Skip to content
safemode.space
All incidents
2012-11-21 (approximate)
data exfiltration

JAXA launch-vehicle data theft by malware (2011-2012)

Confidence in this reading:
high

What happened

Two malware incidents at the Japan Aerospace Exploration Agency became public within eleven months of each other. On 13 January 2012 JAXA disclosed that a virus had been found on a computer used in H-II Transfer Vehicle development work; its investigation results, published on 27 March 2012, record that the infection arrived by email on 6 July 2011 to an employee who had not updated the computer's office software, that data stored on and displayed by that computer and the system log-in information accessed from it may have leaked along with roughly 1,000 email addresses, that no classified information was involved, that no unauthorised access followed, and that no sensitive H-II Transfer Vehicle specification or operations data was searched or displayed while the computer was infected. On 21 November 2012 malware was found on a computer at JAXA's Tsukuba Space Center which was collecting data and transmitting it outside the agency; JAXA reported that the material concerned the Epsilon rocket then due to launch in 2013, its predecessor the M-V, and the H-IIA and H-IIB launch vehicles, and included engine specifications, agency meeting notes and operational protocols. The computer was disconnected from the local network on discovery. JAXA could not determine how much data left the network before detection, and could not confirm whether the infection was incidental or the result of a directed attack.

Two events recorded together because they are the same failure at the same organisation eleven months apart, and because JAXA's own investigation into the first is the document that bounds the second. The prior batch's gap analysis assessed this incident as 'thin: one trade-press source in the bibliography' and recommended independent sourcing before a record was built. That condition is now met: JAXA's own published investigation results are the primary source, and three independent secondary accounts corroborate the November 2012 discovery. The important discipline here is that JAXA's statement bounds the claims in both directions. It records what may have leaked and it records what did not, and the record follows it on both. What is NOT evidenced anywhere is any effect on a vehicle, a mission or a ground system; these were office and development machines.

Attack vector

For the 2011 infection, an email carrying a new virus sent on 6 July 2011 to an employee whose office software was not up to date. For the November 2012 infection, the delivery route is not stated by any cited source.

Operational impact

None reported against flight systems or missions. The infected machines were office and development computers; the November 2012 machine was disconnected from the local area network on discovery.

Data compromised

November 2012: data on the Epsilon, M-V, H-IIA and H-IIB launch vehicles including engine specifications, agency meeting notes and protocols, collected and transmitted outside the agency, with the volume that actually left undetermined. 2011 infection: information stored on and displayed by one computer, its system log-in information, and approximately 1,000 email addresses; JAXA states no classified information was included and no sensitive H-II Transfer Vehicle data was searched or displayed.

Affected segments

ground, launch

Disclosed

2012-11-30

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • JAXA's own investigation establishes malware on the January 2012 Tsukuba terminal, and the November 2012 case is malware collecting and transmitting launch-vehicle data by name. Adversary-introduced executable logic ran on victim systems and acted on them. Recovered per decision 67: previously rejected only because SPARTA's EX-0010 names the vehicle and these were office and development desktops. The EXF-0007 rejection on this record is not recovered: EXF-0008 already carries the same exfiltration, and mapping both would record one act twice.

    https://www.securityweek.com/japans-space-agency-hacked-rocket-data-boosted-malware/

  • EXF-0008 is the one exfiltration technique SPARTA scopes to development and integration environments rather than to mission ground infrastructure: breaching them 'at the mission owner, contractor, or partner' to reach documentation, configuration data and engineering material. Both infections here sit in exactly that place. The 2011 infection was on a computer used in H-II Transfer Vehicle development work, and the November 2012 machine at Tsukuba held launch-vehicle engineering material that the malware transmitted out of the agency. Confidence is moderate because JAXA states it could not determine how much data actually left the network before detection, so the exfiltration is established as behaviour but not as volume.

    https://www.spacesafetymagazine.com/aerospace-engineering/cyber-security/epsilon-rocket-data-stolen-hackers/

  • The November 2012 malware was collecting and transmitting data on four launch vehicles by name, the Epsilon, the M-V, the H-IIA and the H-IIB, including engine specifications. REC-0004's subject is structured launch intelligence, and it names the vehicle family and configuration among the elements adversaries collect. The behaviour is described by JAXA's statement as reported, not inferred from an outcome, and the vehicles are named individually.

    https://www.securityweek.com/japans-space-agency-hacked-rocket-data-boosted-malware/

  • Alongside the engine specifications, the exfiltrated material included agency meeting notes and operational protocols. REC-0009's subject is a CONOPS-level portrait of the mission, and it names mode logic, operational constraints and contingency concepts among the things adversaries extract; internal meeting records and protocols are that class of material. Confidence is moderate rather than high because no source characterises the meeting notes or protocols beyond those two words, so the fit rests on the category rather than on the content.

    https://www.securityweek.com/japans-space-agency-hacked-rocket-data-boosted-malware/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • The near neighbour of the accepted EXF-0008 edge. EXF-0007 requires residence in mission ground infrastructure: operator workstations, mission control servers, baseband chains, telemetry pipelines, archive databases. The compromised asset is described as a desktop holding engineering documents, and nothing places the malware in a telemetry or command path. Re-evaluated under decision 67 and held, on a ground that survives the ruling: EXF-0008 already carries this exfiltration, and mapping both would record one act twice.

  • SPARTA writes IMP-0006 as theft of data "gathered, processed, and sent from the victim spacecraft". What was taken is pre-flight engineering documentation. EXF-0008 carries the exfiltration without stretching an Impact technique past its stated subject.

  • Two reasons. The November 2012 material is launch-vehicle data, and SPARTA gives launch vehicles their own technique in REC-0004; mapping both would double-count one body of material. And the genuinely spacecraft-side thread, the HTV development machine, is the one JAXA's own investigation closes: it states no sensitive HTV specification or operations data was searched or displayed. Mapping REC-0001 would contradict the primary source.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.