IT連携マップシステムどうしのデータ連携・接続仕様のまとめ

5 分で読む

会社の外とつながる入口は、クラウド、ウェブサイトの前に置く CDN(Content Delivery Network)、社外から入るためのリモート接続、メールやファイル共有などの業務 SaaS(インターネット越しに使う業務ソフト)と、いくつもあります。どこから攻撃されるかは入口ごとに違い、提供元が勧める守りも違います。

このページでは 6 つの入口について、報告された攻撃の経路と、提供元などが勧める手を 3 つずつ並べます。


どの入口でも、データ・設定・ID は利用者が守る

次の節に並ぶ攻撃の経路は、どれも事業者の設備ではなく、利用者の側の鍵やパスワード、公開の設定、自分で置いたソフトや機器で起きたものです。Google Cloud も、2025 年後半に増えたソフトの悪用の事案は外に出ている脆弱性を狙ったもので、自社の中核の基盤が破られたものではないと書いています。

Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Notably, these incidents targeted external vulnerabilities and did not involve breaches of Google Cloud’s core infrastructure.

出典を開く確認 2026-09-26

提供元 利用者の受け持ちと書いているもの
Microsoft データ、設定、ID と利用者(どの型のクラウドでも)
Microsoft(Microsoft Learn・Shared responsibility in the cloud・2026-08-24 更新)原文
For all cloud deployment types, you own your data and identities. You're responsible for protecting the security of your data and identities, on-premises resources, and the cloud components you control.

出典を開く確認 2026-09-26

Microsoft(Microsoft Learn・Shared responsibility in the cloud・2026-08-24 更新)原文
Responsibility area On-premises IaaS PaaS SaaS Customer data Customer Customer Customer Customer Configurations and settings Customer Customer Customer Customer Identities and users Customer Customer Customer Customer Client devices Customer Customer Customer Shared Applications Customer Customer Shared Shared Network controls Customer Customer Shared Microsoft Operating system Customer Customer Microsoft Microsoft Physical hosts Customer Microsoft Microsoft Microsoft Physical network Customer Microsoft Microsoft Microsoft Physical datacenter Customer Microsoft Microsoft Microsoft

出典を開く確認 2026-09-26

AWS データの管理と、IAM(AWS の ID と権限の管理)で適切な権限を付けること
AWS(責任共有モデルの解説ページ)原文
お客様は、データの管理 (暗号化オプションを含む)、アセットの分類、IAM ツールでの適切な権限の適用について責任を負います。

出典を開く確認 2026-09-26

Google Cloud アクセスの方針とデータ(どの型でも)
Google Cloud(Architecture Center・責任共有とシェアード・フェイト・2023-08-21 確認)原文
基盤となるネットワークとインフラストラクチャについてはクラウド プロバイダが常に責任を負います。お客様はアクセス ポリシーとデータについて常に責任を負います。

出典を開く確認 2026-09-26

事業者と利用者の分担の考え方そのものは 責任共有モデル(共有責任モデル)とは にまとめてあります。

入口ごとの経路と、勧められている 3 手

攻撃の入口ごとに、報告された経路と最初の1手を6行に並べた図。AWSは漏れたアクセスキーで一時的な資格情報へ、Google Cloudは脆弱性の残った他社製ソフトでWAFで止める、CDNの後ろのサイトはCDNを回る直接の攻撃でCDN以外の接続を断る、リモートデスクトップとVPN機器はランサムウェアの侵入経路で直接開けない・更新する、Microsoft 365などはIDの問題で多要素認証を求める
攻撃の入口ごとに、報告された経路と最初の1手を6行に並べた図。AWSは漏れたアクセスキーで一時的な資格情報へ、Google Cloudは脆弱性の残った他社製ソフトでWAFで止める、CDNの後ろのサイトはCDNを回る直接の攻撃でCDN以外の接続を断る、リモートデスクトップとVPN機器はランサムウェアの侵入経路で直接開けない・更新する、Microsoft 365などはIDの問題で多要素認証を求める

数字は報告ごとに対象と期間が違うので、入口どうしでは比べられません。

入口 報告された攻撃の経路 ① 最初の 1 手 ② ③ 続く 2 手
AWS 攻撃の入口の大部分は、IAM ユーザーのアクセスキーの悪用(Palo Alto Networks の調査チーム Unit 42・2026 年 9 月)
Palo Alto Networks Unit 42(2026-09-21・漏れた AWS の IAM 資格情報を AWS がどう封じるか)原文
When organizations face attacks against their AWS environments, misuse of AWS IAM user access keys continue to account for a large majority of initial attack vectors

出典を開く確認 2026-09-26

長く使うアクセスキーより、一時的な資格情報を使う
AWS(IAM ユーザーガイド・IAM のセキュリティのベストプラクティス)原文
Where possible, we recommend relying on temporary credentials instead of creating long-term credentials such as access keys.

