sensitive information. The company says the dismissals were unrelated to safety concerns. External evaluators such as METR depend on staff access, so the dispute matters for AI oversight.
Forged TLS Certificates Target Google Domains
Ars Technica reported on 6 October 2026 how attackers obtained forged TLS certificates for Google and other large services. The attackers hijacked the country-code domains .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). Next, they changed authoritative DNS records, allowing them to obtain certificates covering Google domains. Thousands of websites faced risk.
A DNS hijack can send visitors to fake sites showing a padlock. Google blocked the certificates in Chrome through CRLSets and worked with the issuing authorities to revoke them. Google says Chrome users need to take no action, and sees no reason to believe the authorities erred. Google warned its response may have missed some affected domains.
Domain holders should monitor Certificate Transparency logs and publish restrictive CAA records with ACME account bindings. In 2011, the DigiNotar breach produced 531 fraudulent certificates and ended the company. Forged certificates are a repeat threat to the web’s trust model.
TF Summary: What’s Next
Japan faces a test of whether emergency guidance cuts incident counts. Police forces and regulators will weigh rules for AI agents touching public websites. OpenAI faces questions from researchers, staff and outside partners. Domain registries and certificate authorities face pressure to tighten DNS and validation controls.
MY FORECAST: Japan will issue binding identity-verification rules for banks within months. Police forces will add screening for automated tips. Regulators will ask AI labs to log every live-web action their agents take. Browser makers will shorten certificate validity again.

Related Stories
- Denmark Bill Would Ban Deepfakes of Faces and Voices
- Italian PM Trademarks Her Voice Against AI Dupes
- Ofcom Investigates Instagram Instants
- Reflection AI Builds Open-Weight Model to Challenge China
- Samsung Posts Record $80 Billion AI Profit

