Security1 publisher2 min readPublished
Japan plans government-built threat hunting for power and telecom operators
Japan's government will build and test methods to find attackers already inside power and telecom networks, with costs in fiscal 2027 budget requests. For operators, the job extends past answering alerts to searching for intruders who never set one off.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The National Cybersecurity Office will recreate attack scenarios in a virtual environment from threat information, then develop detection methods for private operators to use.
- Companies that ask for help can get Defense Ministry personnel whose threat-hunting experience comes from the Self-Defense Forces' own information systems.
- Legislation for Japan's active cyber defense took effect on Thursday, giving the government a legal framework for expanding these measures.
- The government's shared network was hit by a cyberattack that began in May and was disclosed in September 2026.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Hunting runs on large volumes of system event logs, so the shared methods help only as much as the logging each operator already collects and keeps.
- decision Ministry help arrives only when a company asks, so each power or telecom operator has to decide whether to let ministry personnel work inside its systems.
- capability Searching the window after initial access gives operators a chance to catch ransomware crews before deployment, a benefit a National Cybersecurity Office representative cited.
- constraint With costs still sitting in fiscal 2027 budget requests, the methods and the dispatch program remain plans that operators cannot draw on yet.
The Cyber Express reported that the plan targets attackers who have gained access and move through a system without triggering an alert [17]. The government's own network had one. An analysis found that a third party compromised the Government Solution Service by exploiting a bypass involving a VPN [13]. About four months passed between the start of the attack and its public disclosure [1]. Digital Minister Hisashi Matsumoto said about 246,000 personal records could have been leaked [11]. Government agencies and independent administrative agencies use the service. The data at risk includes about 189,000 employee records and around 57,000 records of businesses and individuals involved in agency work [12].
The private-sector cases reported alongside the plan come from different sectors. Nichirei, a frozen food and logistics company, confirmed unauthorized access to its servers in July, and the disruption reached logistics supporting KFC Japan [14]. A malware incident at Nihon Kotsu took parts of its IT infrastructure offline and disrupted taxi dispatch [15]. Earlier breaches at Aflac Japan, KDDI, Sapporo Holdings and Nidec showed attackers getting in through subsidiaries, overseas operations or third-party infrastructure [16]. In these cases, what the incidents share is the way in. A hunt limited to a parent company's core network would miss all three of those paths [16].
At least one Japanese company already does this work. NTT Data Japan has run proactive threat hunting on its own systems since 2024, checking logs for suspicious activity even when no alert has fired [8]. The report does not say whether power and telecom operators will be required to adopt the government's methods or to report what a hunt turns up [2].
What to watch
- The final fiscal 2027 budget, and the amounts approved for the hunting methods and the ministry's dispatch staff.
- The first detection methods the National Cybersecurity Office releases from its virtual-environment testing, and which threats they target.
- The first public case of a power or telecom operator requesting Defense Ministry hunters, and what they found.