Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フ

Japan's day, wrapped and delivered by morning.

Policy Watch

Japan Drafts Rule for Police to Email Firms After Acting on Attacking Computers

A National Police Agency proposal would require officers to notify the administrator of any computer used to attack "critical" systems by email, disclosing its IP address and what was done, but only after the intervention is already over.

Jul 24, 20262 min read
A server rack with one cable disconnected and tagged, illustrating a computer isolated after a law-enforcement cyber intervention.

Japan's National Police Agency has opened public comment on a rule that decides how, and how much, police tell you after they have acted on your servers.

The draft, published July 24, 2026, sets out the notice police must send once they use new authority to act against a computer identified as the source of an attack on what the underlying law calls a "critical computer". That authority itself is not new. It came from a 2025 law, Law No. 43, which added Article 6-2 to the Police Duties Execution Act and created "cyber harm prevention officers" empowered to carry out "cyber harm prevention measures" against attacking machines. What has been missing until now is the mechanics of telling the administrator of that machine what just happened to it.

Under the draft, officers must notify the administrator by email, or by an unspecified alternative method, with four required items.

What Police Must Disclose to Administrators
Draft rule implementing Article 6-2, Paragraph 8 of the Police Duties Execution Act.
Required itemWhat it covers
Date of actionThe date the cyber harm prevention measure was taken
Computer identifierThe IP address or other information identifying the computer used in the attack
Action summaryAn outline of the cyber harm prevention measure carried out
Responsible unitThe police unit to which the officer who took the measure belongs

Notice arrives after the intervention, not before it. The rule contains no requirement to warn an administrator in advance or to seek consent.

The draft also creates an internal reporting duty. Under its Article 3, the director of the Kanto Regional Police Bureau must promptly report to the National Police Agency's Commissioner-General whenever the bureau judges a cyber harm prevention measure is needed. The definitions section separately references a "request for approval" and a "recommendation" tied to other paragraphs of Article 6-2, which suggests the notification duty sits inside a wider approval and advisory structure that this excerpt does not fully spell out.

For companies running servers, cloud instances, or connected devices in Japan, the practical point is straightforward: a machine hijacked for use in an attack, even unknowingly, can be acted on by police first and explained by email second. The rule does not touch liability for running a compromised system. It only fixes what police must disclose once they have already stepped in.

Comments are open through August 22, 2026, submitted via the e-Gov comment form, by email to [email protected] with "パブリックコメント" in the subject line, or by post to the National Police Agency's Cyber Police Bureau, Cyber Planning Division, in Chiyoda-ku, Tokyo. The draft carries the signature of National Public Safety Commission Chairman Jiro Akama.