PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Chinese Hackers Targeted Japan by Exploiting VPN Flaws

Japanese authorities say MirrorFace hackers have conducted over 200 attacks since 2019. China denies the allegations, and blames the US and its allies for spreading 'disinformation.'

 & Kate Irwin Reporter

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Credit: F01 Photo/Shutterstock.com)

Japan's National Police Agency (NPA) has tied over 200 cyberattacks from the last five years to the Chinese state-affiliated hacking group "MirrorFace," the agency announced this week.

The attackers are targeting national security and technology information, meaning they're espionage-related attacks. MirrorFace has targeted Japanese politicians, journalists, and its defense and foreign ministries. Some of these attacks were email phishing attacks, where the hackers used compromised email addresses to send malware disguised as an invitation to a panel to the potential victim. They used email subjects like "Russia-Ukraine war," "free and open Indo-Pacific," "Japan-US Alliance," or "Taiwan Strait," the Associated Press reports.

MirrorFace hackers also leveraged existing VPN flaws to target Japanese aerospace institutions as well as semiconductor firms to view private information, but it's unclear which VPN services were exploited.

Japan Aerospace and Exploration Agency (JAXA) is one of the organizations MirrorFace has targeted via VPN flaws. Of its 1,600 staff members, 207 saw their Microsoft 365 cloud accounts breached, including President Hiroshi Yamakawa and other executives, Nikkei Asia previously reported.

"The attacker seems to have exploited a vulnerability in the VPN to gain the initial access to some of JAXA’s internal servers and computers, further expanded the scope of unauthorized access to steal JAXA’s user account information, and used it to illegally access the information managed on JAXA’s Microsoft 365 service, posing as its legitimate user," Yamakawa said in a July press release, adding: "We have confirmed that some of the information managed by JAXA has leaked due to this cyberattack." The space agency said that hackers didn't get access to its data on rockets, satellites, or defense, though.

China's Foreign Ministry Spokesperson Guo Jiakun denied the NPA's allegations in a statement to the press on Thursday. "China firmly opposes and fights all forms of hacker attacks in accordance with law and opposes politicizing cybersecurity issues. This position is consistent and clear," Jiakun said.

"As many can see, the virtuality of cyberspace makes it difficult to trace the source of actions, and the actors in cyberspace are diverse. It is neither professional nor responsible for relevant Japanese institutions to make judgments based solely on the targets and methods of the hacking attacks," the spokesperson added.

The spokesperson also blamed "some allies of the US" as well as the US itself for "spreading disinformation" about China. "We hope that all parties will approach cybersecurity issues on the basis of facts, guided by international rules, and with objectivity, fairness, and professionalism rather than playing supporting roles in political stunts," Jiakun said.

Last week, the US sanctioned Chinese firm Integrity Tech for helping Flax Typhoon hackers conduct cyberattacks by facilitating a botnet of at least 260,000 compromised devices. And in December, the US Treasury Department said some of its computer systems and some unclassified documents were accessed by China-backed hackers, spurring the department to take its exposed systems offline.

About Our Expert

Kate Irwin

Kate Irwin

Reporter

I’m a reporter for PCMag covering tech news early in the morning. Prior to joining PCMag, I was a producer and reporter at Decrypt and launched its gaming vertical, GG. I have previously written for Input, Game Rant, Dot Esports, and other places, covering a range of gaming, tech, crypto, and entertainment news.

I’ve been a PC gamer since The Sims (yes, the original) in the CD-ROM days. I still think about my first-gen pink iPod mini, which, looking back, was not so mini. In 2020, I finally built my own custom Windows PC for gaming with a 3090 graphics card, but I also regularly use Mac and iOS devices. As a reporter, I’m passionate about documenting the wide world of tech and how it affects our daily lives.

My Areas of Expertise

  • Microsoft
  • Google
  • Artificial intelligence 
  • Cybersecurity
  • Video games are a big one. I specialize in shooters (Apex Legends, Fortnite, Overwatch) but I occasionally test out other genres as well, especially indie games or cozy games (The Sims series, Animal Crossing). 
  • The business and tech that powers video games
  • Cryptocurrency and blockchain technology
  • Social media platforms, including Meta’s apps, X/Twitter, Telegram, TikTok, etc.
  • Tech regulation

The Technology I Use

  • MSI gaming laptops
  • Nvidia graphics cards
  • AMD CPUs
  • MacBook Pro and Air laptops
  • An iPhone from 2019 (though I’m thinking about getting a “dumb phone” like the Light Phone)
  • Nintendo Switch
  • PlayStation 5
  • Freewrite Traveler 
  • At home: Sonos speakers (we have them all over the house), Philips Hue + Ring security products

Read full bio