Key Facts
• August 28, 2025: Sony announced a security vulnerability in FeliCa technology.
• Affects FeliCa IC chips shipped before 2017, used in transit cards and e-money.
• Vulnerability could allow third parties to read or alter data.
• No confirmed cases of exploitation or damage reported so far.
• FeliCa is used in East Japan Railway’s Suica cards and corporate access cards.
• Sony is collaborating with relevant organizations to address the issue.
Summary
Sony has identified a security flaw in its FeliCa contactless IC technology, widely used in transit cards like Suica and corporate access systems. The issue affects chips produced before 2017, potentially allowing unauthorized data access or tampering. While no incidents have been reported, Sony is working with stakeholders to mitigate risks. This highlights the importance of robust encryption in widely adopted technologies.