出典を開く確認 2026-09-26

② ルートのアクセスキーを消し、90 日使っていない資格情報を消すか止める
AWS(Security Hub ユーザーガイド・IAM の管理項目)原文
Security Hub CSPM recommends that you remove all access keys that are associated with the root user.

出典を開く確認 2026-09-26

AWS(Security Hub ユーザーガイド・IAM の管理項目)原文
Security Hub CSPM recommends that you remove or deactivate all credentials that were unused for 90 days or more.

出典を開く確認 2026-09-26

③ S3(ファイルの保存サービス)のパブリックアクセスのブロックを有効にする
AWS(Security Hub ユーザーガイド・Amazon S3 の管理項目)原文
S3 general purpose buckets should have block public access settings enabled

出典を開く確認 2026-09-26

Google Cloud 2025 年後半、脆弱性の残った他社製ソフトの悪用(44.5%)が、弱い資格情報(27.2%)を初めて上回った(Google Cloud の報告)
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Threat actors exploited third-party software-based entry (44.5%) more frequently than weak credentials—a significant increase from the 2.9% observed in H1 2025. While weak or absent credential entry fell from 47.1% in H1 to 27.2% in H2, software exploitation overtook credentials as the primary initial access vector for the first time.

出典を開く確認 2026-09-26

更新できるまで、入口の WAF(Web Application Firewall)で攻撃を止める
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Defensively, organizations should pivot from manual patching to automated defenses—such as patching the Web Application Firewall (WAF)—to neutralize exploits at the network edge before software updates can be applied.

出典を開く確認 2026-09-26

② 組織のポリシーで、あらゆる送信元(0.0.0.0/0)からの受信を禁じる
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Mitigate the risk of human error by deploying an Organization Policy that blocks overly permissive firewall rules and prohibits 0.0.0.0/0 ingress configurations.

出典を開く確認 2026-09-26

③ サービスアカウントの鍵を作らせない
Google Cloud(Resource Manager の文書・セキュリティのベースラインの制約・2026-09-24 更新)原文
このような組織のポリシーの例としては、サービス アカウント キーの作成の無効化やサービス アカウント キーのアップロードの無効化が挙げられます。

出典を開く確認 2026-09-26

CDN の後ろのサイト(Cloudflare など) オリジンサーバーの IP アドレスを直接狙い、CDN を回る攻撃。警察庁は令和 7 年(2025 年)の情勢の報告で、DDoS 攻撃(大量のアクセスでサービスを止める攻撃)の複数の事案で確認されたと書いている
警察庁サイバー警察局(令和 8 年 3 月・令和 7 年におけるサイバー空間をめぐる脅威の情勢等について)原文
IP アドレスを指定し、ウェブコンテンツのオリジナルデータが保存されているオリジンサーバを直接標的にすることで、アクセスの分散によって負荷軽減を実現している CDN (Contents Delivery Network)を回避する攻撃が複数の事案で確認された。

出典を開く確認 2026-09-26

Cloudflare 以外からの接続をオリジンサーバーで断る
Cloudflare(文書・Protect your origin server・2026-04-20 更新)原文
Explicitly block all traffic that does not come from Cloudflare IP addresses

出典を開く確認 2026-09-26

② Cloudflare を使い始めたら、オリジンサーバーの IP アドレスを変える(以前の IP アドレスは記録に残るため)
Cloudflare(文書・Protect your origin server・2026-04-20 更新)原文
rotate your origin IPs, as DNS records are in the public domain. Historical records are kept and would contain IP addresses prior to joining Cloudflare

出典を開く確認 2026-09-26

③ 全プランで使える無料の管理ルールを使う
Cloudflare(WAF の文書・Managed Rules・2026-09-08 更新)原文
Cloudflare Free Managed Ruleset: Available on all Cloudflare plans. Provides protection against high-impact and widely exploited vulnerabilities.

