The new frontier of Japan’s rearmament is cyberspace
Tokyo is expanding its defense strategy against cyber threats from China, Russia and North Korea
Cyberspace will become a new area of responsibility for Japan’s military and police from October, when a law allowing them to neutralize large-scale cyberattacks at their source comes into force. The measure is aimed at threats from state actors such as China, Russia and North Korea, the countries most active against Japanese networks in recent years. The Cyber Defense Law is part of Japan’s accelerated military buildup, a process that has gained further momentum under Prime Minister Sanae Takaichi, a leading figure on the hardline wing of Japanese conservatism who took office last October.
“The new law authorizes the state to launch cyber counterattacks and neutralize the computers from which cyberattacks against critical infrastructure or government systems originate,” explains Jun Osawa, a senior fellow at the Sasakawa Peace Foundation (SPF). “There does not need to be a declared war,” he adds from his Tokyo office, located just five minutes from the government district, where he advises several public agencies on cybersecurity.
Japan refers to its armed forces as the Self-Defense Forces, a military of around 220,000 personnel that, in principle, can respond only after coming under a conventional attack, never beforehand. The country’s pacifist Constitution states in Article 9 that “the Japanese people forever renounce war as a sovereign right of the nation” and that “land, sea and air forces, as well as other war potential, will never be maintained.”
“However,” Osawa continues, “the cyber domain is full of attacks that fall short of the threshold of war, and if no action is taken against them, the country’s infrastructure is left unprotected.”
Osawa points to Russia’s February 2022 invasion of Ukraine as a turning point, noting that cyberattacks preceded the first missile strikes. “It became clear there that cyberattacks, disinformation campaigns, what in Europe is known as Foreign Information Manipulation and Interference [FIMI], start long before a war actually breaks out,” Osawa explains.
In mid-2022, the Japanese government proposed revising the National Security Strategy and set a target of 2% of GDP for defense spending, while also promoting new counterattack capabilities focused on cyberspace, hypersonic missiles and drones.
On Japan’s newly published Defense White Paper, the blacklist of cyber actors linked to foreign governments includes the Chinese groups Salt Typhoon, Volt Typhoon and Flax Typhoon. It also identifies Russian cyber units connected to the General Staff. In North Korea’s case, the report explicitly names Lazarus, a cryptocurrency-heist group that operates under the country’s military, the Korean People’s Army.
Osawa also warns of the growing role of artificial intelligence. Intrusion code can now be written by so-called frontier AI, a new generation of systems capable of carrying out the entire attack chain: initial reconnaissance, vulnerability detection, system exploitation, and the theft or destruction of information.
Foreign cyberattacks have targeted institutions such as the Japan Aerospace Exploration Agency (JAXA) and companies like Mitsubishi Heavy Industries (MHI), one of the archipelago’s earliest military contractors.
In the civilian sector, notable incidents include the ransomware attack against Nagoya Port and the beverage maker Asahi Holdings, as well as the data leak at telecommunications firm KDDI and the cyberattack on Kojima Industries, a key Toyota supplier, that forced the automaker to suspend production across Japan for an entire day.
The Japanese government began prioritizing cybersecurity in 2000, following a series of cyberattacks against government websites. It subsequently established a dedicated office which, after several reorganizations and name changes, evolved into the National Center of Incident Readiness and Strategy for Cybersecurity (NISC).
For Mihoko Matsubara, chief cybersecurity strategist at telecommunications and IT giant NTT, the Active Cyber Defense Law leaves small and medium-sized enterprises unprotected because it focuses primarily on national security and critical sectors such as water, energy and transportation.
Speaking at NTT’s headquarters in central Tokyo, Matsubara highlights the close links between SMEs, the state and major corporations, noting that they all “share the same data and the same technology.” The cybersecurity expert, who has also written several books for general audiences, nevertheless points to Japan’s comparatively low rate of ransomware infections. She cites a report by U.S. cybersecurity firm Proofpoint showing that in 2024 Japan recorded one of the lowest ransomware infection rates among developed economies, at 38%, compared with 85% in Germany, 77% in the United States and 69% in Spain.
The same report notes that Japanese companies tend to pay smaller ransoms. Because Japan is highly prone to natural disasters, businesses are used to maintaining backup systems, allowing them to restore operations without having to negotiate with attackers.
When discussing official support for small and medium-sized enterprises, Matsubara recalls from memory Spain’s INCIBE cybersecurity hotline, 017, as a point of comparison with Japan’s Information-technology Promotion Agency (IPA). The Japanese body handles around 12,000 inquiries a year, compared with the 140,000 received by its Spanish counterpart last year.
She also stresses the vulnerability of supply chains, citing the ransomware attack on the Port of Nagoya that shut down the country’s largest commercial port for two days in July 2023. “That is why Japan concluded it needed to take more proactive measures,” she says.
For Matsubara, the passage of the Active Cyber Defense Law in May 2025, with the backing of the Constitutional Democratic Party, then the main opposition force, confirms the broad political consensus on the urgency of the threat.
“Both the ruling party [the Liberal Democratic Party, LDP] and the opposition agreed that more proactive action was needed because there had already been too many disruptive cyberattacks on critical infrastructure worldwide,” she argues.
Matsubara also points to the ambiguity of the term “neutralization of cyberattacks” in the legislation and acknowledges that it has raised concerns about potential infringements on citizens’ privacy.
In March 2025, during the parliamentary debate over the bill, the liberal Tokyo Shimbun newspaper, a longstanding critic of Japan’s military buildup, warned that the legislation could be used to expand state surveillance. In an article headlined “It Could Change the Nature of the State,” the newspaper questioned the law’s constitutionality.
Sign up for our weekly newsletter to get more English-language news coverage from EL PAÍS USA Edition