Regarding Vulnerability Report on Some Models of FeliCa IC Chips Shipped Before 2017

August 28, 2025
Updated on July 21, 2026
Sony Corporation

We have confirmed that some models of IC chips of Sony's contactless IC card technology "FeliCa", which were shipped prior to 2017, could potentially have data read and tampered through specific operations that were identified in an external report. The report was shared by the Information-technology Promotion Agency, Japan (IPA) in accordance with "Information Security Early Warning Partnership Guideline".

The security of services utilizing FeliCa is built not only on the security of the FeliCa IC chips themselves but also on the overall system for each service. Regarding this matter, we have been cooperating with some service providers and public institutions within the framework of the aforementioned partnership. All stakeholders are encouraged to continue using the services without concern, based on information from relevant providers.

<Updated on July 21, 2026>
Information on countermeasures has been published on the vulnerability countermeasure information portal site "JVN (Japan Vulnerability Notes)", in accordance with the aforementioned partnership guideline.

See the information published by JVN below:
JVN#40509781 Vulnerability in certain IC chips of contactless IC card "FeliCa"

Since receiving the external report under the above partnership guideline, we have issued countermeasure guidelines to relevant service providers using FeliCa IC chips and have been conducting risk assessments and implementing measures to enhance security. We will continue to promote these measures together with relevant service providers.

Contact Information