In July 2026, Japan’s Ministry of Internal Affairs and Communications issued administrative guidance to LY Corporation over the external transmission of approximately 8.03 million pieces of user-related information from several LINE games.
The information included internal user identifiers sent by a development and operations partner to an external analytics service without LY Corporation’s approval and without the required notice to users.
The incident lasted for nearly four years.
At first glance, this may look like yet another story about one company failing to manage user data properly.
But in Japan, the name LINE carries much more weight than an ordinary messaging app.
And that is where this story becomes more interesting.
Ohakonbannichiwa❗️ This is RYO from the Rikigaku Observation Institute.
To Understand the Issue, You First Need to Understand LINE in Japan
For readers outside Japan, a little background is necessary.
LINE was launched in Japan in 2011 by NHN Japan Corporation, which had been established by South Korea’s NHN Corporation, now NAVER Corporation.
So simply calling LINE either a “Japanese app” or a “Korean app” does not fully describe its history.
What matters here is that LINE became extraordinarily successful in Japan.
By March 2026, LINE had about 100 million monthly active users in Japan, equivalent to more than 80 percent of the country’s population.
People use it to talk with family and friends.
Companies use it to communicate with customers.
Stores use official accounts for marketing, reservations and customer service.
And local governments and public organizations have also adopted LINE for administrative communication and public services.
After concerns arose over LINE’s data management in 2021, the Japanese government actually surveyed the use of LINE by government agencies and local authorities and published guidelines for its continued use.
That fact alone tells us something important.
LINE had already become something close to social infrastructure in Japan.
The 2021 Controversy Was More Complicated Than “Servers in China”
This history also explains why some Japanese users react strongly whenever another LINE-related data incident appears in the news.
There is an important factual distinction here.
The 2021 controversy was not simply that “LINE stored all Japanese user data on servers in China.”
The actual problem included the fact that contractors located in China had been able to access certain personal information belonging to Japanese users.
LINE reported to Japan’s Personal Information Protection Commission that such access from China had been blocked by March 23, 2021.
At the same time, some data — including certain photos, videos and files — had been stored in data centers in South Korea.
LINE subsequently began moving the relevant Japanese user data to servers in Japan.
LY Corporation says that the migration of all data covered by that plan was completed by June 2026.
There were also later incidents.
In a major unauthorized-access incident disclosed in 2023 and updated in 2024, LY Corporation reported that 302,980 pieces of user-related personal data had been leaked or potentially leaked, along with information relating to business partners and employees.
That incident began after malware infected a computer used by an employee of a contractor connected to South Korea’s NAVER Cloud.
None of this means that every piece of information on LINE is currently sitting exposed somewhere overseas.
Nor does Korean corporate origin itself prove that a service is unsafe.
The real issue is governance.
Who can access the data❓️
Where is it stored❓️
Which companies and contractors are connected to the system❓️
And are users and public institutions being told those facts accurately❓️
That is a much more useful security question than simply asking which country a company came from.
Infrastructure Does Not Automatically Mean Trust
There is another contradiction in Japan that is easy to miss from overseas.
LINE has become infrastructure-like, but not everyone wants to participate in that infrastructure.
There are Japanese users who consciously avoid LINE, PayPay and other services associated with the broader SoftBank–LY ecosystem.
The reasons are not all the same.
Some are specifically concerned about privacy, cross-border data management or past security incidents.
For others, the reaction is less technical and almost instinctive:
“I simply don’t want to give that corporate ecosystem more of my data.”
There is no reliable statistic telling us exactly how many Japanese people avoid LINE or PayPay for this particular reason.
So it would be wrong to exaggerate this into a majority view.
But privacy-driven refusal of digital services itself is certainly not imaginary.
A 2026 Japanese consumer survey found that, among respondents who felt uncomfortable providing personal information, 35 percent said they had stopped using a service.
This produces an interesting kind of friction.
If a privately operated platform becomes deeply embedded in everyday life, choosing not to use it begins to carry a cost.
A person may distrust the service, yet discover that a company, store, school, neighborhood association or local authority assumes everyone has it.
The technical freedom not to use a service still exists.
But the practical price of exercising that freedom gets higher as the network grows.
That is worth remembering when somebody says:
“If you don’t trust LINE, just don’t use it.”
The Front Door Is Fortified — While the Back Door Is Left Open
Now let us move from LINE itself to corporate information security.
Many companies protect their company-issued computers and smartphones very seriously.
USB storage is restricted.
Software installation is controlled.
Access logs are recorded.
Smartphones are managed through MDM.
Endpoint protection and access-control systems are installed.
Ohakonban’nichiwa! I’m RYO from the Rikigaku Observation Institute!
