Japan's Ground Self-Defense Force used USB drives infected with a China-linked virus on classified computers for nearly a year without disclosure. Similar infected drives have spread across online retailers, affecting factories and research facilities.

The breach highlights significant cybersecurity vulnerabilities within Japan's defense infrastructure and the widespread nature of sophisticated cyber threats originating from China, impacting both government and private sector entities.
Japan's Ground Self-Defense Force utilized USB drives containing a virus believed to be linked to Chinese hackers on computers that held classified information for nearly a year. This occurred without disclosure, according to a Nikkei investigation. Similar infected memory sticks have since been found to have spread across online retailers, infecting computers at factories and research facilities in various industries.
A separate investigation by Japan's National Police Agency linked over 200 cyberattacks between 2019 and 2024 to a Chinese hacking group known as MirrorFace. These systematic attacks aimed to steal data related to Japan's national security and advanced technology, targeting entities including the Foreign and Defense ministries, the country's space agency, and individuals and organizations involved in advanced technology.
Experts have expressed ongoing concerns about Japan's cybersecurity vulnerabilities, particularly as the nation enhances its defense capabilities and collaborates more closely with international partners like the United States. In response, Japan has begun sharing intelligence on cyber threats, including malware used by China, North Korea, and Russia, with NATO member countries to bolster cyber defenses.