出典を開く確認 2026-09-26

リモートデスクトップ(RDP) ランサムウェアの侵入経路の 20.7%。2025 年の警察庁の調査を、IPA(情報処理推進機構)が表にまとめたもの
IPA(2026-03・情報セキュリティ 10 大脅威 2026 解説書[組織編]・表の出典は警察庁)原文
感染経路 2022年 2023年 2024年 2025年 ① VPN機器 61.8% 63.5% 55.0% 66.3% ② リモートデスクトップ 18.6% 18.3% 31.0% 20.7%

出典を開く確認 2026-09-26

インターネットに直接開けない
Microsoft(Microsoft Learn・PC への外からのアクセスを許可する・2025-06-26)原文
You're opening your PC up to the internet, which isn't recommended. If you must, make sure you have a strong password set for your PC. It's preferable to use a VPN.

出典を開く確認 2026-09-26

② 外から使うなら VPN を通す
Microsoft(Microsoft Learn・PC への外からのアクセスを許可する・2025-06-26)原文
You're opening your PC up to the internet, which isn't recommended. If you must, make sure you have a strong password set for your PC. It's preferable to use a VPN.

出典を開く確認 2026-09-26

③ 開けるなら、接続元の IP アドレスを限る
Microsoft(Microsoft Learn・PC への外からのアクセスを許可する・2025-06-26)原文
Most routers allow you to define which source IP or source network can use port mapping. So, if you know you're only going to connect from work, you can add the IP address for your work network - that lets you avoid opening the port to the entire public internet.

出典を開く確認 2026-09-26

VPN 機器 ランサムウェアの侵入経路の 6 割以上(令和 7 年・被害組織へのアンケート)。
警察庁サイバー警察局(令和 8 年 3 月・令和 7 年におけるサイバー空間をめぐる脅威の情勢等について)原文
被害組織へのアンケート結果によると、侵入経路は VPN(Virtual Private Network)機器が6割以上を占める状況である。

出典を開く確認 2026-09-26

修正プログラム(パッチ)を当てていない脆弱性、漏れた資格情報、簡単なパスワード、設定の不備が使われる
警察庁サイバー警察局(令和 8 年 3 月・令和 7 年におけるサイバー空間をめぐる脅威の情勢等について)原文
攻撃者は、未修正のぜい弱性、漏えいした認証情報や簡易なパスワード、設定不備等を悪用して組織のネットワークへ侵入する。

出典を開く確認 2026-09-26

Fortinet の案内では、勧める版に更新し、
Fortinet(2025-04-10・PSIRT ブログ・Analysis of Threat Actor Activity)原文
However, we recommend all customers to upgrade to one of these recommended versions regardless.

出典を開く確認 2026-09-26

管理画面をインターネット側から外す
Fortinet(2026-03-06・ブログ・Attacks at the Speed of AI)原文
(Best) Remove administrative access to your FortiGate from internet-facing interfaces and instead manage it via an internal or out-of-band method.

出典を開く確認 2026-09-26

② 影響を受けた機器は、設定をすべて侵害されたものとして扱う
Fortinet(2025-04-10・PSIRT ブログ・Analysis of Threat Actor Activity)原文
Treat all configuration as potentially compromised and follow the recommended steps below to recover

出典を開く確認 2026-09-26

③ 管理者と VPN 利用者の全員に多要素認証(MFA)を掛ける
Fortinet(2026-06-19・PSIRT ブログ・FortiGate の資格情報の侵害の報告の分析)原文
Implement MFA on all administrator and VPN user accounts

出典を開く確認 2026-09-26

Microsoft 365・Google Workspace 大手のクラウドと SaaS の事案の 83% で、初期の侵入に ID の問題が使われた(Google Cloud の報告・2025 年後半)
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Based on Mandiant Incident Response (IR) and Mandiant Threat Defense (MTD) engagements from H2 2025, our analysis found that threat actors exploited identity issues to gain initial access in 83% of the incidents involving major cloud and SaaS-hosted environments.

出典を開く確認 2026-09-26

追加の費用なしで使える Microsoft の「セキュリティの既定値群」で多要素認証を求める。
Microsoft(Microsoft Learn・Microsoft Entra ID のセキュリティの既定値群・2025-07-21)原文
Based on our learnings more than 99.9% of those common identity-related attacks are stopped by using multifactor authentication and blocking legacy authentication. Our goal is to ensure that all organizations have at least a basic level of security enabled at no extra cost.

