Sources: in the fall of 2020, the NSA discovered that Chinese hackers had access to Japanese defense networks; the problem persisted until at least fall 2021
Not 2021. They're still in there, as of June 2023: https://www.nisc.go.jp/... X: Ellen Nakashima / @nakashimae : The penetration was so disturbing that NSA chief Gen. Paul Nakasone and then-Deputy National Security Advisor Matt Pottinger flew to Tokyo to alert the defense minister. He was so concerned he arranged for them to brief the prime minister himself. Ellen Nakashima / @nakashimae : SCOOP: China hacked Japan's sensitive defense networks, alarming top U.S. national security officials. Tokyo has made strides since the 2020 breach was discovered by the NSA. But the problem is still not fully fixed. https://www.washingtonpost.com/ ... Ellen Nakashima / @nakashimae : Japan is boosting its cyber budget, quadrupling its cyber forces, taking more steps to secure its networks from adversaries. “At the end of the day, we're going to share information with them,” a defense official said. “We just want to do our best to keep our adversaries out.” LinkedIn: Robert Metzger : We are seeing a string of reports such as this, all exposing China's intent to deny, degrade or even destroy critical information systems … Forums: r/hacking : China hacked Japan's sensitive defense networks, officials say r/worldnews : China hacked Japan's sensitive defense networks, officials say r/fucktheccp : China hacked Japan's sensitive defense networks, officials say r/neoliberal : China hacked Japan's sensitive defense networks, officials say Beehaw : China hacked Japan's sensitive defense networks, officials say
Context & Ripple Effects
The reported intrusion shows that concern over Chinese access to Japanese systems extended beyond a single incident: later coverage described a breach of Japan’s cybersecurity agency, the reported NISC email-system compromise.
It also preceded a joint U.S.-Japan warning that BlackTech was using compromised network devices to establish corporate backdoors, placing defense-network security in a wider allied exposure problem.
First-order effects
- Japan’s defense establishment and U.S. security counterparts must treat the reported multi-year access as a potential intelligence exposure, requiring investigation, containment, and review of affected networks.
- The episode raises the operational urgency of securing not only defense systems but the administrative and network infrastructure through which persistent access can be maintained.
Second-order effects
- U.S.-Japan cyber coordination is likely to put greater emphasis on shared detection and remediation, since the reported discovery depended on NSA visibility rather than a purely domestic finding.
- Organizations supporting Japanese defense networks face pressure to harden network equipment and access paths, a concern reinforced by the later BlackTech device-backdoor warning.
Third-order effects
- If repeated compromises across Japanese public and defense-related systems continue, cyber resilience becomes an alliance-wide ecosystem problem rather than one confined to military networks.
- The pattern points toward persistent-access campaigns as a strategic risk: the relevant measure is not merely preventing entry, but detecting and evicting long-lived intrusions across interconnected institutions.
The trend: This is one data point in a broader shift toward allied cyber defense built around finding and removing persistent access across shared public, telecom, and enterprise infrastructure.