It has been revealed that the Japan Ground Self-Defense Force had been using USB memory sticks infected with Chinese malware in systems handling confidential information for about a year. This case highlights “supply chain blind spots” in the procurement of goods during disaster dispatch and the structural vulnerabilities hidden in the operational framework of the defense core.
- Background of Discovery and the Reality of Intrusion into ‘Closed-System’ Systems
- The True Nature of Clever ‘Counterfeit Goods’ and the Threat of Chinese Malware
- The ‘hole’ and opaque acquisition route during the emergency of the Noto Peninsula earthquake
- Risks Spreading on General E-Commerce Sites and Their Ripple Effects on Society as a Whole
- The contradiction between lack of information sharing and “proactive cyber defense”
- Expansion of the security market and self-defense measures companies should take
Background of Discovery and the Reality of Intrusion into ‘Closed-System’ Systems
The incident took place at the Chubu Regional Headquarters of the Japan Ground Self-Defense Force, located in Itami City, Hyogo Prefecture, responsible for defense in the, Chugoku, and Shikoku regions. In February 2025, an investigation was conducted after a duty officer noticed a computer operating delay, and a virus was detected on a connected USB memory drive.
As a result of the investigation, six infected USB memory sticks were found, and it was revealed that more than 50 of the approximately 480 computers within the Inspectorate Office were connected. What is serious is that about half of those connected devices were systems that handled top-secret information physically cut off from the internet, known as “closed systems.” Originally, the “air gap” (physical disconnection) meant to prevent external cyberattacks was neutralized by a “bridge” called a contaminated USB. From around March 2024, the Japan Ground Self-Defense Force continued to bring this source of infection into classified territory for about 11 months.
The True Nature of Clever ‘Counterfeit Goods’ and the Threat of Chinese Malware
When the recovered USB memory sticks were analyzed by the Japan Ground Self-Defense Force Cyber Protection Unit, a shocking reality was revealed. The product in question was advertised as having a capacity of 1 terabyte, but in reality, it was a “capacity fraud” with only a quarter of that capacity, 240 gigabytes. Furthermore, it was identified that the internal structure was not genuine flash memory, but rather a cheap microSD card hidden inside, making it look like a USB memory stick, making it a poorly made counterfeit Chinese product.
What was embedded in this fake USB was known malware that was said to have been used by a Chinese hacker group in the past. This virus automatically activates the moment a USB is plugged into a computer, functioning as a “stepping stone” to spread infection even without users opening files. Instead of directly breaching the network, attackers chose a highly rational approach: to have malicious devices implanted during manufacturing and distribution carried inside by a “human hand.”
The diagram below illustrates the structure of the system intrusion in this case.

[Supply Network Blind Spots] Supply Chain Attacks Hidden Behind Disaster Dispatch
The ‘hole’ and opaque acquisition route during the emergency of the Noto Peninsula earthquake
The entry of fake USBs into the Self-Defense Forces is closely related to the Noto Peninsula earthquake that occurred in January 2024. According to internal documents, the Chubu Regional Headquarters reportedly received this USB from Ishikawa Prefecture in March of the same year during disaster relief activities in the affected area for data sharing. Prioritizing life-saving and urgently requiring time to count, this creates a “safety management gap” where strict procurement procedures and virus checks are omitted during normal times.
However, there are still unclear points regarding the origin of the items. Ishikawa Prefecture responded to interviews that they could not confirm records of procuring the USB or the fact that the purchase cost was paid, and the exact supply route of who brought the device to the site and with what intentions remains unclear. This fact teaches us a security lesson that supply chain management is most vulnerable during emergencies and disasters, providing excellent opportunities for hostile forces to infiltrate.
Risks Spreading on General E-Commerce Sites and Their Ripple Effects on Society as a Whole
This fake USB was not obtained through special channels but was widely distributed on common e-commerce (e-commerce) sites like Amazon and Rakuten. Priced nearly half the price of genuine products, they advertise “large capacity” and flood the market in ways that stimulate consumers’ desire to buy. This incident shows that the Self-Defense Forces, the core of national defense, have fallen into a cheap “trap” that anyone can buy online, and its impact extends beyond the military domain.
Many critical infrastructures—such as electronic medical record systems in medical institutions, control lines in factories, and core systems in financial institutions—are operated separately from the internet for security reasons still use USB memory sticks for data transfer. If similar counterfeit goods enter these sites, there is a risk of large-scale damage that paralyzes social functions. The very structure of modern society, which relies on cheap imported products, is exposed to a vast web of cyberattacks.
The following chart illustrates the risk of attacks spreading through the general market.

[Future Developments and Countermeasures] The Philosophy of ‘Proactive Cyber Defense’ and Market Trends
The contradiction between lack of information sharing and “proactive cyber defense”
The Self-Defense Forces only learned of the infection in February 2025, but this fact was only made public in June 2026, more than a year later. The government is advancing the institutionalization of “active cyber defense” by 2025, aiming to prevent damage by sharing threat information through public-private collaboration. However, the fact that the Self-Defense Forces themselves concealed information about dangerous USB devices widely circulating in society for a long time is a direct contradiction to this new defense philosophy.
Defense Minister Koizumi acknowledged that the rule requiring all virus checks during USB use was not being followed, emphasizing thorough prevention of recurrence. Going forward, the culture of hiding organizational scandals will shift, and the effectiveness of mechanisms that enable rapid sharing of identified threat information between public and private sectors will be questioned. The success or failure of “proactive cyber defense,” aiming for full-scale operation within fiscal year 2027, depends more on ensuring transparency and transforming organizational culture than on technical measures.
Expansion of the security market and self-defense measures companies should take
In response to this incident, interest in cybersecurity-related stocks has renewed in the Japanese stock market. In particular, companies such as FFRI Security (3692), which has extensive experience serving defense ministries and government agencies, and Trend Micro (4704), which excels in endpoint protection, are drawing attention amid the accelerated adoption of proactive cyber defense. Security investments by critical infrastructure operators and related industries are expected to continue expanding toward the government’s 2027 operational launch target.
At the same time, the practical measures that companies and individuals should take are also being redefined.
-
Never disable virus scanning settings for external media
-
Do not purchase or use USB memory sticks of unknown origin or large-capacity devices that are inexpensive and out of market value
-
Even in emergencies such as disasters, thorough recording of procurement routes and initial quarantine are enforced.
Society as a whole needs to recognize that “operational laxity,” which prioritizes convenience and cost over security, is the greatest vulnerability that can disable even modern systems.
[#サイバーセキュリティ #自衛隊 #サプライチェーン攻撃 #能動的サイバー防御 #情報セキュリティ]


コメント