Main Findings:

  • Today, 124 threat actors target or have targeted Japan. That’s 82% more than the 68 actors we tracked in 2024.
  • Ransomware attacks against Japanese organizations increased 39% year-over-year in early 2026, outpacing global increases in ransomware attacks which increased by 25%.
  • Japan was the 14th most attacked country by ransomware groups between January and April 2026, up from 28th during the same period just two years ago, underscoring the country’s growing exposure to cybercriminal activity. Manufacturing, automotive, and technology companies faced the greatest concentration of attacks.
  • The ongoing #OpJapan hacktivist campaign has targeted critical infrastructure organizations in the country with DDoS, data leaks, and compromise of industrial control systems.
  • There are 22 million internet-exposed devices in Japan, 34% more than we observed in 2024.

Mitigation Recommendations:

  • Inventory and assess every asset connected to your network, especially OT and IoT assets that are often vulnerable.
  • Leverage automated controls within the entire enterprise rather than in isolated silos.
  • Avoid exposing unmanaged devices directly to the internet.
  • Use a secure remote access solution to mediate interactions between remote users and OT assets.
  • Segment the network to isolate IT, IoT and OT devices, restricting network connections to specifically designated management and engineering workstations.
  • Utilize an IoT/OT-capable monitoring solution to detect and alert malicious indicators and behaviors.

Japan is one of the world’s most technologically advanced and economically significant nations, with industries ranging from manufacturing and automotive to semiconductors and critical infrastructure playing essential roles in both domestic and global supply chains. As organizations accelerate digital transformation, connect operational technology (OT) environments, and adopt AI-driven technologies, their cyber exposure grows alongside new business opportunities.

Amid this growth, Japan faces an increasingly complex threat landscape. Cybercriminals continue to target organizations with ransomware and extortion campaigns, state-sponsored actors seek intelligence and intellectual property, and hacktivist groups are increasingly targeting critical infrastructure and internet-exposed systems. These challenges reflect broader global trends. In the first half of 2026, published vulnerabilities increased 51% year-over-year, ransomware attacks rose 25%, and Forescout Research – Vedere Labs tracked more than 5,700 hacktivist attack claims worldwide. At the same time, AI is reshaping both defense and attacker behavior, accelerating the discovery of vulnerabilities and lowering barriers for threat actors to develop and scale cyber operations.

In response to global and local threats, both government agencies and industry groups in Japan have introduced new regulations, guidance, and cybersecurity initiatives aimed at strengthening resilience across key sectors.

In this era of rapid change, understanding where cyber risk exists and how threat actors are evolving is critical. In this report, Forescout Research – Vedere Labs analyzes internet-exposed assets, ransomware activity, threat actor targeting, and emerging hacktivist activity affecting Japan, and provides practical recommendations to help organizations reduce risk.

In 2024, we revealed thousands of critical infrastructure assets exposed to the internet in Japan, despite the increasing frequency of high-impact cyberattacks targeting the country. Two years later, cyber threats continue to target Japanese organizations, while internet-exposed assets, ransomware activity, and the number of threat actors targeting the country have all increased. Recent examples include ransomware impacting Asahi’s operations and a breach on international networks of Denso, a large automotive parts manufacturer. We also see emerging signs of hacktivism targeting the country’s institutions.

At the same time, Japan has introduced new cybersecurity regulations and sector-specific guidance designed to improve resilience across critical industries.  Examples include the Guidelines on Cybersecurity for the Financial Sector published by the Financial Services Agency (FSA), the Cybersecurity Guidelines published by the Japan Automobile Manufacturers Association (JAMA) and the Japan Auto Parts Industries Association (JAPIA), and the OT Security Guidelines for Semiconductor Device Factories published by the Ministry of Economy, Trade and Industry (METI). The most recent and probably most comprehensive of these is the Active Cyber Defense law, which was enacted in 2025 and will be enforceable by 2027. The law requires critical infrastructure operators in 15 sectors to, among other things, report incidents to the government.

These efforts reflect Japan’s broader commitment to cybersecurity. In the International Telecommunication Union’s 2024 Global Cybersecurity Index, Japan ranked among the highest-performing countries globally, although continued investment in technical capabilities and cooperation remains important as the threat landscape evolves.

Given these challenges to Japanese critical infrastructure organizations, in this blog we analyze the threat landscape in Japan – including the risk of exposed devices and threat actors targeting the country – to provide concrete risk mitigation recommendations.

Threat Landscape: Threat Actors and Ransomware

Forescout Research – Vedere Labs’ Threat Actor Knowledgebase currently tracks 124 threat actors that target or have targeted organizations in Japan. That’s 82% more than the 68 actors we tracked in 2024. Most of these actors have targeted government agencies (74%), financial services (62%) or technology companies (56%), but other industries have also been attacked. The increase in threat actors we’re tracking mirrors a broader global trend in which threat actor activity remains high. Worldwide, we are seeing an increasingly more complex and crowded cybersecurity threat landscape.

