Japan Ground Self-Defense Force Used Malware-Infected USB Drives on Sensitive Systems
Japan’s Ground Self-Defense Force used counterfeit USB flash drives infected with China-linked malware on computers connected to sensitive military networks for nearly a year, according to a Nikkei investigation.
The malware was discovered in February 2025 after a computer at the JGSDF Middle Army headquarters in Itami, near Osaka, began running slowly. A wider internal review found that multiple infected USB drives had already been connected to dozens of systems.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The incident highlights a basic but serious cybersecurity risk: low-cost removable hardware can become an entry point into high-security environments when procurement checks, scanning rules, and device controls fail.
How the USB Malware Reached Military Systems
The infected drives were reportedly counterfeit products made in China and sold as high-capacity USB storage devices. Investigators found that some devices advertised 1TB of storage but actually used cheaper microSD cards with far less usable capacity.
According to CyberInsider, internal records cited by Nikkei said the regional headquarters received eight USB drives during disaster relief operations after the January 2024 Noto Peninsula earthquake. The drives were transferred from Ishikawa Prefecture in March 2024.
Six of the eight drives were reportedly found to contain the same malware. Investigators could not determine exactly how the devices were originally procured, which points to a supply chain and procurement control gap.
| Detail | Reported Information |
|---|---|
| Organization affected | Japan Ground Self-Defense Force |
| Discovery date | February 2025 |
| Location | Middle Army headquarters in Itami, near Osaka |
| Initial clue | A computer started running unusually slowly |
| Devices examined | Eight USB drives |
| Infected drives | Six drives reportedly carried the same malware |
More Than 50 Computers Were Connected to the Drives
The internal review reportedly examined about 480 computers. More than 50 had been connected to one of the infected USB drives at some point.
Nearly half of those affected systems were reportedly tied to isolated networks used for highly sensitive information, including command-and-control data. That does not mean the malware successfully stole classified data, but it shows how close the incident came to Japan’s most sensitive military environments.
The Defense Post reported that the Self-Defense Forces said they found no evidence of system compromise or leakage of sensitive information. The SDF also said antivirus screening procedures have since been strengthened.
The Malware Was Linked to Chinese Threat Activity
The malware found on the counterfeit drives matched a strain that a U.S. cybersecurity company had previously linked to a Chinese hacking group, according to reporting based on the Nikkei findings.
The malware reportedly ran automatically when an infected USB drive was inserted into a computer. That behavior would make the attack more dangerous in environments where users may assume a removable drive is safe after routine procurement or antivirus checks.
The case shows why USB malware remains a practical threat, especially in segmented or closed networks. Attackers may use infected removable media when direct internet-based intrusion is harder.
- The drives were reportedly counterfeit and falsely advertised higher storage capacity.
- The malware could execute when the USB drive was connected.
- Multiple screening procedures failed to stop the infected devices.
- The malware remained undetected for almost a year.
- The affected systems included computers linked to sensitive networks.
Why the Incident Was Not Publicly Disclosed Earlier
The JGSDF reportedly kept the incident internal after the malware was found. That decision drew concern because similar counterfeit drives were still available through online marketplaces.
The risk was not limited to military users. The Edge Malaysia, citing Nikkei Asia, reported that fake USB sticks loaded with China-linked malware had also reached computers at factories and research facilities in different industries.
Nikkei also examined low-rated reviews for top USB products listed on Amazon Japan and Amazon U.S. The review found complaints that suggested similar counterfeit storage problems had appeared in both markets, with more complaints emerging since 2024.
What Failed Inside the Security Process
The incident appears to involve several failures rather than a single mistake. The drives entered a sensitive environment, passed through or avoided expected checks, and remained in use long enough to touch more than 50 systems.
Reports said the JGSDF had procedures for scanning USB devices during procurement and use. However, the compromised drives were reportedly excluded from some endpoint security scans for reasons investigators could not fully explain.