“Which do people prefer: fiction written by ChatGPT or fiction written by a human?”
A study by researchers at Villanova University, recently covered by CNET Japan, produced an intriguing result: participants rated the ChatGPT-generated stories more highly than the human-written ones.
In the first experiment, 1,682 adults aged 18 to 81 evaluated short stories written either by humans or by ChatGPT, rating their quality and how absorbing they found them. The AI-generated stories received higher ratings overall. Yet another effect appeared at the same time: stories described as “human-written” were rated more favorably, regardless of who had actually written them.
In subsequent experiments, participants were asked to distinguish human-written stories from AI-generated ones. Their performance showed that telling the two apart was far from straightforward.
So far, so interesting. But while reading the Japanese article, something else caught my attention.
In Japanese, the AI Version Really Is Easier to Read
The CNET Japan article includes Japanese translations of excerpts from the stories used in the study.
In the AI-generated story, the narrator sits beside a pond, remembers her mother, watches autumn leaves fall and koi swim beneath the surface, and reflects on change and constancy in life.
The prose may have that slightly familiar ChatGPT tendency to wrap things up a little too neatly, but its meaning comes across immediately.
The human-written story, by contrast, develops a metaphor around childbirth. One character is described as being in labor; the narrator casts herself as a midwife; the husband becomes an anxious father; and the metaphor expands toward the idea of a sacred event.
Of course, these are only excerpts from longer works, so it would be unfair to judge either story as a whole from these passages alone. But when I read the two excerpts in Japanese, I found the AI-generated one noticeably smoother and easier to follow.
The human-written passage felt different. In Japanese, it had the flavor of an older translated novel—or, to exaggerate slightly, something produced by an earlier generation of machine translation.
There is a particular kind of translation effect that Japanese readers sometimes encounter in American films, advertisements or tech presentations: a perfectly ordinary English phrase crosses into Japanese and somehow comes out sounding grand, solemn and vaguely philosophical.
To invent an exaggerated example:
“This is not merely a device. It is a new way to experience tomorrow.”
Perfectly plausible in an English-language presentation. Translate that too literally into Japanese, however, and suddenly it sounds as though Apple has started writing philosophy.
The human-written excerpt gave me a little of that feeling.
But Wait—These Stories Weren’t Written in Japanese
And then an obvious point occurred to me: the experiment was conducted in English.
Japanese readers of the CNET Japan article are therefore not reading exactly what the participants in the study read. What reaches us has already traveled through another process:
English original → Japanese translation → Japanese reader
That distinction matters particularly when the subject is fiction. In a news report, a translation can often do its job as long as factual information—dates, numbers, events and statements—is transferred accurately. Fiction is different. Word order, rhythm, ambiguity, metaphor and cultural association can all be part of the work itself.
A metaphor that feels natural and understated in English may become conspicuous, overly dramatic or strangely explicit when its structure is carried directly into Japanese.
So by the time I compare these two excerpts in Japanese, I am no longer observing only ChatGPT vs. human. I am also observing ChatGPT in English → Japanese translation versus human writing in English → Japanese translation.
There is another lens between the original text and me: translation.
The AI Wasn’t Writing from Nothing
Looking at the original paper reveals another important detail. The researchers used three human-written stories and asked GPT-4 to generate a corresponding story for each one.
For example, the AI story Reflections in Still Water was paired with the human-written story FISH. GPT-4 was given fairly specific instructions involving themes such as life and death across generations, uncertainty, koi as a symbol, and the perspective from which the story should be told.
In other words, the researchers did not simply tell GPT-4:
“Write me a story.”
Themes, symbols, narrative perspective and other elements were extracted from the human-written works and used to construct corresponding prompts for the AI.
That is a reasonable way to make the stories comparable in an experiment. But when the study is reduced to the popular question “Which writes better fiction, AI or humans?”, this experimental condition is worth remembering.
Using Saussure as a Measuring Stick
This is where Ferdinand de Saussure becomes useful—not as a subject for a linguistics lecture, but as a tool for observation.
To simplify his theory considerably, Saussure described the linguistic sign through the relationship between the signifier—the form of a word or expression—and the signified—the concept it evokes.
These signs connect to their meanings in a relatively straightforward way. Leaves fall in autumn / koi swim beneath the water / the narrator remembers her mother / something constant offers comfort amid a changing life.
Of course, none of these meanings is completely independent of language or culture. But the relationships among them seem relatively easy to preserve when the passage moves from English into Japanese.
Here, meaning develops through an extended metaphor. The effect depends not only on what each individual word signifies, but also on the network of associations created among those words within a particular linguistic and cultural context.
That network may not survive translation in exactly the same form. The words can all be translated correctly, and the tone can still shift. What felt literary in English may become unusually explicit in Japanese. A metaphor may remain perfectly understandable while becoming heavier, more conspicuous, or simply more “translated.”
In other words, translation does not merely replace one signifier with another. It has to reconstruct relationships among signs in another linguistic system.
And that raises another question.
Are AI-Generated Texts More “Translation-Resistant”?
From this point on, I am no longer describing a finding from the Villanova study. This is a hypothesis that occurred to me while reading the Japanese translations.
Perhaps AI-generated prose is not simply easier to read because it is more direct. Perhaps it also tends to preserve its semantic relationships more easily when moved from one language to another.
Large language models learn from enormous quantities of text. In doing so, they may gravitate toward patterns and structures that recur across many examples of language. That can certainly be a weakness: AI prose can feel averaged out / less idiosyncratic / overly polished / strangely familiar.
But turn the same characteristic around, and it suggests another possibility: those more widely shared structures may also be easier to carry across languages.
Human literary writing can derive much of its richness from exploiting the peculiarities of a particular language, culture, voice or network of associations. Precisely because those relationships are so specific, some of that richness may be difficult to reproduce elsewhere.
AI-generated prose may sacrifice some of that specificity. But could the same sacrifice make it more portable?
Less dependent on a particular system of signifiers → less lost when those signifiers have to change?
I don’t know. And the Villanova study does not answer that question.
Testing it would require a different experiment—one designed specifically to compare how human-written and AI-generated texts behave across translation. But that is exactly why the Japanese version of the article interested me. Translation may have introduced a new variable that the original experiment was never designed to examine.
The Researchers Themselves Don’t Say “AI Won Because It’s Easier to Read”
There is another point worth keeping in mind. Popular coverage naturally tends to focus on a simple explanation: AI-generated stories may have been preferred because they were more direct, concise and easier to understand.
The original paper is more cautious.
The researchers discuss ease of interpretation as one possible explanation for the higher ratings, not as a conclusion established by the experiments. They also point out an obvious complication: literary fiction is not necessarily “better” simply because it is easier to understand. Ambiguity, complexity and room for interpretation can be part of what gives a story its value.
The later experiments produced an even more interesting result. Participants who relied on wording as a clue to authorship tended to be worse at identifying whether a story had been written by a human or by ChatGPT. In one experiment, participants who used their own enjoyment of a story as a clue were also more likely to get the answer wrong.
In other words, an intuition such as “This is easy to read, so it must be AI” may not help us identify AI writing at all. It may even push us in the wrong direction.
That makes the result more interesting, not less.
How Long Will “AI vs. Human” Remain a Useful Comparison?
There is a broader problem with the question itself. In a controlled experiment, separating “AI-written” from “human-written” text makes perfect sense. Outside the laboratory, however, that boundary is already becoming difficult to maintain.
Consider professional shogi. Today’s top players study moves suggested by AI, including moves that previous generations of human players might have considered unnatural or even poor. They examine the reasoning behind those moves, understand their value, and incorporate what they learn into their own play.
When a professional later plays such a move in an actual match, whose move is it? The human’s? The AI’s? The question quickly becomes awkward.
Something similar happened long ago with spreadsheets. Before software such as Microsoft Excel, enormous amounts of human time were spent performing calculations and organizing data manually. Today, we do not normally look at a spreadsheet produced with software and say, “This is not human work because a computer calculated it.”
The software has become part of the human workflow. Generative AI may be moving in the same direction.
Human → AI → Human
Writing is already beginning to look like this:
A human develops the idea → ChatGPT produces a draft → the human spots what feels wrong → the AI generates alternatives → the human rejects some, keeps others and rewrites the result.
Who wrote the finished text?
“The human” and “the AI” are both incomplete answers.
The more interesting change may therefore be not that AI is becoming capable of writing better stories than humans, but that humans and AI are beginning to alter one another’s output.
Humans learn from AI. Humans incorporate those techniques into their own writing. AI systems, in turn, learn from human-produced language in an environment that is itself increasingly influenced by AI.
Human → AI → human → AI.
Shogi offers an early example of this cycle. What begins as an “AI move” can eventually become part of ordinary human theory.
If something similar happens to writing, the clean boundary required by the question “AI or human?” may become increasingly artificial.
Perhaps the more useful question will eventually be not “Who wrote this?”, but “What forces shaped the text that ended up in front of us?”
