JAXA and ~200 Japanese organisations targeted by Tick (2016-2017, attributed 2021)
What happened
On 20 April 2021 the Tokyo Metropolitan Police Department referred a Chinese systems engineer in his thirties, a member of the Chinese Communist Party, to prosecutors over alleged involvement in cyberattacks against the Japan Aerospace Exploration Agency (JAXA) and around 200 other Japanese companies and research institutions in 2016 and 2017. Investigators found that the suspect had contracted for rental servers in Japan under a false name, and that those servers were used in the attacks on JAXA in 2016; the suspect had left Japan by the time of the referral. Police attributed the campaign to the group tracked as Tick, also called BRONZE BUTLER and STALKER PANDA, operating under the direction of the People's Liberation Army, and on 23 April 2021 the commissioner-general of the National Police Agency said it was highly likely that the PLA's Unit 61419, based in Qingdao, was involved. FireEye characterises Tick as targeting the defence, heavy industry and aerospace sectors for theft of sensitive intellectual property. No cited source states what, if anything, was taken from JAXA.
One edge, and it is about the adversary's infrastructure rather than about JAXA. The best-documented fact in this case is the one the criminal referral itself rests on: servers rented in Japan under a false name and used in the 2016 attacks. What was taken from JAXA is not stated by any source cited here, so the three Reconnaissance techniques SPARTA's bibliography attaches to this incident are rejected on the record rather than mapped. Note the date range: the intrusions are placed in 2016 and 2017, and 2021 is the year of the referral and the attribution, not of the activity. Distinct from the separate JAXA intrusion disclosed in 2023, which is not covered here. SCOPE UNDETERMINED, recorded 2026-08-22. Whether this record belongs in this corpus has not been established. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path; the victim being a space agency is expressly not the test. What the sources establish is the adversary's own infrastructure, servers rented in Japan under a false name and used in the 2016 attacks, and a campaign against JAXA alongside around 200 other Japanese companies and research institutions. What no cited source establishes is what the activity reached inside JAXA, and no cited source states that it reached only administrative or general research systems either, so the question is open in both directions. A source naming a mission network, ground station, tracking system, spacecraft operations network, or spacecraft design, telemetry or command data would settle it one way; a source stating that the activity reached only corporate or general research systems, or that no intrusion succeeded, would settle it the other. The likely places to look are the Japanese-language National Police Agency and Tokyo Metropolitan Police statements of 20 and 23 April 2021, JAXA's own statement, and technical reporting on the Tick group that identifies the victim environment. A Japan Times report of 20 April 2021 that SPARTA's bibliography cites at three techniques is recorded as not retrieved and has not been retried. The record stays published while the question is open, under decisions entry 189.
Attack vector
Rental servers in Japan contracted under a false identity, used as attack infrastructure against JAXA in 2016. The intrusion method against JAXA's own systems is not described by any cited source.
Operational impact
None reported. No cited source describes an effect on JAXA missions, spacecraft or operations.
Data compromised
Not established. Police described the targeting; no cited source states what was obtained from JAXA.
Disclosed
2021-04-20
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
Police investigators found that the suspect contracted for rental servers in Japan under a false name and that those servers were used in the 2016 attacks on JAXA. RD-0001's own description names 'network presence (leased ASNs/IP space, VPS fleets, CDN relays)' and 'identity fabric (burner accounts, domains, certificates)', and says adversaries favour assets that are inexpensive, deniable and geographically diverse. Renting servers inside the target country under a false identity is that technique described rather than inferred, and it is the single fact the criminal referral itself was built on.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
The referral concerns the fraudulent server contracts and the intrusions. No cited source confirms exfiltration from JAXA. An espionage actor's presence is not a completed theft.
The near neighbour of the accepted edge, and the wrong one. SPARTA distinguishes RD-0002 as compromising existing infrastructure rather than purchasing or renting. These servers were rented, under a false identity but through a commercial contract.
FireEye's characterisation of Tick as an IP-theft actor in aerospace establishes targeting intent, not outcome. No cited source says any spacecraft design artefact was obtained from JAXA. Intent is not a mapping.
Nothing in the police account or the trade reporting describes supply-chain mapping. Around 200 organisations is a breadth of targeting, not an enumerated supply chain, and no source connects the other targets to JAXA's.
Same defect as REC-0001: no cited source states what was accessed at JAXA.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
Tier 3: Trade press consolidating the NHK and Kyodo reporting of the police referral, plus FireEye and ESET characterisations of Tick. Not a first-hand account of the police statement.
Tier 2: National English-language daily of record for Japan. SPARTA's own bibliography cites this URL at three techniques.
Tier 2: Established regional business daily reporting the police action on the day it was taken. Independent of the Insurance Journal chain.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.