Menu
Browse

Cyber Incident Victim: Government of Japan

Date:

Sep 2022

Location:

Japan

Summary

A Russia-affiliated hacking group known as Killnet claimed responsibility for cyber-attacks targeting multiple government websites and companies, causing temporary inaccessibility and login disruptions across four ministries' online services. The distributed denial-of-service (DDoS) incidents were reportedly linked to geopolitical tensions involving Ukraine support and a territorial dispute, though officials confirmed investigations into the failures and attribution were ongoing. Services were restored within hours, with cybersecurity analysts noting the group's history of similar disruptive attacks against other nations' infrastructure, emphasizing data theft and operational interference tactics. The incident highlighted broader patterns of politically motivated cyber campaigns aimed at disrupting public services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

On or around September 6, 2022, multiple Japanese government websites experienced disruptions attributed to cyber-attacks. The Russia-affiliated hacking group Killnet claimed responsibility for targeting Japanese companies and approximately 20 websites across four government ministries. Japan’s Chief Cabinet Secretary Hirokazu Matsuno confirmed the government was investigating whether a denial-of-service (DDoS) attack caused accessibility issues. The country’s digital agency separately reported login problems affecting some services on its e-Gov administrative portal on September 7, though it did not explicitly link these issues to the attacks. Government websites became inaccessible on Tuesday evening but were restored within the same day. Matsuno acknowledged Killnet’s claim of involvement but emphasized investigations into the failures were ongoing, including verifying the group’s role. No data breaches or permanent damage to systems were reported.

Cyber Incident Image

Threat intelligence analysts attributed the attacks to Killnet’s pattern of targeting nations supporting Ukraine during the Russia-Ukraine conflict, with Japan’s stance on Ukraine and historical disputes over the Kuril Islands cited as potential motives. Check Point’s Sergey Shykevich characterized the incidents as disruptive DDoS attacks intended to inconvenience government operations and citizens rather than cause permanent infrastructure damage. The attacks aligned with Killnet’s established tactics of combining DDoS disruptions with data theft operations, as previously observed in similar incidents affecting Italy, Lithuania, Estonia, Poland, and Norway. Japanese authorities implemented restoration procedures promptly but did not disclose specific technical countermeasures. No additional collateral impacts on private sector entities or critical infrastructure were documented in the immediate aftermath.

Sources
Sources available to members
1 source