SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Doppel honeypot spots Japanese phishing on day one

Doppel honeypot spots Japanese phishing on day one

Fri, 31st Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Doppel has published findings from a five-week phishing honeypot project in Japan that began receiving hostile mail on its first day.

The cybersecurity group used a network of email inboxes designed to attract attacks from threat actors targeting Japanese users. The operation was intended to show what can be seen when phishing campaigns are observed from inside the target environment rather than after they surface in feeds, blocklists or victim reports.

During the first five weeks, the sensors received thousands of unsolicited messages. Doppel said 51.5% of the activity was reconnaissance, with attackers probing whether the server was live, whether it would accept mail and whether functions such as an open relay were available.

The rest included direct fraud attempts. Of all messages received, 40.1% were genuine lures designed to deceive recipients, with advance-fee scams forming the largest category, followed by credential phishing and sextortion.

Local patterns

Japan was chosen because much of the phishing activity aimed at Japanese users remains difficult for Western threat-intelligence providers to detect. Doppel pointed to the country's regional email environment, which relies heavily on domestic services and mobile carrier or internet provider mailboxes, including Docomo, SoftBank, au, Nifty and Biglobe.

Many phishing attacks targeting Japanese users also load only over Japanese mobile networks. As a result, a page that displays a credential form to a user in Tokyo may appear blank to a crawler operating from a foreign datacentre, creating a gap in outside monitoring.

The report found that attackers repeatedly used the same types of brands in impersonation campaigns. Four out of five mimicked a technology brand, while eCommerce, shipping, finance, social media and streaming services accounted for the rest.

More specifically, credit card and consumer finance companies were the most impersonated brands in the top 10 observed by the honeypot. They were followed by eCommerce businesses and global card and payment networks.

Timing signals

The lures showed a clear weekly pattern. Some 34% arrived on Mondays and 33% on Fridays, meaning those two days accounted for more than two-thirds of all observed lures.

Most also arrived at 9 a.m. Japan Standard Time or noon, with those time slots making up almost half the total. This suggests attackers were timing messages to match periods when recipients were likely to be checking email, such as the start of the workday and lunch hour.

The project also examined what Doppel described as the social engineering attack chain. Phishing emails, it said, are only the visible part of a broader operation that begins earlier with domain registration, cloned login pages, phishing kits and tests of sending infrastructure.

By operating as the recipient, the honeypot was designed to capture campaigns at the contact stage rather than after a user had already interacted with them. This approach also exposed pre-launch activity such as mail port probing, address validation and test messages.

Collection model

The honeypot did more than collect raw mail. It used an analysis engine to inspect each message, classify the threat by intent, identify the impersonated brand and process content in both Japanese and English.

That produced three layers of intelligence: the phishing payload itself, reconnaissance traffic and login attempts against the honeypot accounts. Because no legitimate users were attached to the accounts, every login attempt could be treated as hostile.

The system also tracked the signatures of attacker tools across different addresses, Doppel said, allowing the same operator to remain visible even when connection points changed. This made it possible to link probes, test activity, source addresses, domains and fake login pages into a single operation.

The broader aim is to move detection earlier in a campaign's life. When infrastructure, domains and phishing kits are reused, intelligence gathered from one operation can provide warning of the next before it reaches intended victims.

Japan was the initial market for the project, but Doppel said the same method could be applied in other non-English regions where local phishing activity is underrepresented in mainstream threat-intelligence sources.

"Most phishing intelligence arrives after the attack is already working," Doppel said.