Japan's Ministry of Internal Affairs and Communications (MIC) opened a public comment period on July 22 that runs through August 4, 2026, on a draft proposal aimed at a specific kind of cybercrime infrastructure: home internet-of-things devices quietly turned into relay points for fraud. The draft, produced by a ministry study group on countering increasingly sophisticated cyberattacks, asks telecom carriers and internet service providers what role they should play in shutting the practice down.
The mechanism is straightforward once explained. Criminals plant unauthorized programs on home devices, video-streaming boxes are named specifically, that relay outside traffic through the household's own IP address. Because that address is one an ISP legitimately issued to a home user, security tools built to blacklist suspicious IPs largely wave the traffic through. The industry term for this is a 'residential proxy,' and the draft says the tactic has been recognized as cyberattack infrastructure since roughly 2020, drawing research attention from Japanese universities since then.
The numbers behind the push come from Japan's National Police Agency. Of 4,369 unauthorized online banking transfer fraud cases recorded in 2024, with total damage of about ¥8.69bn, at least 1,918 cases involved a residential proxy at the time of the crime. Those proxy-linked cases account for roughly 44% of all incidents, and the associated losses of about ¥2.89bn represent roughly 33% of total damage.
| Metric | Total (2024) | Residential-proxy-linked | Share |
|---|---|---|---|
| Fraud cases | 4,369 | at least 1,918 | 44% |
| Damage | ¥8.69bn | ¥2.89bn | 33% |
The draft also points to policing already underway. The National Police Agency issued a public warning in March 2025 about infected home PCs and IoT devices being used as stepping stones for crime, then followed with the 2024 fraud breakdown in March 2026, the same data now anchoring MIC's proposal. The document cites one overseas precedent it considers further along: Germany's Federal Office for Information Security notified device owners, working through ISPs, in December 2024 about devices infected with malware called 'Badbox' that had been functioning as residential proxies.
What happens next is procedural but has a firm date. MIC will collect comments in Japanese only, submitted through its e-Gov portal or by written form, until the August 4 deadline, and it does not commit to responding to submissions individually. After that, the ministry says it plans to publish a finalized version of the proposal reflecting the input it receives. The public comment guidelines spell out submission mechanics, including postal and electronic routes, but do not yet describe what obligations, voluntary or otherwise, ISPs and carriers would take on once the recommendations are finalized.
For now, the substance readers should note is the scale of the problem MIC is responding to: a fraud vector that, on the police's own accounting, already touches roughly a third of Japan's online banking fraud losses, routed invisibly through devices sitting in ordinary households.
