Japan takes a month of hacktivist DDoS and real breaches

Published

Three hacktivist crews spent August pointing at the same country. Japanese government agencies, local authorities and companies in transport, finance and shipbuilding were all named as targets of claimed denial of service attacks, which work by flooding a website with enough junk traffic to knock it offline. The crews were NoName057(16), Dark Storm Team and a group calling itself BD Anonymous, according to the August threat actor review published by AhnLab's ATCP team.

Claimed is the operative word. These crews announce their own results, and a website that is slow for an hour looks identical to a website that was never attacked at all.

Three crews, one target country

BD Anonymous widened the target list beyond the usual government portals to museums, cultural foundations and police-related sites. Dark Storm Team claimed a similar spread across Japanese government agencies and financial institutions. A Norwegian public digital services agency was also named as a target during the month, which is a reminder that these campaigns move by political weather rather than by sector.

Denial of service is the cheapest thing a crew can do and the easiest to publicize, so volume here is not a measure of capability. It is a measure of attention. What matters is what else was happening in Japan while the attention was on the outage claims.

The hosting breach with the longest reach

Unauthorized access was confirmed against hundreds of rental server accounts at major Japanese internet infrastructure and hosting providers, and the disclosure indicated the potential impact could extend to as many as several million accounts. That is the incident in this report with real downstream consequences, because every one of those accounts belongs to somebody else's website.

Elsewhere in Japan, a global insurance company headquartered there disclosed that customer data may have been exposed through a vulnerability in its file transfer software, a Japanese IT services company opened an investigation into unauthorized access, and a major Japanese media outlet warned that contact details may have leaked after accounts were taken over. Japan has been a steady target for quieter operations as well, including the APT-C-60 espionage campaign that hid its traffic inside developer platforms. Our Japan country profile tracks the wider picture.

The same month, elsewhere

In the United Kingdom, a small power plant was attacked by hackers linked to Iran, and operations were disrupted for several days. In the United States, a global medical and pharmaceutical distributor disclosed a cyber incident, and a global apparel manufacturer said corporate information was taken after employee devices were compromised through social engineering. In Singapore, a virtual asset wallet service confirmed that customer order information was reached through an authentication flaw in its order tracking system, and a hardware wallet manufacturer disclosed a customer data breach that originated at a logistics company it used.

Recruiting on one side, arrests on the other

The extortion economy kept hiring. Rootor advertised for initial access providers on a dark web forum, Eclipse promoted a Windows ransomware-as-a-service affiliate program, and Storm and Panzer continued recruiting affiliates and network intrusion specialists. ATCP also records a claim that the operator behind the LockBitSupp persona was identified as a specific individual whose role differs from that of previously known figures, which remains an unverified claim rather than a confirmed identification.

Law enforcement had a month too. Two members of a supply chain attack group were arrested, the US Department of Justice and FBI seized infrastructure used by a China-linked state-sponsored group, INTERPOL made a large set of arrests against an organized crime network in West Africa, and a ransomware operator received a lengthy prison sentence. Defenders reading a month like this should weigh the hosting provider compromise far above the outage claims, because one of them changes who can reach your systems and the other only changes who can see your homepage.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions