After living in the United States for more than 25 years, I have noticed a difference in how people in the U.S. and Japan tend to think about data breaches and cybercrime.
In Japan, attention often centers on the fact that personal information has been exposed. In the United States, where identity theft is a familiar risk, the discussion more often extends to how the information may be misused afterward.
Preventing a breach remains essential. But no organization or individual can eliminate the risk entirely. The practical question is how exposed information may be misused—and how to prevent that exposure from leading to financial loss, account takeover, or fraud.
This is the first article in a three-part series examining information security and identity verification through my experience in the United States. It focuses on limiting the damage after personal information has been exposed.
This article is based on a piece originally published in 2022 and has been updated to reflect current practices.
A data breach may be the beginning, not the end
A breach does not always produce an immediate financial loss.
A name, address, phone number, email address, date of birth, or purchase history may appear harmless in isolation. But when several pieces of information are combined, they can support phishing, payment fraud, account takeover, and identity theft.
The breach is therefore not necessarily the end of the incident. It can be the starting point for another crime.
In the United States, the Federal Trade Commission operates IdentityTheft.gov, which helps people report identity theft and develop a recovery plan. Its existence reflects an important operational assumption: prevention matters, but recovery must also be designed in advance.

Personal information makes scams more convincing
Fraud is no longer limited to generic messages sent to large numbers of people. Personal data allows criminals to tailor their messages to specific individuals.
An email that includes the name of a store someone has used and the approximate amount of a previous purchase may look like a legitimate transaction alert. A coupon appearing to come from a familiar retailer may be more likely to attract a click.
Passwords and credit card numbers are not the only valuable data. Purchase history, employer information, family relationships, and personal interests can all make a fraudulent message appear credible.
In the United States, fraudulent calls and messages impersonating the Internal Revenue Service often increase around tax season. Japan has similar problems involving messages that impersonate banks, delivery companies, government agencies, and e-commerce platforms.
The details vary, but the underlying strategy is the same: create urgency, increase anxiety, and persuade the recipient to act before taking time to verify the request.

What happens when you click a link
It is tempting to assume that clicking a link is harmless as long as no password or payment information is entered.
That is not always the case. A link may contain an identifier that tells the sender that an email address is active and that its owner responded to a particular subject. This information can make the address more useful for future scams.
If the destination is a fraudulent login page, anything entered there may be captured.
The U.S. Federal Trade Commission recommends avoiding links in unexpected messages and contacting the company through a website or phone number known to be legitimate. The display name of an email sender is not enough. Display names can be forged, and look-alike domains can be difficult to recognize on a small screen.
A safer practice is to open the company’s official application or use a previously saved bookmark rather than signing in through an email or text message.
What individuals can do to limit the damage
Individuals cannot control the security practices of every service they use. They can, however, reduce the chance that one incident will compromise several accounts.
Basic measures include:
- Using a different password for each service
- Using a trusted password manager
- Adopting passkeys where available
- Enabling multi-factor authentication
- Avoiding login links in unsolicited messages
- Reviewing bank and credit card activity regularly
- Keeping operating systems, browsers, and applications updated
- Knowing how to report an unauthorized transaction
The objective is not merely to keep every piece of information secret. It is to ensure that the compromise of one service does not automatically give an attacker access to everything else.
Recovery is part of security
Over the past two decades, I have experienced unauthorized credit card transactions more than ten times.
As a result, reviewing transaction histories has become routine. When I identify a suspicious charge, I contact the issuer, confirm which transactions are unauthorized, and follow the issuer’s process for blocking and replacing the card.
Fraud is never desirable. But clear processes for detection, verification, reimbursement, and card replacement can substantially reduce both the financial impact and the customer’s burden.
This is an important distinction. Security is not only a technology for preventing incidents. It is also the customer experience of returning to normal after an incident occurs.
The risk of remote-support scams
I once received a call in the United States from someone claiming to represent a major technology company. The caller said that my computer was infected and guided me to a Windows administration screen.
Ordinary warnings were presented as evidence of an infection. The next step was an attempt to persuade me to install remote-access software.
If remote access is granted, a criminal may be able to view information on the screen, change settings, or demand payment for unnecessary support. The strength of the scam does not come from technology alone. It comes from creating fear and persuading the victim to follow instructions without stopping to verify the claim.
When a message says that an account will be closed, a computer has been infected, or immediate action is required, urgency itself should be treated as a warning sign.

What companies must do after a breach
For a company, a data breach is not only a security issue. It can affect trust, customer retention, brand value, and financial performance.
A notification that simply says personal information may have been exposed is not enough. Customers need actionable guidance:
- What information may have been exposed?
- How could that information be misused?
- Should passwords or payment cards be changed?
- Where should suspicious activity be reported?
- What monitoring and remediation is the company providing?
- What has been changed to prevent a recurrence?
Warnings that increase anxiety without explaining what to do next do little to protect customers.
From preventing breaches to limiting the damage
Prevention remains the first priority. But a security model that assumes incidents will never happen is incomplete. Individuals need safeguards that limit how far an incident can spread. Companies need plans for detection, communication, recovery, and customer support.
Security must be designed for both sides of an incident: before it happens and after it happens.
Shinya Fujimoto | Founder / Chief Strategist, Silicon Valley Japan Lab
Based in the United States for more than 25 years, Shinya draws on his experience as an engineer and business leader to examine how technology trends emerging from Silicon Valley can inform corporate strategy and business development at Japanese companies.

日本語