Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フ

Japan's day, wrapped and delivered by morning.

Policy Watch

Japan's Telecoms Ministry Opens Comment Window on Home-Device Fraud Proxies

Hijacked home IoT gadgets routed at least 1,918 of Japan's 4,369 online banking fraud cases in 2024, and the ministry now wants internet providers to help close the gap before comments close on August 4.

Jul 22, 20263 min read
Editorial illustration of a home router and streaming device linked by cables to a wall junction box, with abstract glowing lines representing internet traffic flowing outward toward a network cloud.

Japan's Ministry of Internal Affairs and Communications (MIC) opened a public comment period on July 22 that runs through August 4, 2026, on a draft proposal aimed at a specific kind of cybercrime infrastructure: home internet-of-things devices quietly turned into relay points for fraud. The draft, produced by a ministry study group on countering increasingly sophisticated cyberattacks, asks telecom carriers and internet service providers what role they should play in shutting the practice down.

The mechanism is straightforward once explained. Criminals plant unauthorized programs on home devices, video-streaming boxes are named specifically, that relay outside traffic through the household's own IP address. Because that address is one an ISP legitimately issued to a home user, security tools built to blacklist suspicious IPs largely wave the traffic through. The industry term for this is a 'residential proxy,' and the draft says the tactic has been recognized as cyberattack infrastructure since roughly 2020, drawing research attention from Japanese universities since then.

The numbers behind the push come from Japan's National Police Agency. Of 4,369 unauthorized online banking transfer fraud cases recorded in 2024, with total damage of about ¥8.69bn, at least 1,918 cases involved a residential proxy at the time of the crime. Those proxy-linked cases account for roughly 44% of all incidents, and the associated losses of about ¥2.89bn represent roughly 33% of total damage.

2024 online banking fraud: residential-proxy share
Figures are National Police Agency data as cited in MIC's draft proposal; the 1,918-case figure is described as a minimum.
MetricTotal (2024)Residential-proxy-linkedShare
Fraud cases4,369at least 1,91844%
Damage¥8.69bn¥2.89bn33%

The draft also points to policing already underway. The National Police Agency issued a public warning in March 2025 about infected home PCs and IoT devices being used as stepping stones for crime, then followed with the 2024 fraud breakdown in March 2026, the same data now anchoring MIC's proposal. The document cites one overseas precedent it considers further along: Germany's Federal Office for Information Security notified device owners, working through ISPs, in December 2024 about devices infected with malware called 'Badbox' that had been functioning as residential proxies.

What happens next is procedural but has a firm date. MIC will collect comments in Japanese only, submitted through its e-Gov portal or by written form, until the August 4 deadline, and it does not commit to responding to submissions individually. After that, the ministry says it plans to publish a finalized version of the proposal reflecting the input it receives. The public comment guidelines spell out submission mechanics, including postal and electronic routes, but do not yet describe what obligations, voluntary or otherwise, ISPs and carriers would take on once the recommendations are finalized.

For now, the substance readers should note is the scale of the problem MIC is responding to: a fraud vector that, on the police's own accounting, already touches roughly a third of Japan's online banking fraud losses, routed invisibly through devices sitting in ordinary households.