Forty percent of these actors are cyber-criminals with a main goal of financial gain. Another 40% are state-sponsored actors focused on intelligence gathering, espionage and intellectual property theft. Finally, 20% are hacktivists executing denial of service attacks, defacements, sabotage or destruction operations. While larger organizations are more likely to attract state-sponsored actors and ransomware groups due to the value of their data and operations, smaller organizations are often targeted opportunistically by hacktivists and cybercriminals seeking victims with weaker security postures.

Forty-one percent of the threat actors tracked are from China, 24% are based in Russia, 5% are North Korean, 2% are Iranian and the remaining 28% come from other countries. Threat actor origin and targeting information is drawn from the Forescout Research – Vedere Labs Threat Actor Knowledgebase, which combines our own tracking with publicly reported threat intelligence and attribution from industry and government sources.

According to public ransomware breach claims, Japan was the 14th most attacked country by ransomware groups between January and April 2026, with 32 incidents claimed by 14 groups. That is a 39% increase over the 23 incidents in the same period of 2025, which in turn was a 229% increase over the 7 incidents in the same period of 2024. The most active groups in this period were Qilin, The Gentlemen, Everest, Night Spire and Inc Ransom. Notably, ransomware activity in Japan is rising faster than global trends. Tracking ransomware incidents globally in the first half of 2026, our team observed a 25% increase year-over-year, compared to Japan’s 39% increase in a similar period.

In 2026, manufacturing was the most targeted industry (19%), followed by automotive (13%), technology (9%), healthcare and retail (6% each). Historically, these industries have always been among the most targeted.

Overall, the same database of ransomware attacks records 208 attacks on Japanese organizations between 2021 and April, 2026. However, this is likely not the full picture. A recent survey by the Japan Institute for Promotion of Digital Economy and Community found that at least 507 companies in the country had ever been hit by ransomware and 222 (44%) had paid the ransom demand to restore data. Of those paying, 139 (63%) could not restore their data – which is something we explored when discussing the LockBit leak last year.

Cyber incidents have already demonstrated their ability to disrupt major Japanese organizations. In recent years, ransomware and other cyberattacks have affected transportation, manufacturing, and defense-related networks, including a ransomware attack that disrupted operations at the Port of Nagoya in 2023 and a denial-of-service attack that affected Japan Airlines flight operations in 2024.

The Rise of Politically Motivated Hacktivism and #OpJapan

One increasingly important part of the threat landscape we did not discuss in 2024 is the emergence of politically motivated hacktivism targeting critical infrastructure in Japan. Japan was rarely a target of the ‘new wave’ of state-aligned hacktivism in the past. The original #OpJapan hashtag was used by hacktivist group Anonymous in 2012 when protesting against new piracy laws in the country.

However, since last year, a wave of politically motivated hacktivist activity using the #OpJapan hashtag has targeted critical infrastructure and other organizations in the country. The rise of #OpJapan also aligns with broader global hacktivist activity. Forescout tracked more than 5,700 hacktivist attack claims globally, with denial-of-service attacks, data breaches, system disruption, and defacement among the most common techniques.

The first sign we noticed was a warning post from the group Cyber Volk Arcanum in June, although that was not followed by any attack claims.

Next, during the whole month of October, the group CLOBELSECTEAM forwarded messages from allied group Hezi Rash and posted their own claims of dozens of attacks including DDoS, data leaks and hack of devices such as IP cameras and printers, all using the #OpJapan hashtag and mentioning organizations in the country. Those claims were interspersed with political messages ‘justifying’ the attacks, as shown below.

The group moved on to other targets, such as Israel and European countries, and stopped posting on November 30, with the last message being an attack against a SCADA system in Australia.

More recently, between February 11 and 15, 2026, NoName057(16) – the infamous pro-Russian group, which was also an ally of CLOBELSECTEAM – claimed ten attacks against Japanese organizations. These were equally split, with five messages showing DDoS attacks and five showing attacks against OT/IoT devices. The images below show example claims against agricultural systems, IP cameras and industrial control systems. Not coincidentally, these are the exact kinds of systems we describe below in the exposed devices sections. Hacktivists are well-known for opportunistically targeting whatever can be found accessible on the internet that will have a psychological impact on their victims.

The last #OpJapan claim we saw was from the Z-Pentest Alliance on April 26, also mentioning IP cameras. Although we haven’t seen more activity since, it is safe to assume that now that Japanese organizations are in the list of targets of these hacktivist alliances, more attacks will happen soon. More broadly, recent #OpJapan activity reflects a growing trend of geopolitically motivated hacktivist campaigns that have increasingly targeted organizations around the world. While most recent #OpJapan activity has focused on disruption and opportunistic targeting of exposed systems, incidents in other countries have shown how attacks against operational technology can have broader consequences. Examples include cyberattacks against Ukraine’s power grid in 2015-2016 and more recent attacks affecting water facilities in the United States. When critical infrastructure systems are attacked, it has the potential to directly impact public health and safety.

