Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
Threat Intelligence

Doppel Threat Intelligence: An Inside-Out View of Japan's Phishing Problem

Doppel’s five-week honeypot project in Japan exposes how localized threat actors operate. This report breaks down attacker timing patterns, the top impersonated regional brands, and common fraud tactics. Learn how moving inside the target environment closes critical visibility gaps across the social engineering attack chain.

An Inside-Out View of Japan's Phishing Problem
Report Date: 07/29/2026

Most phishing intelligence arrives after the attack is already working. Here is what changes when you stop watching for phishing from the outside and start receiving it the way the target does—and why we chose Japan to prove it.

A domain gets registered. A phishing kit gets staged. The mail goes out, the links circulate, and the first stolen logins are already flowing back before anyone on the defensive side has seen a thing. Only then does a URL surface in a threat feed, a blocklist, or a customer report, and the defense finally gets visibility and can act. The cybersecurity industry is excellent at reacting quickly. The problem is that even the fastest reaction comes after the attack has already done its work.

There’s another way to see the attack earlier: experience it from the target’s point of view. Instead of waiting for a phishing URL to appear in a feed or customer report, you create the conditions for attackers to target you directly. Their emails arrive in your inbox, exposing campaigns as they begin to operate.

That is the idea behind Honeymail, Doppel’s global honeypot network. Here’s why we started in Japan.

Why Japan, and why the map was blank

Japan has a large, highly localized phishing ecosystem that remains largely invisible to Western threat-intelligence vendors. Much of the industry’s visibility comes from US-centric mail providers, English-language detection models, and global breach feeds. Those sources capture only a small portion of the attacks targeting Japanese users.

Japan’s email ecosystem is regional and largely self-contained, built on providers most Western tools barely account for. Consumer mail runs through yahoo.co.jp, a different company from yahoo.com. It also runs through the mobile-carrier and internet-provider mailboxes that anchor everyday email in Japan, providers like Docomo, SoftBank, au, Nifty, and Biglobe. Most of them rarely register outside the region. The phishing attacks aimed at Japanese users ride those same regional services, and the majority of them only load over Japanese mobile networks, so a datacenter crawler in Virginia sees a blank page where a phone in Tokyo sees a credential form.

That is a coverage gap you cannot close by monitoring for threats from the outside. You close it by operating from inside the target population, as ordinary Japanese consumers and small businesses. Do that, and the region’s phishing traffic flows to you on its own.

The honeypot is the easy part

Email honeypots have been in the threat-intelligence toolkit for decades. The concept is simple. A mailbox, or a network of them, is built to be attacked, so that the attack can be studied safely with no real users behind it and nothing of value to steal. Anyone in security knows what they are and what they are for, and the technique itself is table stakes. What matters is what you point it at, what you pull out of it, and how quickly that becomes protection for someone who would otherwise have been hit. 

The one genuinely hard part is exposure. A honeypot that receives no attacks is useless. The work is getting credible identities in front of attackers; the kind of addresses they already trade, target, and trust. 

That is where the real question begins: not if you can collect it, but if you can turn it into faster protection for the people and brands in the attacker’s path.

Capture is only half the job

Raw attacker mail is not intelligence. It’s a pile of messages in multiple languages, meaningless until it is read and analyzed the way a cyber threat analyst would.

That is the second half of Honeymail: an automated analysis and detection engine that inspects every message the network captures. It parses the structure, classifies the threat by what the message actually tries to do (rather than what it claims to be), identifies which brand is being impersonated, and works natively in Japanese and English so nothing is lost in translation. Each message is tagged, correlated, and turned into structured, first-party intelligence.

Three distinct surfaces come out of it. The first is the phishing itself, the payloads, links, attachments, and lures, captured whole. The second is reconnaissance. Most traffic hitting an exposed mail server is not phishing at all; it’s automated scanning probing for a way in, and that tells you which tools and techniques are in active rotation. The third is credentials. When an attacker tries to log in, we record exactly what they submit. Nothing real lives here, so every attempt is hostile by definition, and every attempt reveals which accounts, brands, and password lists are being worked on right now. We can even recognize the signature of an attacker’s tooling across different addresses, so the same operator stays visible when they change where they connect from.

This is the difference between threat intelligence that reports on attackers and threat intelligence that observes them directly, in real time. These are indicators we watch arrive, not indicators we buy secondhand or wait for a victim to report.

What the traffic showed

We turned Honeymail on in June, and hostile mail did not take weeks to find us. It arrived the same day. Over the first five weeks, the sensors took in thousands of unsolicited messages.

Volume insights, from June 15 to July 20

Volume insights, from June 15 to July 20

Roughly half of activity (51.5%) wasn’t direct phishing; it was reconnaissance. Attackers probing to see whether the server was live, whether it would accept mail, and what functions, like an open relay, it left available for them to use and abuse. That’s expected on any internet-facing mail server, but it is not just noise: it is insight and intelligence on which hosts are hunting for usable infrastructure in real time.

The rest, and the part that matters, was the real thing. 40.1% of everything the honeypot received was a genuine lure, a message built to defraud someone, and those sort into a few familiar tactics. The largest is the advance-fee scam, the unclaimed inheritance, the parcel stuck in customs, the windfall that needs one small payment to release it. Next is credential phishing, the fake login page waiting for a password. Then sextortion, the threat to expose something the recipient never actually did.

The malicious emails, by type of scam

The malicious emails, by type of scam

Attackers reach for the same brands again and again. Four out of five impersonation campaigns mimic a technology brand, the account-security and login prompts people are trained to act on without thinking. E-commerce, shipping, finance, social media, and streaming split what is left.

