CSIDB logo
Incident

Government of Japan

Incident posture

Attack window
Sep 2022
Location
Japan
Status
Historical
CIA posture
Available to members
Updated
2026-01-09 17:53

Linked entities

Victim
Government of Japan
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Sep 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Russia-affiliated hacking group known as Killnet claimed responsibility for cyber-attacks targeting multiple government websites and companies, causing temporary inaccessibility and login disruptions across four ministries' online services. The distributed denial-of-service (DDoS) incidents were reportedly linked to geopolitical tensions involving Ukraine support and a territorial dispute, though officials confirmed investigations into the failures and attribution were ongoing. Services were restored within hours, with cybersecurity analysts noting the group's history of similar disruptive attacks against other nations' infrastructure, emphasizing data theft and operational interference tactics. The incident highlighted broader patterns of politically motivated cyber campaigns aimed at disrupting public services.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around September 6, 2022, multiple Japanese government websites experienced disruptions attributed to cyber-attacks. The Russia-affiliated hacking group Killnet claimed responsibility for targeting Japanese companies and approximately 20 websites across four government ministries. Japan’s Chief Cabinet Secretary Hirokazu Matsuno confirmed the government was investigating whether a denial-of-service (DDoS) attack caused accessibility issues. The country’s digital agency separately reported login problems affecting some services on its e-Gov administrative portal on September 7, though it did not explicitly link these issues to the attacks. Government websites became inaccessible on Tuesday evening but were restored within the same day. Matsuno acknowledged Killnet’s claim of involvement but emphasized investigations into the failures were ongoing, including verifying the group’s role. No data breaches or permanent damage to systems were reported.

Threat intelligence analysts attributed the attacks to Killnet’s pattern of targeting nations supporting Ukraine during the Russia-Ukraine conflict, with Japan’s stance on Ukraine and historical disputes over the Kuril Islands cited as potential motives. Check Point’s Sergey Shykevich characterized the incidents as disruptive DDoS attacks intended to inconvenience government operations and citizens rather than cause permanent infrastructure damage. The attacks aligned with Killnet’s established tactics of combining DDoS disruptions with data theft operations, as previously observed in similar incidents affecting Italy, Lithuania, Estonia, Poland, and Norway. Japanese authorities implemented restoration procedures promptly but did not disclose specific technical countermeasures. No additional collateral impacts on private sector entities or critical infrastructure were documented in the immediate aftermath.

Sources

Sources available to members: 1 source.

CSIDB