Japan's J-Alert system exposed as vulnerable to counterfeit satellite messages
A flaw in Japan's nationwide emergency alert network could let forged data trigger false warnings, according to a cybersecurity specialist.
Japan's J-Alert emergency broadcast network, which disseminates warnings about earthquakes, tsunamis and overseas missile launches, does not encrypt satellite data nor authenticate its source, leaving it open to counterfeit alerts. Cybersecurity expert Yudai Kirishiki of Unknown Technologies Inc. found that the system's receivers lack electronic-signature verification and can be tricked by data formatted like genuine alerts, even when transmitted from drones or other high-altitude devices.
A Ministry of Internal Affairs and Communications source acknowledged the vulnerability, and a Civil Protection Office official declined to give details for security reasons but affirmed ongoing efforts to ensure reliable operation. The official also expressed regret over the appearance of used receivers on the second-hand market, noting that disposal instructions were provided to municipalities in late July. The flaw stems from the system's original design in 2007, when cyber threats to satellite communications were not anticipated, and it is used by agencies such as the Japan Meteorological Agency and the Cabinet Secretariat to relay alerts via TV, radio, smartphones and other channels.
Why it matters
A spoofed emergency alert could cause panic or disrupt daily life across Japan.
In this story