出典を開く確認 2026-09-26

Google Workspace なら、管理者と主要な利用者に 2 段階認証プロセスを義務付ける
Google(Google Workspace 管理者ヘルプ・小規模企業向けのセキュリティのチェックリスト)原文
管理者と主要ユーザーには 2 段階認証プロセスを義務付けてください。

出典を開く確認 2026-09-26

② フィッシングに強い多要素認証にする
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Enforce phishing-resistant MFA using physical hardware keys or FIDO2-compliant passkeys.

出典を開く確認 2026-09-26

Microsoft(2025-10-16・Microsoft Digital Defense Report 2025 の紹介記事)原文
The implementation of phishing-resistant multifactor authentication (MFA) can stop over 99% of this type of attack even if the attacker has the correct username and password combination.

出典を開く確認 2026-09-26

③ アプリへの同意を、決めた条件のアプリだけに限る
Microsoft(Microsoft Learn・同意フィッシングから守る・2025-01-08 更新)原文
Configure user consent settings to allow users to only consent to applications that meet certain criteria.

出典を開く確認 2026-09-26

言葉の意味は 多要素認証(MFA)・VPN・リモートデスクトップ(RDP)・ランサムウェア・WAF・CDN とオリジンサーバー の各ページにあります。

決めること

決めること 手がかり
自社の入口の一覧 使っているクラウド・CDN・リモート接続・業務 SaaS と、それぞれの管理者を書き出す。表の 6 つに無い入口も足す
1 年を超えて有効なままのアクセスキー AWS の IAM ユーザーの 59% が、1 年を超えて有効なアクセスキーを持っていた(Datadog・2025 年 9 月のデータ)。
Datadog(State of Cloud Security・2025-10 更新・2025 年 9 月のデータ)原文
In AWS, 59% of IAM users have an active access key older than one year. Over half of these users have credentials that have been unused for over 90 days

出典を開く確認 2026-09-26

自社のアクセスキーの作成日を見る
漏れたアクセスキーの後始末 AWS が漏れたアクセスキーに自動で付ける検疫のポリシーは、キーを無効にしない。
Palo Alto Networks Unit 42(2026-09-21・漏れた AWS の IAM 資格情報を AWS がどう封じるか)原文
AWS purposefully denies specific actions rather than completely disabling the compromised access key or user password. However, this decision allows advanced threat actors to use the exposed credentials for any actions the policy does not explicitly deny.

出典を開く確認 2026-09-26

自分で無効にして入れ替える
更新の後の見直し 米国の CISA(サイバーセキュリティ・インフラセキュリティ庁)は Cisco の機器について、修正プログラムを当てても、入り込んだ攻撃者が消えるとは限らないとしている。
米 CISA(緊急指令 ED 25-03 V1・2025-09-25 発出・2026-04-23 更新・Cisco の機器)原文
CISA analysis determines that applying the Cisco-provided security updates required by the original issuance of ED 25-03 does not necessarily remove an existing threat actor from the compromised device.

出典を開く確認 2026-09-26

VPN 機器などは、更新の後に設定と利用者の一覧に覚えのない変更が無いかを見る
Fortinet(2026-06-19・PSIRT ブログ・FortiGate の資格情報の侵害の報告の分析)原文
Review firewall and VPN users and other configuration for unauthorized changes.

出典を開く確認 2026-09-26

関連するページ

知りたいこと ページ
中小企業のランサムウェア被害と守り方 中小企業はなぜランサムウェア被害の 6 割か
公表の前から悪用される脆弱性 ゼロデイ脆弱性とは
電話やメールで ID をだまし取る手口 フィッシング(Phishing)とは
使わない窓口を閉じる仕組み ファイアウォールとは
ウェブサイトの鍵を公開フォルダに置かない順番 鍵の置き場所と守りの順番

ここから先は調査の詳細です(約 7 分)。上のカードだけで決められます。調べた 1 件ずつの記録は IT連携マップ に、出典 URL と調査日つきで公開しています。

