Key facts
- Japan's Ministry of Defense will implement a zero-trust cybersecurity model by 2027.
- The initiative aims to continuously monitor for both external and internal cyber threats.
- A malware incident involving compromised USB drives affected over 50 computers in the Ground Self-Defense Force.
- The compromised drives were counterfeit and linked to a China-linked hacker group.
- Despite safeguards, the malware infected computers handling classified data, though the ministry claims no data exfiltration occurred.
Japan's Ministry of Defense is set to implement a zero-trust cybersecurity framework by 2027, a move prompted by a significant malware incident involving compromised USB drives within the Ground Self-Defense Force. This new approach aims to enhance the continuous monitoring of both external and internal cyber threats, addressing growing concerns that Japan's cyber defenses could become a vulnerability in information sharing with allies like the U.S.
The incident, reported by Nikkei, involved counterfeit USB drives, linked to a China-affiliated hacker group, that were distributed during disaster relief operations in March 2024. Despite multiple safeguards, including requirements for scanning external drives, the malware was not discovered until February 2025 when a soldier reported a slow-operating computer. A scan revealed a virus carried on a compromised flash drive.
An internal investigation found the same malware on six of the eight USB drives examined. More than 50 computers were connected to these infected drives, with nearly half handling classified data, such as unit movements. The Defense Ministry, however, stated that the malware was a legacy type limited to self-replication and did not exfiltrate information or perform external communication, asserting it had no impact on army systems or spread beyond the connected computers.
The ministry is investigating the circumstances of the drive acquisition and plans to enforce mandatory virus scanning safeguards to prevent recurrence. The incident highlights the persistent threat of sophisticated cyberattacks, including the embedding of malware in IT systems by state-linked actors, a practice U.S. intelligence agencies have warned about.
