Japanese Police, Japan Self-Defense Forces (JSDF) to Directly Neutralize Servers Used in Cyberattacks
- Input
- 2026-10-01 10:23:03
- Updated
- 2026-10-01 10:23:03

【Financial News, Tokyo = Correspondent Seo Hye-jin】Japan will launch 'active cyber defense,' which involves directly infiltrating servers used in cyberattacks to delete malicious programs. Companies operating critical infrastructure, including power, finance and telecommunications, will be required to report signs of attacks and any damage to the government. The initiative aims to establish a system that goes beyond responding after damage occurs by proactively blocking attacks.
According to Nihon Keizai Shimbun (Nikkei) on the 1st, the Japanese government began enforcing legislation related to active cyber defense that day. If unauthorized access is detected and there is a risk of serious damage, police will be allowed to neutralize servers used in attacks.
Police will be responsible for the response in principle. Under the amended Police Duties Execution Act, the measures are classified as 'measures to prevent harm' and will be carried out by enforcement officers designated by the commissioner general of the National Police Agency of Japan after analyzing threat information. One option under consideration is infiltrating attack servers to delete malicious programs. The Special Response Section, established last year within the National Police Agency of Japan's Cyber Special Investigations Division, will lead the response.
The JSDF may respond jointly with police to highly organized and carefully planned attacks backed by foreign governments. Under the system, the prime minister orders the implementation of measures to protect communications after deliberations by the National Security Council (NSC).
As a rule, measures to neutralize servers require prior approval from the independent oversight body, the Cyber Communications and Information Oversight Commission. If an attack is imminent and there is no time to obtain approval, the commission must be promptly notified after the measures are carried out.
Private companies also face stricter reporting requirements. The rules apply to companies in 15 core infrastructure sectors designated by the government, including electricity, gas, finance, telecommunications and railways. If they confirm a malware infection or unauthorized access, they must promptly report it to the government and submit detailed information within 30 days.
Companies are updating their communication networks with authorities and incident-response procedures. According to the Japanese Bankers Association, individual banks have strengthened their attack-monitoring and detection capabilities while expanding information sharing with relevant agencies. NTT is consulting with the National Cybersecurity Office (NCO) and the Ministry of Internal Affairs and Communications on response measures, while Tokyo Gas has established a system for reporting security incidents to the government.
The Japanese government plans to establish a council to share information on attack-related damage and warning signs with critical infrastructure companies. The NCO will work with the National Security Secretariat to coordinate responses by the police and the Ministry of Defense of Japan, among others. The government is also considering establishing a joint base where police and the JSDF can carry out neutralization measures.
However, the system for collecting and using communications intelligence will be introduced in stages. Legislation allowing the acquisition of communications information from servers and other sources that may have been used in attacks is scheduled to take effect by next fall. The government will establish an oversight framework and operating rules to protect the confidentiality of communications.
[email protected] Seo Hye-jin Reporter