調査の詳細

調べたのは、6 つの入口についての提供元の文書と報告(AWS、Google Cloud、Microsoft、Cloudflare、Fortinet、Google Workspace)、第三者の調査(Palo Alto Networks Unit 42、Datadog、Verizon)、公的機関の資料(警察庁、IPA、JPCERT/CC(JPCERT コーディネーションセンター)、米国の CISA)です。すべて 2026 年 9 月 26 日に取り直し、引用が原文のまま在ることを確かめています。報告ごとに対象(誰の事案か)と期間が違うため、入口どうしの数字は比べられません。調べていないことは、各報告の数え方の検証と、日本の中小企業に限った割合です。

資料 公表・期間 使ったところ
Palo Alto Networks Unit 42 2026 年 9 月 21 日 AWS の初期侵入、漏れたキーの検疫
Datadog State of Cloud Security 2025 年 10 月(2025 年 9 月のデータ) 1 年を超えて有効なアクセスキー
AWS の文書(IAM、Security Hub、責任共有モデル) 2025 年 6 月 17 日ほか 勧められている手、ルートの多要素認証
Google Cloud Threat Horizons Report H1 2026 2026 年(2025 年後半の観測) Google Cloud と業務 SaaS の初期侵入
Google Cloud の文書 2026 年 9 月 24 日更新ほか ベースラインの制約、多要素認証の必須化
Cloudflare の文書 2026 年 4〜9 月更新 オリジンサーバーの守り、管理ルール、ボット対策
警察庁 2026 年 3 月(令和 7 年の情勢) CDN の回避、VPN 機器
IPA 情報セキュリティ 10 大脅威 2026 2026 年 3 月 感染経路の割合(2022〜2025 年)
Microsoft の文書と報告 2025 年 1 月〜2026 年 8 月更新 責任の分担、リモートデスクトップ、既定値群、同意フィッシング
Verizon DBIR(データ侵害調査報告書)2025 の中小企業向け版 2025 年(2023 年 11 月〜2024 年 10 月の事案) 境界の機器と VPN の修正
JPCERT/CC・米国の CISA・Fortinet 2025〜2026 年 VPN 機器の悪用と、更新の後に残るもの

AWS — 漏れたアクセスキーと「検疫」

Unit 42 は GitHub の公開リポジトリにアクセスキーを置く試験をし、AWS は 10 秒以内に検疫のポリシーをキーに付けたと書いています。

Palo Alto Networks Unit 42(2026-09-21・漏れた AWS の IAM 資格情報を AWS がどう封じるか)原文
During the test scenario, AWS attached the AWSCompromisedKeyQuarantineV3 managed policy within 10 seconds of the access key exposure.

出典を開く確認 2026-09-26

ただしこのポリシーは特定の操作を拒むだけで、キーやパスワードを無効にはしません。Unit 42 は、拒まれていない操作には漏れた資格情報が使えると書いています。
Palo Alto Networks Unit 42(2026-09-21・漏れた AWS の IAM 資格情報を AWS がどう封じるか)原文
AWS purposefully denies specific actions rather than completely disabling the compromised access key or user password. However, this decision allows advanced threat actors to use the exposed credentials for any actions the policy does not explicitly deny.

出典を開く確認 2026-09-26

通知が来たら、キーを自分で無効にして入れ替えます。

Datadog の 2025 年版の調査では、AWS の IAM ユーザーの 59% が 1 年を超えて有効なアクセスキーを持ち、その半分超は 90 日以上使われていませんでした。

Datadog(State of Cloud Security・2025-10 更新・2025 年 9 月のデータ)原文
In AWS, 59% of IAM users have an active access key older than one year. Over half of these users have credentials that have been unused for over 90 days

出典を開く確認 2026-09-26

数字は 2025 年 9 月に集めたデータです。
Datadog(State of Cloud Security・2025-10 更新・2025 年 9 月のデータ)原文
Findings are based on data collected in September 2025.

出典を開く確認 2026-09-26

ルートユーザーの多要素認証は、AWS が 2025 年 6 月にすべての種類のアカウントで必須にしています。
AWS(2025-06-17・ルートユーザーの多要素認証をすべての種類のアカウントで必須に)原文
本日、AWS Identity and Access Management (IAM) は、すべてのアカウントタイプのルートユーザーを対象として、包括的な多要素認証 (MFA) 要件を発表し、メンバーアカウントにも拡張しました。

出典を開く確認 2026-09-26

残るのは、IAM ユーザーに発行した長期のアクセスキーの側です。キーが漏れる道は API キーは実際どう漏れるのか にまとめてあります。

Google Cloud — ソフトの悪用が、資格情報を上回った

Google Cloud の 2026 年の報告では、設定の誤りによる初期侵入は 2025 年前半の 29.4% から後半の 21% に下がりました。

Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
initial access by threat actors using misconfiguration, which accounted for 29.4% of incidents in the first half of 2025, dropped to 21% in H2 2025.

