Japan is preparing to give its military and police new powers to counter cyberattacks at their source, marking a significant expansion of the country’s security posture and raising questions about the limits of state power in cyberspace.
A new Cyber Defence Act due to take effect in October will allow the Japanese state to neutralise computers from which large-scale cyberattacks against critical infrastructure or government systems originate, including attacks linked to state actors such as China, Russia and North Korea.
The legislation forms part of Japan’s accelerated military build-up, which has gained further momentum under Prime Minister Sanae Takaichi, who took office in October last year and represents the hardline conservative wing of Japanese politics.
“The new law enables the state to counterattack through cyberspace and neutralise computers where cyberattacks against critical infrastructure or the government originate,” said Jun Osawa, a senior researcher at the Sasakawa Peace Foundation. Crucially, he added, “There is no need for a war to have been declared.”
The change represents a notable development for a country whose post-war security policy has been shaped by its pacifist Constitution. Japan’s approximately 220,000-strong armed forces are formally known as the Self-Defence Forces, and Article 9 of the Constitution renounces war as a sovereign right and states that land, sea and air forces will not be maintained.
Yet cyberattacks frequently fall below the conventional threshold of war. Osawa argues that failing to respond to such attacks can leave national infrastructure exposed. He identifies Russia’s invasion of Ukraine, which began in February 2022, as a turning point, noting that cyberattacks preceded the missile strikes.
“What became clear there was that cyberattacks and information warfare, what Europe calls Foreign Information Manipulation and Interference (FIMI), begin long before a war itself breaks out,” Osawa said.
Japan’s response has included a major expansion of its security ambitions. In mid-2022, the government proposed revising its National Security Strategy and set a target of military spending equivalent to 2% of GDP, while promoting new counterattack capabilities involving cyberspace, hypersonic missiles and drones.
Japan’s latest Defence White Paper identifies Chinese-linked groups including Salt Typhoon, Volt Typhoon and Flax Typhoon, as well as Russian cyber units linked to the General Staff. It also names Lazarus, a cryptocurrency-looting group operating under North Korea’s People’s Army.
The threat is also evolving through artificial intelligence. Osawa warns that so-called frontier AI can already generate intrusion codes and potentially carry out an entire attack chain, from initial reconnaissance and vulnerability detection to exploitation and the destruction or theft of information.
Japanese institutions and companies have already been targeted. Attacks have affected the Japan Aerospace Exploration Agency (JAXA) and Mitsubishi Heavy Industries, while civilian targets have included Nagoya port, Asahi Holdings, KDDI and Kojima Industries Corporation, a major Toyota components supplier. An attack on Kojima Industries forced Toyota to halt domestic production for an entire day.
Japan began prioritising cybersecurity in 2000 after attacks on government websites, eventually establishing what became the National Cybersecurity Office.
However, Mihoko Matsubara, Chief Cybersecurity Strategist at NTT, warns that the new Active Cyber Defence Act may leave small and medium-sized enterprises exposed because it concentrates on national security and vital sectors such as water, energy and transport. She stresses that smaller firms, the state and major corporations share data and technology, making supply chains particularly vulnerable.
Matsubara also notes that Japan has recorded a comparatively low ransomware infection rate. A 2024 Proofpoint report cited by her put Japan at 38%, compared with 85% in Germany, 77% in the US and 69% in Spain. Japanese companies also tend to pay fewer ransoms, partly because regular backups allow them to restore operations without negotiating with attackers.
The Active Cyber Defence Act was approved in May 2025 with the support of the Constitutional Democratic Party, then the main opposition force. Matsubara sees that cross-party backing as evidence of broad agreement over the urgency of the threat.
But the law has also prompted concerns about privacy and surveillance. Its wording on the “neutralisation of cyberattacks” has been described as ambiguous. In March 2025, during parliamentary debate, the liberal-progressive Tokyo Shimbun warned that the legislation could be used for state surveillance and questioned its constitutionality, under the headline: “It Could Change the Nature of the State”.
Japan’s new cyber powers therefore mark more than a technical shift in how the country confronts digital attacks. They place cyberspace at the centre of a broader transformation in Japanese security policy, where the boundary between defence, counterattack and state surveillance is becoming increasingly difficult to define.