The brands attackers pretended to be, by industry

The brands attackers pretended to be, by industry

 

Looking more granularly at the top ten most impersonated brands, credit card and consumer finance companies were the most impersonated. They are followed closely by ecommerce and global card and payment networks. The takeaway? Attackers know where the money is, and financial organizations are always under siege. 

Top ten most impersonated brands

Top ten most impersonated brands

Interestingly, the lures followed a clear weekly pattern: 34% arrived on Mondays and 33% on Fridays. Together, those two days accounted for more than two-thirds of all observed lures. One possible explanation is that attackers are timing campaigns around moments when targets may be more vulnerable to deception. Mondays often bring crowded inboxes and competing priorities, while fatigue and reduced focus can make unusual requests easier to overlook on Fridays. Although the data does not prove intent, the concentration suggests that delivery timing may be an important part of attackers’ social engineering strategy.

Most common dates malicious lures were received during the week

Most common dates malicious lures were received during the week

Additionally, most lures arrived at 9 a.m. JST (28%) or noon JST (19%). Together, those two time slots accounted for nearly half of all observed lures. This suggests that scammers may be timing messages to coincide with moments when recipients are more likely to be checking email: at the start of the workday and around the lunch hour.

Timing when a malicious lure was received

Timing when a malicious lure was received

Taken together, the findings reveal a phishing ecosystem built around the routines, brands, and infrastructure of its intended audience. The lures arrived at predictable moments in the Japanese workweek, impersonating the financial and technology services people use every day, and moving through a regional email environment that many Western threat-intelligence systems have limited visibility into.

That is the coverage gap Honeymail was built to close. None of this intelligence came from a commercial feed, blocklist, or victim report after the campaign had already succeeded. We observed the activity directly as it reached the target environment, giving us visibility into both the finished lures and the attacker behavior surrounding them.

Left of the inbox

The message in the inbox is not the attack. It is the point where a long operation finally becomes visible to the target. Doppel calls that operation the social engineering attack chain: five stages that run SetupLaunchContactEngagement, and Compromise. The attacker registers the domains, clones the login page, and stages the kit during Setup, days or weeks before anything is ever sent. Inspect only the email, and you enter the fight at the last stage, on the attacker’s terms.

Honeymail changes where you enter. Because we are the recipient, the sensor sits inside the Contact stage by design, so we see a campaign the moment it launches, in the first wave, not after a victim notices and files a report. We also see the work that comes before the lure. Attackers probe our mail ports, check whether an address is live, and test-run their sending setup against it well ahead of any real message. That activity is Setup, and it lands on the sensors in plain sight. When the finished lure arrives, it carries the rest of the Setup with it: the sending domains, the fake login pages, the phishing-kit fingerprints, the source addresses, the reusable signature of the attacker’s tooling.

That’s where collection stops being a research curiosity and starts changing outcomes. Correlated in the Doppel Threat Graph, those scattered signals stop being fragments and become a single operation. The probe, the test, the sending domain, the cloned login page, the source address, and the next lookalike for the same actor are already up and running, linked across the attack chain rather than landing on five separate desks. It’s the chain itself, seen from the inside, and all of it is pre-compromise, gathered at scale and in real time, before the operation ever reaches the person it was built to victimize.

Fed with that signal at the moment of launch, the graph can move against the infrastructure while the campaign is still going out. Because attackers reuse domains, kits, and hosting, what we capture on one operation is often the early warning on the next before it reaches anyone. Earlier is cheaper. A brand-impersonation site taken down in under an hour rather than left live for weeks is the difference between an attempt and a breach.

When one of those campaigns impersonates a brand Doppel protects, the capture is not a statistic. It’s early warning for that customer, ahead of the same lure reaching their people or their market.

So, every message the network receives does two jobs at once. It shows us how the chain actually works, and it is a live signal that pulls the takedown upstream, toward Setup and Launch, and away from the moment someone gets hurt.

Built to scale, region by region

What begins as a small network in a single region becomes a standing, first-party feed into Doppel’s Social Engineering Defense: more signal, observed directly rather than pulled from a feed, and sooner, caught at launch instead of after a report. Japan is the proving ground, not the ceiling. The same model extends to any market or region where the threats against our customers sit in a coverage gap today, and most non-English markets still do.

The attack always started long before the message arrived. The intelligence about it has usually come from the outside, and after the fact, reconstructing an operation the adversary already built, launched, and walked away from. Honeymail is how you get inside it while it is still running. This is what it looks like to be there first.

About Doppel

Doppel protects individuals and brands from AI-powered impersonation, phishing, fraud, and social engineering by dismantling attacker infrastructure and building resilience through training and simulation.

Doppel's comprehensive Digital Risk Protection solution detects threats across multiple channels, links alerts into a real-time threat graph, and offers AI-driven infrastructure disruption. These threats inform phishing simulation campaigns and security awareness training to offer robust Human Risk Management capabilities that strengthen employee defenses through next-generation training and testing.

Our Mission

Doppel's mission is to protect the world from social engineering attacks every day. Founded in 2022, Doppel is an AI-native platform designed for social engineering defense.

Median Takedown Time Domains, Social Media, Paid Ads

<10h

Faster takedowns on emerging threat vectors than our competitors.

Indicators Analyzed Daily

+1B

Faster takedowns on emerging threat vectors than our competitors.

Trusted Customers

200+

Companies have chosen Doppel