出典を開く確認 2026-09-26

脆弱性の公表から約 48 時間で、暗号資産の採掘プログラム(XMRig)を置かれた事案も複数あったとしています。
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
we observed multiple incidents of threat actors deploying XMRig cryptocurrency miners within approximately 48 hours of CVE-2025-55182’s public disclosure.

出典を開く確認 2026-09-26

Google Cloud は、この変化を、既定で安全にする方針と資格情報の保護が、たやすい経路を閉じた結果の可能性があると見ています。
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
We assess that this change in behavior from threat actors is potentially due to Google's secure-by-default strategy and enhanced credential protections successfully closing traditional, more easily exploitable paths

出典を開く確認 2026-09-26

数字は観測した事案の一部で、すべての利用者を表すものではないと断っています。
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Note: Data reflects a subset of observed activity and may not represent all customers.

出典を開く確認 2026-09-26

サービスアカウントの鍵を作らせない制約は、2024 年 5 月 3 日以降に作られた組織では最初から有効です。

Google Cloud(Resource Manager の文書・セキュリティのベースラインの制約・2026-09-24 更新)原文
2024 年 5 月 3 日以降に作成されたすべての組織には、Google Cloud セキュリティ ベースラインの制約が適用されます。

出典を開く確認 2026-09-26

それより前に作った組織は、自分で確かめます。漏れたサービスアカウントの鍵について、Google Cloud は見つけると自動で無効にすると書いています。
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
If Google Cloud detects an exposed service account key, it will automatically disable the key.

出典を開く確認 2026-09-26

無効にしない AWS の検疫とは、扱いが違います。Google Cloud は多要素認証を全利用者に段階的に義務付けていますが、
Google Cloud(2 段階認証の必須化の文書・2026-09-24 更新)原文
Google はすべての Google Cloud のお客様にアカウントで多要素認証(MFA)を有効にするよう段階的に義務付けています。

出典を開く確認 2026-09-26

対象は管理の操作(コントロールプレーン)で、動いているアプリやデータの側は対象外だと書いています。
Google Cloud(2 段階認証の必須化の文書・2026-09-24 更新)原文
つまり、コントロール プレーンは MFA の適用の影響を受けますが、データプレーンは影響を受けません。

出典を開く確認 2026-09-26

CDN の後ろのサイト(Cloudflare など)

CDN を回る攻撃と、オリジンサーバーの IP アドレスが知られる道は CDN とオリジンサーバーとは に、管理ルールで止められるものと止められないものは WAF とは にまとめてあります。ボット 対策の設定(Bot Fight Mode)について、Cloudflare は API やスマートフォンのアプリの通信にも確認の画面(チャレンジ)を出すことがあると書いています。

Cloudflare(ボット対策の文書・Bot Fight Mode・2026-08-03 更新)原文
Although these products are designed to fight malicious actors on the Internet, they may challenge API or mobile app traffic.

出典を開く確認 2026-09-26

入れるかどうかの判断は 「自動トラフィック急増」の警告の読み方 にあります。

リモートデスクトップ

IPA は警察庁の統計から、ランサムウェアの感染経路は VPN 機器経由が過半数で、リモートデスクトップ経由と合わせると 8 割を超えると書いています。

IPA(2026-03・情報セキュリティ 10 大脅威 2026 解説書[組織編]・表の出典は警察庁)原文
VPN 機器を経由したものが過半数を占めている。また、リモートデスクトップを経由した感染との合計値では 8 割を超えている。

出典を開く確認 2026-09-26

リモートデスクトップの割合は 2022 年 18.6%、2023 年 18.3%、2024 年 31.0%、2025 年 20.7% です。
IPA(2026-03・情報セキュリティ 10 大脅威 2026 解説書[組織編]・表の出典は警察庁)原文
感染経路 2022年 2023年 2024年 2025年 ① VPN機器 61.8% 63.5% 55.0% 66.3% ② リモートデスクトップ 18.6% 18.3% 31.0% 20.7%

出典を開く確認 2026-09-26

年 VPN 機器 リモートデスクトップ
2022 年 61.8% 18.6%
2023 年 63.5% 18.3%
2024 年 55.0% 31.0%
2025 年 66.3% 20.7%