English → Japanese (translator unknown) → ChatGPT → English. At this point, even Saussure might ask for a system update.😂
小説では、語順、リズム、曖昧さ、比喩、文化的な連想まで作品の一部です。英語では自然な表現でも、その構造を保ったまま日本語へ移せば、大げさだったり説明臭かったりする文章になることがあります。つまり、われわれが比較しているのは単純な「ChatGPTの文章 vs 人間の文章」ではありません。翻訳というレンズが一枚挟まっています。
たとえば人間作品『FISH』に対応するAI作品『Reflections in Still Water』では、「世代をまたぐ生と死/不確実性/鯉を象徴として使うこと/成長した子どもの視点」といった具体的な条件がGPT-4に与えられました。つまり、「はい、小説を書いて」と丸投げしたわけではありません。人間作品からテーマ、象徴、視点などを抽出し、それに対応する条件を与えたうえでAI作品を生成しています。
Ohakonbanichiwa! RYO here from the Dynamics Observation Institute. Yes, that means good morning, hello, and good evening — all at once. Very efficient.
Japanese frozen-food giant Nichirei was hit by a cyberattack that disrupted shipments and other operations.
The ransomware group RansomHouse later claimed responsibility and reportedly published more than 200,000 files, including documents that may contain personal and business information.
“More than 200,000 files leaked” certainly sounds alarming. But there is another way to look at what happened.
What exactly did RansomHouse gain by publishing them?
Did Nichirei Refuse to Pay?
There is no public confirmation that Nichirei refused to pay a ransom, nor do we know what negotiations, if any, took place behind the scenes.
So we cannot say that Nichirei “didn’t pay.”
What we can observe, however, is the sequence of events.
Nichirei detected the system failure on July 13, isolated affected systems, worked with external cybersecurity specialists, and subsequently restored normal operations. Meanwhile, RansomHouse continued releasing stolen data, with more than 200,000 files reportedly published by August 10.
We do not know what happened at the negotiating table. But looking at what happened outside it, one question naturally arises:
Is this really how RansomHouse wanted things to end?
Extortion Is Most Powerful Before the Data Is Published
In double-extortion ransomware attacks, stolen data has value. But perhaps even more valuable is the fact that it has not yet been made public.
As long as the attacker can say, “Pay us or we’ll publish it,” the data remains a hostage and a bargaining chip. Once the data is published, however, that particular bargaining chip is gone. Publish more, and even more chips disappear.
The damage to the victim is real, especially when personal or confidential information is involved. But from the attacker’s perspective, there is a strange contradiction: every threat they carry out also destroys part of their own leverage.
In other words, self-defeating extortion.
Are 200,000 Files Really 200,000 Valuable Targets?
The number 200,000 sounds impressive. But 200,000 leaked records do not automatically translate into 200,000 profitable victims.
If much of the data consists of names, email addresses, phone numbers or business relationships, criminals still have to turn that information into money through phishing, impersonation or fraud.
Information linking someone to Nichirei may certainly make targeted scams more convincing, so the risk should not be underestimated. But if Nichirei and related companies repeatedly warn customers and business partners about suspicious messages, invoices and payment requests, the success rate of those scams can be reduced.
Leaked data cannot be taken back. But its value as a criminal commodity can still be reduced.
Nichirei Paid a High Price — But It Also Gained Experience
The price Nichirei paid for this incident was undoubtedly high. But the company also gained something that only an organization that has actually been attacked can acquire: real-world experience.
Business continuity plans, backups and incident-response exercises are essential. But some weaknesses only become visible when systems actually go down.
Which operations stop? / Who makes the decisions? / How far does the disruption spread? / How quickly can the business recover?
These are part of an organization’s “shadow” — weaknesses and realities that remain hidden during normal operations.
If Nichirei turns this experience into organizational knowledge, the next time it faces a cyberattack, it will no longer be experiencing one for the first time.
That is an asset the attacker cannot steal or copy.
So What Did RansomHouse Gain?
Breaking into systems, stealing data, maintaining infrastructure, threatening a victim and eventually publishing the stolen files all require time, skills and resources.
Again, we cannot conclude that Nichirei refused to pay, nor can we say that the attack was unprofitable.
Still, watching RansomHouse continue to burn through its remaining cards by publishing more and more data makes it difficult not to wonder:
“We leaked 200,000 files!”
Okay.
But how much money did you make?
The Best Defense May Be Making Ransomware Unprofitable
Ransomware defense usually focuses on one question: How do we stop attackers from getting in?
That is obviously essential. But if ransomware is also viewed as an economic activity, there is another form of defense:
Make successful attacks unprofitable.
Recover quickly. / Limit the damage. / Warn potential secondary victims. / Continue operations without depending on the attacker.
The more organizations can do this, the greater the chance that attackers will successfully break in — and still fail to make money.
For ransomware operators, that may be almost as damaging as failing to break in at all.
Break in. / Steal the data. / Disrupt operations. / Threaten the victim. / Leak the files.