Risks: Exposed Devices

The Shodan search engine reports over 22 million internet-exposed devices in Japan, 34% more than we observed in 2024. The figure below shows a breakdown of these devices per exposed port/service and device type in the case of non-traditional IT assets.

The top two ports, 80/HTTP and 443/HTTPS, are the same as in the worldwide distribution. Of the other remaining ports, only two also appear in the worldwide top 10: 161/SNMP (top 3 in Japan and 8 worldwide) and 7547/CWMP (top 6 in Japan and 10 worldwide).

The only meaningful difference in the top 10 exposed ports in Japan between 2024 and 2026 is that port 500/IKE jumped from seventh to fourth most exposed, which reflects increased usage of VPN services for remote access. We also saw a significant increase in exposed IP cameras and DVR systems. While these were 16% of exposed IoT in 2024, they are now 51%.

In terms of exposed OT devices and protocols, the changes in the past two years were very significant. In 2024, Modbus was the top exposed, accounting for almost 30% of exposed OT services. In 2026, Modbus is the third most common exposed OT protocol, with 15% of assets. Siemens S7 is now the top, followed by port 30718 for the Lantronix Discovery Protocol (LDP) used by serial-to-IP converters. Lantronix is one of the vendors found vulnerable in our recent BRIDGE:BREAK research. Interestingly, building automation protocols such as BACnet, KNX and Tridium Fox, which were prevalent in 2024 have been mostly replaced by industrial automation protocols.

Many of these OT devices can be directly compromised by opportunistic attackers, such as hacktivists, who can interact with protocols that require no authentication. In other cases, these attackers can access human-machine interfaces (HMIs) that provide start/stop or configuration capabilities, such as the one shown below to control a greenhouse agricultural system. We explore some of these kinds of attacks in the next section.

This type of HMI is often exposed online via ports 3389/RDP or 5900/VNC. Although these ports are not in the top 10 shown above, our recent research showed that Japan is the fourth country in the world with most exposed RDP and VNC servers.

Some of the exposed OT devices also include firmware version information that can be used by attackers to match existing exploitable vulnerabilities. The figure below shows internet-exposed Siemens S7 programmable logic controllers (PLCs) with hardware and firmware versions.

Mitigation Guidance

Japan is the world’s fourth largest economy by nominal GDP. It is a powerhouse of advanced manufacturing and international trade — and an important player in geopolitics, especially in Asia. Organizations operating in the country are likely to be targeted by cybercriminals seeking money, hacktivists trying to spread a political message and state actors serving foreign interests.

To manage the risk, organizations should proactively identify and reduce their cyber exposure, starting with internet-exposed assets but including every connected IT, IoT, OT or medical device in their internal networks. Due to the increased scope of attacks on unmanaged devices, we recommend organizations in Japan focus on the following three strategic areas of cybersecurity:

  1. Risk & Exposure Management. Begin by conducting a thorough assessment of every asset connected to your network, especially OT and IoT assets that are often vulnerable. Scrutinize its security posture, known vulnerabilities, credentials and open ports. Replace default and easily guessable credentials with strong, unique passwords for each device. Disable unused services, patch vulnerabilities promptly, and adopt a risk-based approach for mitigation. Leverage automated controls within the entire enterprise rather than in isolated silos.
  2. Network Security. Avoid exposing unmanaged devices directly to the internet. Opt for network segmentation to isolate IT, IoT and OT devices, restricting network connections to specifically designated management and engineering workstations. Segmentation should extend not only between IT and OT but also within these networks to thwart lateral movement and data exfiltration. Implement restrictions on external communication paths and employ isolation or containment measures for vulnerable devices as a mitigating control, especially when immediate patching is challenging.
  3. Threat Detection & Response. Utilize an IoT/OT-capable monitoring solution to detect and alert malicious indicators and behaviors. Monitor internal systems and communications for known hostile actions, such as vulnerability exploitation, password guessing and unauthorized use of OT protocols. Alert network operators to anomalous and malformed traffic. Consider solutions that collect telemetry and logs from diverse sources that correlate attack signals for analyst investigation. These solutions offer the capability to automate response actions across the enterprise.

We emphasize that traditional cyber hygiene practices must be applied comprehensively across all network assets. Prioritize the most critical attack surfaces based on up-to-date threat and business intelligence for a robust cybersecurity posture.

Additionally, mitigating the risks of exposed OT systems will in most cases require the use of a secure remote access solution to mediate each interaction between a remote user and an OT asset, such as a PLC, HMI, or engineering workstation.

Stay on top of the latest threats. Sign up for the Vedere Labs Threat Feed and get the full context in our monthly newsletter.