VPN 機器

Verizon の 2025 年の報告(2023 年 11 月〜2024 年 10 月の事案)では、脆弱性を突く攻撃の標的のうち、境界の機器と VPN が 22% でした。

Verizon(2025・DBIR 2025 中小企業向けスナップショット・対象は 2023 年 11 月〜2024 年 10 月の事案)原文
The percentage of edge devices and VPNs as a target on our exploitation of vulnerabilities action was 22%

出典を開く確認 2026-09-26

その脆弱性が 1 年のうちに完全に直されたのは約 54% で、直すまでにかかった日数の中央値は 32 日でした。
Verizon(2025・DBIR 2025 中小企業向けスナップショット・対象は 2023 年 11 月〜2024 年 10 月の事案)原文
Organizations worked very hard to patch those edge device vulnerabilities, but our analysis showed only about 54% of those were fully remediated throughout the year, and it took a median of 32 days to accomplish.

出典を開く確認 2026-09-26

修正プログラムが出る前から悪用される例もあります。JPCERT/CC は、Ivanti Connect Secure などの脆弱性(CVE-2025-0282)が公表される前の 2024 年 12 月下旬から、国内で複数の被害を確認しています

JPCERT/CC(2025-01-09 公開・2025-02-13 更新・Ivanti Connect Secure などの脆弱性 CVE-2025-0282 の注意喚起)原文
JPCERT/CCでは、本脆弱性公開前の2024年12月下旬から本脆弱性が悪用された被害を国内で複数確認しています。

出典を開く確認 2026-09-26

(ゼロデイ脆弱性とは)。

修正プログラムを当てても、それで終わりとは限りません。Fortinet は 2025 年 4 月、脆弱性を直す版に更新した後も、攻撃者が置いたリンクが残っている場合があり、設定を含むファイルを読める状態が続きうると書いています。

Fortinet(2025-04-10・PSIRT ブログ・Analysis of Threat Actor Activity)原文
Therefore, even if the customer device was updated with FortiOS versions that addressed the original vulnerabilities, this symbolic link may have been left behind, allowing the threat actor to maintain read-only access to files on the device’s file system, which may include configurations.

出典を開く確認 2026-09-26

パスワードの側の攻撃も続いています。Fortinet は 2026 年 3 月、報告された攻撃は脆弱性ではなく、外に開いた管理用の窓口と、多要素認証の無い弱い資格情報を突いて成功したとし、

Fortinet(2026-03-06・ブログ・Attacks at the Speed of AI)原文
During our investigation, we observed no exploitation of FortiGate vulnerabilities. Instead, this campaign succeeded by exploiting exposed management ports and weak credentials with single-factor authentication.

出典を開く確認 2026-09-26

多要素認証があれば成り立たなかったと書いています。
Fortinet(2026-03-06・ブログ・Attacks at the Speed of AI)原文
Enable multifactor authentication (MFA): The reported cyberattack would have been impossible with MFA in place.

出典を開く確認 2026-09-26

2026 年 6 月には、過去の事案で漏れた資格情報の使い回しと、
Fortinet(2026-06-19・PSIRT ブログ・FortiGate の資格情報の侵害の報告の分析)原文
we believe the activity involves threat actors reusing credentials from previous incidents

出典を開く確認 2026-09-26

弱いパスワードで多要素認証の無い機器への総当たりを挙げています。
Fortinet(2026-06-19・PSIRT ブログ・FortiGate の資格情報の侵害の報告の分析)原文
employing brute-force techniques (as described in a March blog, “ Attacks at the Speed of AI ”) against devices with weak password hygiene and no multi-factor authentication (MFA).

出典を開く確認 2026-09-26

Microsoft 365・Google Workspace

Google Cloud の同じ報告は、2025 年後半の大手のクラウドと SaaS の事案について、17% が電話でだます手口(ビッシング)、

Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Phishing : 17% of cases involved voice-based social engineering (vishing).

出典を開く確認 2026-09-26

12% がメールのフィッシングで、多要素認証の通知を大量に送って承認させる攻撃も含むとしています。
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Email phishing accounted for 12% of cases, which included activity by the financially motivated group UNC6345 using employee rewards-themed lures to harvest credentials and execute MFA fatigue attacks.

