JAXA confirms intruders reached its internal network
- Organization
- Japan Aerospace Exploration Agency (JAXA)
- Exploit
- Hacking
- Industry
- Government
The Japan Aerospace Exploration Agency confirmed in late November 2023 that intruders had gained unauthorized access to its internal network. Chief Cabinet Secretary Hirokazu Matsuno acknowledged the breach at a briefing on November 29 and said an investigation was underway.
Reporting indicated the intrusion took place during the summer of 2023 and went undetected until police alerted the agency in the autumn. Investigators found that the attackers had reached JAXA's central Active Directory server, the system that holds employee account credentials and access permissions across the organization.
JAXA said no data relating to rockets or satellite operations appeared to have been accessed, and officials said no data leak had been confirmed. The agency shut down parts of its network, including its intranet, while it assessed the scope of the incident. Its public website remained online, and the Japanese government asked the agency to put countermeasures in place.
No attacker was identified. The Record reported that the intruders were believed to have exploited a vulnerability in network equipment that the manufacturer disclosed in June 2023, though the vendor was not named. JAXA had been targeted before, including a 2016 campaign later attributed to a Chinese national, and the agency said the 2023 investigation was continuing.