# Japan-Britain Cybersecurity Cooperation Agreement Amid China Concerns

> The Japan-Britain Cyber Partnership Agreement establishes a bilateral cybersecurity cooperation framework between two of the world's leading cyber powers, creating mutual defense obligations, intelligence sharing protocols, and coordinated incident response capabilities. Signed as an extension of the 2023 Hiroshima Accord and the UK-Japan Reciprocal Access Agreement (RAA), this agreement formalizes: (1) real-time cyber threat intelligence sharing between NCSC (UK) and NISC/JPCERT (Japan); (2) coordinated attribution and public naming of state-sponsored cyber actors; (3) joint cyber exercises and workforce development; (4) supply chain security cooperation targeting shared vendor ecosystems; (5) critical infrastructure protection alignment across energy, financial, telecommunications, and transportation sectors; and (6) mutual assistance during significant cyber incidents. The agreement represents a strategic response to escalating threats from China (APT10, APT31, APT40), Russia (Sandworm, Fancy Bear), and North Korea (Lazarus Group) targeting both nations' critical infrastructure and defense industrial base.

- **Published:** 2026-02-03T04:25:00Z
- **Last reviewed:** 2026-02-03T04:25:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0049
- **ID:** TL-2026-0049
- **Severity:** LOW
- **Category:** POLICY
- **Status:** MONITORING
- **Detections:** 10 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The Japan-Britain Cyber Partnership is a STRATEGIC GOVERNANCE agreement that strengthens the defensive posture of both nations against shared adversaries. Unlike technical threats in this database, TL-0049 represents a DEFENSIVE CAPABILITY ENHANCEMENT — it reduces risk rather than creating it.

**Strategic Context:**

Japan and the United Kingdom share critical geopolitical positioning:
- Both face persistent cyber campaigns from China, Russia, and North Korea
- Both maintain significant defense industrial bases targeted by espionage
- Both are members of intelligence-sharing networks (UK: Five Eyes; Japan: expanding bilateral partnerships)
- Both experienced major cyber incidents driving policy evolution:
  - UK: SolarWinds, NHS WannaCry ($100M+ impact), Russian election interference
  - Japan: MHI/JAXA breaches (APT10), Mitsubishi Electric hack, Tokyo Olympics targeting

**Agreement Components:**

1. **Threat Intelligence Sharing**
   - Real-time exchange of cyber threat intelligence between NCSC (UK National Cyber Security Centre) and NISC (Japan's National Center of Incident Readiness and Strategy for Cybersecurity) / JPCERT/CC
   - Structured sharing via STIX/TAXII formats for automated ingestion
   - Classified intelligence sharing under existing security agreements
   - Joint analysis of APT campaigns targeting both nations

2. **Coordinated Attribution**
   - Bilateral agreement to publicly attribute state-sponsored cyber operations
   - Joint attribution statements carry greater diplomatic weight than unilateral
   - Historical precedent: UK-Japan joint statements on APT10 (Cloud Hopper), APT31, APT40
   - Diplomatic coordination with Five Eyes and Quad partners

3. **Incident Response Cooperation**
   - Mutual assistance protocol during significant cyber incidents
   - Shared incident response playbooks for critical infrastructure sectors
   - Cross-deployment of cyber response teams during major incidents
   - 24/7 coordination channel between national CERTs

4. **Supply Chain Security**
   - Joint assessment of shared vendor ecosystems (semiconductor, telecommunications, cloud)
   - Coordinated vendor security requirements for defense procurement
   - Alignment on 5G/6G network security standards (excluding high-risk vendors)
   - Shared approach to securing submarine cable infrastructure

5. **Critical Infrastructure Protection**
   - Alignment of protection standards across energy, finance, telecom, and transport
   - Joint exercises simulating attacks on interconnected infrastructure
   - Shared best practices from UK's NIS Regulations and Japan's Cybersecurity Basic Act
   - Cross-sector incident notification protocols

6. **Workforce and Capacity Building**
   - Joint cyber exercises (expanding Japan's participation in NATO CCDCOE exercises)
   - Cybersecurity workforce exchange programs
   - Academic research collaboration on AI-enhanced cyber defense
   - Joint training on emerging threats: AI-powered attacks, quantum computing risks

**Adversary Context:**

The agreement directly addresses shared threat actors:

- **China (APT10/Cloud Hopper, APT31, APT40)**: Both nations' defense contractors, government agencies, and technology firms are persistent targets. APT10's Cloud Hopper campaign targeted managed service providers in both countries simultaneously. Japan's geographic proximity and UK's intelligence role make both priority targets.

- **Russia (Sandworm, Fancy Bear/APT28, Turla)**: UK is a primary Russian cyber target (Salisbury/Novichok response, election interference, NotPetya). Japan faces Russian cyber operations in the context of Northern Territories/Kuril Islands dispute and sanctions enforcement. Shared intelligence on Russian TTPs strengthens both nations.

- **North Korea (Lazarus Group/APT38)**: DPRK cyber operations target both nations for financial theft (cryptocurrency, banking) and espionage. Japan faces unique DPRK threat due to geographic proximity and abduction issue. UK financial sector targeted by Lazarus. Connects directly to TL-0027 ($158B illicit crypto).

**Impact Assessment:**

The agreement STRENGTHENS defensive posture by:
- Reducing intelligence blind spots through bilateral sharing
- Increasing adversary cost through coordinated attribution
- Improving incident response speed through pre-established protocols
- Harmonizing standards to eliminate exploitable gaps between allies
- Building workforce resilience through joint training

The agreement also carries RISKS:
- Intelligence sharing requires trust infrastructure that takes years to build
- Classification barriers may slow real-time sharing
- Operational security risks from broader sharing (more endpoints = more leak vectors)
- Diplomatic constraints may limit attribution speed
- Implementation gap between agreement signing and operational capability

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1596 Search Open Technical Databases
- T1584 Compromise Infrastructure
- T1587 Develop Capabilities
- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1003 OS Credential Dumping
- T1021 Remote Services
- T1005 Data from Local System
- T1039 Data from Network Shared Drive
- T1041 Exfiltration Over C2 Channel
- T1485 Data Destruction

## Sources

- [UK Government — Cyber Partnerships](https://www.gov.uk/)
- [NCSC (UK)](https://www.ncsc.gov.uk/)
- [NISC (Japan)](https://www.nisc.go.jp/eng/)
- [JPCERT/CC](https://www.jpcert.or.jp/english/)
- [UK-Japan Hiroshima Accord](https://www.gov.uk/government/publications/uk-japan-hiroshima-accord)
- [CISA International Cooperation](https://www.cisa.gov/topics/international-cooperation)
- [NATO CCDCOE](https://ccdcoe.org/)
- [Mandiant APT10 Analysis](https://www.mandiant.com/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0049