出典を開く確認 2026-09-26

Microsoft は、2024 年 7 月から 2025 年 6 月の動きをまとめた報告で、
Microsoft(2025-10-16・Microsoft Digital Defense Report 2025 の紹介記事)原文
Microsoft Digital Defense Report , which covers trends from July 2024 through June 2025

出典を開く確認 2026-09-26

ID への攻撃の 97% 超はパスワードへの攻撃だとしています。
Microsoft(2025-10-16・Microsoft Digital Defense Report 2025 の紹介記事)原文
more than 97% of identity attacks are password attacks.

出典を開く確認 2026-09-26

手口(報告) 勧められている手
パスワードを大量に試す攻撃(Microsoft) 多要素認証を求める。Google Workspace のチェックリストは、管理者と主要な利用者には 2 段階認証プロセスを義務付けるよう勧める
Google(Google Workspace 管理者ヘルプ・小規模企業向けのセキュリティのチェックリスト)原文
管理者と主要ユーザーには 2 段階認証プロセスを義務付けてください。

出典を開く確認 2026-09-26

多要素認証の通知の連打(Google Cloud) 物理的な鍵やパスキーによる、フィッシングに強い方式にする
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Enforce phishing-resistant MFA using physical hardware keys or FIDO2-compliant passkeys.

出典を開く確認 2026-09-26

社員になりすましてヘルプデスクに電話し、パスワードと多要素認証を再設定させる
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
UNC3944 impersonating employees to trick IT help desk staff into resetting credentials and multi-factor authentication (MFA).

出典を開く確認 2026-09-26

ヘルプデスクの本人確認を厳しくする(ビデオ通話で顔を見る、上長の承認を取る)
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Establish strict verification protocols for IT help desk staff, such as requiring visual verification using video call or secondary manager approval.

出典を開く確認 2026-09-26

連携した他社のアプリの OAuth トークンを盗み、Salesforce から大量のデータを持ち出す
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
UNC6395 leveraged compromised OAuth tokens associated with the Salesloft Drift application to conduct extensive discovery and bulk exfiltration of sensitive data from Salesforce tenants.

出典を開く確認 2026-09-26

外部のアプリに与えた範囲を点検して絞る
Google Cloud(Cloud Threat Horizons Report H1 2026・2025 年後半の観測)原文
Strictly govern OAuth and third-party application access by auditing and restricting the scopes granted to external integrations.

出典を開く確認 2026-09-26

アプリへの同意を使う攻撃は、パスワードを盗まずに、悪意のあるクラウドのアプリに権限を与えさせるものです。

Microsoft(Microsoft Learn・同意フィッシングから守る・2025-01-08 更新)原文
Consent phishing attacks trick users into granting permissions to malicious cloud applications. These malicious applications can then gain access to legitimate cloud services and data of users. Unlike credential compromise, threat actors who perform consent phishing target users who can grant access to their personal or organizational data directly.

出典を開く確認 2026-09-26

つながっているアプリと、その許可の範囲の考え方は OAuth とは何か にまとめてあります。

セキュリティの既定値群は、2019 年 10 月 22 日以降に作ったテナント(組織の契約の単位)では有効になっている場合があります。

Microsoft(Microsoft Learn・Microsoft Entra ID のセキュリティの既定値群・2025-07-21)原文
If your tenant was created on or after October 22, 2019, security defaults might be enabled in your tenant.

出典を開く確認 2026-09-26

それより前からのテナントは、管理画面で有効かどうかを確かめます。Google Workspace のチェックリストは、特権管理者のアカウントを、別々の人が管理する 2 つ以上にするよう勧めています。
Google(Google Workspace 管理者ヘルプ・小規模企業向けのセキュリティのチェックリスト)原文
ビジネスでは複数の特権管理者アカウントを用意して、それぞれを別のユーザーが管理することをおすすめします。

出典を開く確認 2026-09-26

この記事に登場するシステム(1)

Google Workspace

← 調査記事の一覧へ 比較する

編集部はベンダーからの掲載料・送客料・成果報酬を一切受け取りません。判定は編集部の調査記録にある一次資料から、機械で組み立てています。 相談内容はその場で回答に使うだけで、保存しません。
一覧: システム一覧 連携ツール(連携サービス)一覧 AI・自動化ツール一覧 稼働状況・障害情報
記載の誤り・掲載についてのご連絡 → 訂正・掲載のご依頼(無料・無条件・全社同一) 運営者情報