Japan is stepping up its plans to find cyber attackers who may already be inside the networks that keep essential services running. Under a new fiscal 2027 initiative, the government plans to work with private companies to strengthen Japan threat hunting across critical infrastructure, including power utilities and telecommunications operators.
The focus is not only on stopping attacks after they are detected, but on finding signs that an attacker has gained access and is quietly moving through a system without triggering an alert.
The government will develop ways to detect these threats and share the methods with private-sector operators, while the Defense Ministry will be able to provide personnel to assist companies when requested.
The initiative forms part of Japan’s broader active cyber defense efforts. Threat hunting involves actively searching systems for signs of malicious activity rather than waiting for an alert or confirmed attack.
Japan’s National Cybersecurity Office plans to use information about potential threats to recreate attack scenarios in a virtual environment. The office will then develop and test detection methods that can be used by private-sector companies.
The aim is to help critical infrastructure operators identify attackers that may have already entered their systems and remained undetected. Detecting such activity could also help reduce the risk of a cyberattack disrupting essential services during an emergency.
Legislation related to active cyber defense took effect on Thursday, giving the government a framework for expanding these cybersecurity measures.
Japan’s Defense Ministry is also preparing to provide direct support to operators of critical infrastructure.
Companies will be able to request assistance, after which the ministry could dispatch personnel with threat-hunting experience developed through the information systems of Japan’s Self-Defense Forces.
The National Cybersecurity Office and Defense Ministry have included the related costs in their fiscal 2027 budget requests.
Threat hunting can require considerable resources because security teams need to collect and examine large amounts of system event logs. The purpose is to identify unusual activity that may otherwise go unnoticed.
NTT Data Japan has been carrying out proactive threat hunting on its own systems since 2024. The company checks system logs for suspicious activity even when there has been no security alert.
A representative of the National Cybersecurity Office also said threat-hunting methods could help address ransomware. Such attacks can involve attackers exploring a victim’s systems after gaining initial access, meaning suspicious activity may exist before the ransomware itself is deployed.
Japan’s planned expansion of threat hunting comes as cyber incidents have affected government networks and companies across different sectors.
In September 2026, the government disclosed that its common infrastructure network had been targeted in a cyberattack that began in May. Digital Minister Hisashi Matsumoto said about 246,000 personal records could have been leaked.
The affected Government Solution Service, or GSS, is used by government agencies and independent administrative agencies. The potentially exposed information included about 189,000 employee records and around 57,000 records belonging to businesses and individuals involved in agency operations.
An analysis found that a third party had compromised the system by exploiting a bypass involving a virtual private network, or VPN.
Other recent incidents have affected private-sector operations. The Nichirei cyberattack in July disrupted food deliveries after the frozen food and logistics company confirmed unauthorized access to its servers. The incident affected logistics operations supporting KFC Japan.
Nihon Kotsu also recently reported a malware-related incident that disrupted taxi dispatch services after parts of its IT infrastructure were taken offline.
Earlier incidents involving Aflac Japan, KDDI, Sapporo Holdings and Nidec showed that attackers could gain access through subsidiaries, overseas operations or third-party infrastructure.
Japan’s fiscal 2027 plans therefore put greater emphasis on looking for attackers that may already be inside a network, rather than relying only on alerts after suspicious activity has become visible.