TL;DR

Japan’s Self-Defense Forces used USB drives infected with a virus linked to Chinese hackers for almost a year. The military did not disclose the incident, raising cybersecurity concerns.

Japan’s Ground Self-Defense Force used USB drives infected with a virus linked to Chinese hackers on computers with access to classified information for nearly a year, and did not disclose the incident despite the availability of similar infected drives online, according to a Nikkei investigation.

The investigation found that the Ground Self-Defense Force employed USB drives containing malicious software believed to be connected to Chinese cyber espionage activities. These drives were used on computers with access to sensitive information, raising concerns about cybersecurity vulnerabilities within Japan’s defense infrastructure.

Officials reportedly chose not to disclose the incident for almost a year, even as similar infected USB drives were accessible on the open market and online. The decision not to reveal the breach has sparked questions about transparency and cybersecurity protocols within Japan’s military.

Implications for Japan’s Military Cybersecurity

This incident highlights potential weaknesses in Japan’s cybersecurity defenses, especially within its defense forces. The use of infected USB drives could have exposed sensitive information to foreign cyber actors, increasing the risk of espionage or cyber attacks. The lack of disclosure also raises concerns about transparency and the management of cybersecurity threats in Japan’s national security framework.

USB data recovery tools

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Cybersecurity in Japan’s Defense Sector

Japan has been increasingly aware of cybersecurity threats linked to China and other state actors. Prior incidents have involved cyber espionage and hacking attempts targeting government and military networks. The use of infected removable media has been a known vulnerability, but this is among the first reports of such a long-term breach involving the Self-Defense Forces.

“The use of infected USB drives within a military context is a significant breach of cybersecurity protocols.”

— an anonymous cybersecurity expert

Unclear Details About the Infection and Disclosures

It is not yet confirmed how the virus was introduced into the USB drives or whether any classified information was compromised. The full extent of the breach and the specific Chinese hacking group involved remain unclear. The Defense Ministry has not issued a detailed explanation or apology, and investigations are ongoing.

Next Steps in Japan’s Cybersecurity Review

Authorities are expected to conduct a comprehensive review of cybersecurity protocols within the Self-Defense Forces and other government agencies. Public disclosures may increase, and measures to prevent similar incidents are likely to be implemented. Further investigations are anticipated to clarify the scope and impact of the breach.

Key Questions

How did the USB drives become infected?

The exact method of infection has not been confirmed. It is believed that the drives may have been deliberately compromised or infected through malicious software available online.

Was any classified information leaked or stolen?

It is not yet clear whether sensitive information was accessed or exfiltrated during the incident. Investigations are ongoing to determine the full impact.

Has the Japanese government responded publicly?

The government has not issued a detailed public statement regarding the incident. The Defense Ministry is reportedly reviewing cybersecurity procedures.

Could this incident affect Japan’s international relations?

Potentially, especially if foreign intelligence agencies or state actors are implicated. Diplomatic implications could arise if classified information was compromised.

Source: Nikkei Asia


You May Also Like

Why DMARC’s New “NP” Tag Can Fail With DNSSEC

New DMARC ‘NP’ tag can cause email authentication failures when DNSSEC is enabled, potentially impacting email security and deliverability.

Court approves $46.75 million payout for 23andMe data breach victims

A court has approved a $46.75 million payout for victims of the 23andMe data breach, affecting thousands of users and raising privacy concerns.

Europe Regulated the Interface and Forgot to Build the Engine

Europe has regulated the interface of AI but has not developed the underlying technology, leaving it behind in global AI competitiveness and innovation.

Private AI prompt workspace for sensitive teams

A new local-first AI prompt workspace designed for small, regulated teams handling sensitive data is entering testing, aiming to improve data control and compliance.