HomeAll NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Japan Defense Ministry to adopt 'zero trust' after USB malware attack

Created at 23 Jul · 4:26 PM1 source↑ Market-relevant
IN SHORT

Japan's Ministry of Defense will implement a zero-trust cybersecurity approach by 2027 following a malware incident involving compromised USB drives. The move aims to enhance monitoring of both external and internal threats, addressing concerns about the nation's cyber defenses.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

2027year for zero-trust adoption
50+computers infected by malware
8USB drives inspected
6infected USB drives found
March 2024delivery of infected USB drives
February 2025discovery of malware infection

Who's Involved

Japan's Ministry of Defense
plans to adopt zero-trust cybersecurity by 2027
Japan's Ground Self-Defense Force
affected by malware from compromised USB drives
China-linked hacker group
linked to the counterfeit USB drives
Japan Defense Ministry to adopt 'zero trust' after USB malware attack

↳ Why This Matters

The adoption of a zero-trust model by Japan's Defense Ministry signifies a critical shift in national cybersecurity strategy, aiming to bolster defenses against increasingly sophisticated state-sponsored cyber threats and protect sensitive military information.

Key facts

  • Japan's Ministry of Defense will implement a zero-trust cybersecurity model by 2027.
  • The initiative aims to continuously monitor for both external and internal cyber threats.
  • A malware incident involving compromised USB drives affected over 50 computers in the Ground Self-Defense Force.
  • The compromised drives were counterfeit and linked to a China-linked hacker group.
  • Despite safeguards, the malware infected computers handling classified data, though the ministry claims no data exfiltration occurred.

Japan's Ministry of Defense is set to implement a zero-trust cybersecurity framework by 2027, a move prompted by a significant malware incident involving compromised USB drives within the Ground Self-Defense Force. This new approach aims to enhance the continuous monitoring of both external and internal cyber threats, addressing growing concerns that Japan's cyber defenses could become a vulnerability in information sharing with allies like the U.S.

The incident, reported by Nikkei, involved counterfeit USB drives, linked to a China-affiliated hacker group, that were distributed during disaster relief operations in March 2024. Despite multiple safeguards, including requirements for scanning external drives, the malware was not discovered until February 2025 when a soldier reported a slow-operating computer. A scan revealed a virus carried on a compromised flash drive.

An internal investigation found the same malware on six of the eight USB drives examined. More than 50 computers were connected to these infected drives, with nearly half handling classified data, such as unit movements. The Defense Ministry, however, stated that the malware was a legacy type limited to self-replication and did not exfiltrate information or perform external communication, asserting it had no impact on army systems or spread beyond the connected computers.

The ministry is investigating the circumstances of the drive acquisition and plans to enforce mandatory virus scanning safeguards to prevent recurrence. The incident highlights the persistent threat of sophisticated cyberattacks, including the embedding of malware in IT systems by state-linked actors, a practice U.S. intelligence agencies have warned about.

Frequently asked questions

A zero-trust security model assumes that threats can exist both outside and inside the network perimeter, requiring strict identity verification for every person and device trying to access resources on a private network, regardless of their location.

The malware was spread via counterfeit USB drives, linked to a China-linked hacker group, which were distributed to the Ground Self-Defense Force. These drives infected computers when inserted, despite existing safeguards.

Over 50 computers were connected to the infected drives, some handling classified data. However, the Defense Ministry stated the malware was limited in scope and did not exfiltrate data or compromise army systems.

The ministry plans to introduce the zero-trust approach as early as 2027.

What Happens Next

01The Ministry of Defense will introduce the zero-trust approach as early as 2027.
02Mandatory virus scanning safeguards will be enforced to prevent future occurrences.
03Investigations into the acquisition of the compromised USB drives will continue.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence
CME Headlines
  • Is AI Making Inflation Better or Worse?
    22 Jul · 3:26 PM

How It Developed

Japan's Ministry of Defense plans to adopt a zero-trust cybersecurity approach by 2027.
The decision follows a malware incident involving compromised USB drives within the Ground Self-Defense Force.
The malware was detected on six of eight USB drives, infecting over 50 computers, some handling classified data.
The Defense Ministry stated the malware had no impact on army systems and did not exfiltrate data.
Safeguards were in place but failed to prevent the infection, which occurred despite multiple security measures.
The compromised USB drives were counterfeit and linked to a China-linked hacker group.
The incident raises concerns about Japan's cyber defenses and potential vulnerabilities in information sharing with allies.
The ministry is investigating the acquisition of the drives and will enforce mandatory virus scanning.
Sponsored

London Quick Take - 22 July - UK inflation softens, oil rises and chips rally ahead of Alphabet, Tesla earnings

SAXO

Sources

T1
Japan Defense Ministry to adopt 'zero trust' after infected USB attackNikkei Asia
T2
Nikkei Warns of Japan's Ground Self-Defense Force Used USB Drives ...cybersecuritynews.com
T2
Fake USB Sticks Spread China-Linked Virus in Japan's Armynewsweek.com

Related Stories

Anduril eyes Japanese tech for global drone expansion
22 Jul · 10:06 PM
Japan rocket for small satellites completes burn test ahead of launch
23 Jul · 5:50 PM
US eyes ban on Chinese humanoid robots amid tech rivalry
23 Jul · 11:36 AM
Hacked firm calls AI model breach 'wake-up call'
23 Jul · 5:21 AM
Nvidia donates advanced AI supercomputer to U.S. military university
22 Jul · 11:06 PM