That gap matters because removable media controls depend on consistency. A policy that exists on paper cannot protect sensitive systems if field processes, procurement workflows, and endpoint tools do not enforce it every time.
| Security Layer | Reported Weakness | Risk Created |
|---|---|---|
| Procurement | Counterfeit USB drives entered use | Untrusted hardware reached military systems |
| Device scanning | Some checks failed or did not run as expected | Malware remained active for months |
| Network separation | Drives reached computers tied to sensitive networks | Potential exposure of classified environments |
| Disclosure | The broader risk was not publicly warned about earlier | Other buyers may have remained unaware of infected devices |
Counterfeit USB Drives Are a Wider Supply Chain Risk
The military incident fits a broader pattern of counterfeit storage devices being sold online. These products often advertise unrealistic storage capacity at unusually low prices.
In some cases, counterfeit drives report fake capacity to the operating system while using much smaller internal storage. In more serious cases, as this incident shows, the device can arrive with malicious files already present.
The Nikkei investigation raises a larger question for defense agencies and private companies: whether their hardware purchasing rules can detect cheap, fake, and tampered devices before they reach operational networks.
How Organizations Should Respond
Organizations should stop treating removable media as low-risk office supplies. USB drives used in sensitive environments should come only from approved vendors, with documented procurement paths and device inventories.
Security teams should also scan and validate removable media on isolated systems before use. The drive should never move directly from a package or external source to a production, research, or classified environment.
CyberInsider also noted that buyers should avoid unusually cheap products from unknown sellers and validate storage capacity before deployment. Those steps can help detect counterfeit devices before they create a larger compromise.
- Buy storage devices only from verified vendors and approved procurement channels.
- Block unapproved USB storage on sensitive systems by default.
- Scan removable media on isolated machines before operational use.
- Validate advertised storage capacity before deployment.
- Log every connection between removable media and sensitive systems.
- Remove USB exceptions that bypass endpoint protection scans.
Why This Matters Beyond Japan’s Military
The incident shows how old attack methods can still bypass modern security when they exploit trust in physical hardware. A fake USB drive does not need to break through a firewall if someone connects it inside the network.
Factories, research labs, government offices, and defense contractors face the same type of risk. Many still use removable media to move files between isolated systems, test equipment, legacy machines, and secure networks.
The Defense Post report said several control systems stopped functioning as a result of the incident, although the SDF found no evidence of sensitive data leakage. That detail shows why even non-leak incidents can disrupt operations and trigger costly investigations.
What Buyers Should Watch For
Consumers and organizations should be cautious with USB drives that look too cheap for their advertised capacity. Very low prices, unknown sellers, unusual packaging, fake branding, and inconsistent storage behavior can all point to counterfeit hardware.
Businesses should also treat online marketplace reviews as a warning signal. Reports of files that cannot be deleted, strange drive behavior, unexpected executables, and fake capacity should trigger immediate rejection of the product.
The Edge Malaysia reported that Nikkei found similar complaints in Japan and the U.S. marketplace review data. That suggests the problem extends beyond one military incident and remains relevant to everyday buyers.
FAQ
Japan’s Ground Self-Defense Force reportedly used counterfeit USB drives infected with China-linked malware on computers connected to sensitive military networks for nearly a year before the malware was discovered in February 2025.
The malware was discovered after a computer at the JGSDF Middle Army headquarters in Itami, near Osaka, began running unusually slowly. A scan then found malware linked to a recently inserted USB drive.
The Self-Defense Forces said they found no evidence of system compromise or leakage of sensitive information. However, more than 50 computers had reportedly been connected to the infected drives, and some were tied to sensitive networks.
Counterfeit USB drives may advertise fake storage capacity, use low-quality parts, or arrive with malicious files already present. If connected to sensitive systems, they can bypass network defenses and introduce malware directly.
Organizations should buy removable storage only from approved vendors, block unapproved USB devices, scan media on isolated systems, validate storage capacity, and log every removable media connection to sensitive computers.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages