ENVALITH
LINEヤフー株式会社 logo

LY Corporation

4689Prime MarketInformation & Communication

LINEヤフー株式会社 logo
LY Corporation4689
Technology

Generative AI Business Strategy Risk

If the establishment of new user touchpoints in response to rapid changes in user behavior accompanying the spread of generative AI, and the establishment of new monetization models such as agentic advertising and AI feature billing, do not proceed as planned, it may become difficult to achieve future revenue and profit targets. In addition, if the increase in AI costs (inference, training, operations, etc.) accompanying the expanded use of LLMs is not appropriately managed, there is a risk of deteriorating profit margins and reduced future investment capacity. As countermeasures, the company is promoting improvements in the profitability of existing advertising through data utilization, ongoing optimization of contract terms with model provider vendors, and a hybrid strategy combining technology development and collaboration with external partners.

Technology

Information Security / Cyberattack Risk

If information leakage, data destruction, or service outages occur due to human error in operations, malware infection, targeted cyberattacks, system vulnerabilities, or other causes, it may impact business performance and damage the company's credibility. Recurrence prevention measures (system/network segregation, introduction of multi-factor authentication, enhanced management of outsourcing partners, etc.) implemented in response to the unauthorized access incident in November 2023 completed implementation of the main measures by the end of March 2026 and transitioned to a steady-state operation phase; however, in October 2025 a system failure caused by a ransomware attack occurred at consolidated subsidiary Askul Corporation, and in February 2026 an unauthorized access incident occurred at a consolidated subsidiary of BEENOS Inc. While continuing the monitoring framework by the Security Governance Committee, the company is prioritizing verification of data preservation and recovery procedures in collaboration across the group as a countermeasure against ransomware.

Regulation

Domestic and International Regulatory Tightening Risk

While legal frameworks requiring user information provision/preservation obligations and the establishment of legal representatives are being developed in Europe and various Asian countries, domestic trends continue toward reviewing amendments to the Act on the Protection of Personal Information, the Consumer Contract Act, and the Act on Specified Commercial Transactions, as well as strengthening regulations on youth protection and SNS usage, requiring the company to establish systems and change operations for its services. If the response is insufficient, corporate value may decline due to sanctions based on domestic and international laws, reputational decline, and user attrition and increased response costs resulting from service changes. The company is advancing monitoring of overseas regulations, building operational frameworks and systems for legal compliance, and engaging in appropriate regulatory formation through proposals to government review committees, among other measures.

Regulation

Economic Security / Geopolitical Risk

The company was designated as a Specified Critical Infrastructure Business Operator in November 2023 under the Economic Security Promotion Act, and is required to respond to obligations such as prior review and reporting regarding the introduction and modification of critical facilities. If heightened geopolitical tensions—such as worsening conditions in the Middle East, the prolonged Russia-Ukraine conflict, and risks of a Taiwan contingency—lead to strengthened export controls, investment regulations, and cross-border data transfer regulations, as well as constraints on procurement of cloud infrastructure and critical components, or supply chain disruptions, this could have a material impact on business continuity, performance, and credibility. The company conducts risk management centered on the Economic Security Office, monitoring domestic and international political and economic trends and drawing on expert advice.

Regulation

Active Cyber Defense Act Compliance Risk

Under the Act on Enhancement of Cyber Response Capabilities (Active Cyber Defense Act) enacted in May 2025, the company, as a Specified Critical Infrastructure Business Operator, is expected to be subject to obligations such as registering specified electronic computer assets and reporting cyber incidents; failure to establish an appropriate management framework could result in administrative measures. Increased response costs and information management burdens are also anticipated, which could affect business operations and performance. The company is proceeding with its response to this legislation, but additional responses may be required as the details of the regulatory requirements are finalized.

Technology

Talent Acquisition / Business Strategy Alignment Risk

Due to changes in the recruitment environment, increased workforce mobility, and rapid technological evolution including generative AI, if staffing plans and personnel allocation in each business domain fail to be realized as planned, the company may be unable to appropriately secure and retain the personnel necessary to execute its business strategy, potentially resulting in a divergence between business strategy and human resources. If such divergence continues, it could cause delays in executing business strategy, failure to achieve expected results, and a decline in operational efficiency and competitiveness, thereby affecting performance and financial condition. The Human Resources and General Affairs department, centrally, conducts ongoing cross-group monitoring of the alignment between business strategy and personnel in each business domain, as well as the status of staffing plan realization.

Financial

Group Company Security Risk

While the company supports information security at group companies, and despite measure-sharing and implementation support under the Group CISO Board framework, the risk of cyber incidents occurring at group companies has materialized, as demonstrated by the ransomware attack at Askul Corporation in October 2025 and the unauthorized access incident at a consolidated subsidiary of BEENOS Inc. in February 2026. Incidents at group companies could damage the credibility of the entire group and affect performance; the company is prioritizing verification of data preservation and recovery procedures in collaboration across the group, anticipating system outages caused by ransomware and other attacks.

Technology

AI Governance Risk

If governance deficiencies arise in the utilization of AI, this could undermine trust from users and society, and this has been positioned as an important business strategy risk in a newly established risk category starting this fiscal year. With the rapid spread of generative AI, social demands for ethics, safety, and transparency in AI usage are increasing, making the establishment of an appropriate governance framework essential. The company is addressing this through a hybrid strategy of technology development and collaboration with external partners, as well as strengthening its governance framework, but additional responses may be required due to changes in the regulatory environment and evolving social expectations.

Technology

Data Governance Risk

This risk relates to the management and utilization of the large volume of user data held by the company group; if inappropriate management or use of data occurs, it could lead to violations of laws such as the Act on the Protection of Personal Information, loss of user trust, and sanctions from regulatory authorities. Amid a trend of strengthening data protection regulations both domestically and internationally, the ongoing maintenance and strengthening of an appropriate data governance framework is continuously required. The company has positioned data governance risk as one of its risk categories and is advancing the establishment of a management framework.

Financial

Supply Chain Governance Risk

If inappropriate selection of outsourcing partners or insufficient management of outsourced operations and personnel occurs, there is a risk of suffering effects such as information leakage or legal violations; in the November 2023 unauthorized access incident, a breach via an outsourcing partner was also identified as an issue. While enhanced management of outsourcing partners was implemented as a recurrence prevention measure, with implementation of the main measures completed by the end of March 2026, new cyberattacks or management deficiencies occurring through outsourcing partners could affect performance and credibility. The company has established supply chain governance risk as a risk category and is working on the continuous strengthening of its outsourcing partner management framework.

Importance and likelihood are shown based on the company's disclosures.

Last updated: July 19, 2026