Kobe Steel and Pasco defence-contractor breaches (Japan, disclosed 2020)
What happened
In early February 2020 two Japanese defence contractors, Kobe Steel and Pasco, disclosed cyberattacks against their networks. The disclosures followed Japan's Ministry of Defense announcing that two unnamed contractors, in addition to Mitsubishi Electric and NEC, had been targeted, and Defense Minister Taro Kono's press conference of 31 January 2020. Pasco, Japan's largest geospatial services provider and a supplier of satellite imagery to the Ministry of Defense, detected unauthorised network access and malware infections in May 2018 and stated it had found no evidence that personal or business information had been exfiltrated. Kobe Steel, a supplier of submarine parts to the Japan Self-Defense Forces, disclosed two intrusions during which files may have been taken; the two retrieved sources give different dates for them, which is recorded rather than resolved. Both companies and the Ministry of Defense stated that no classified government information was compromised. The attacks on Mitsubishi Electric, NEC and Pasco are, in SecurityWeek's words, "believed to have been carried out by Chinese hackers", with Tick named as possibly involved in at least two of them.
The space nexus and the confirmed data loss are at different companies, and the record says so rather than blurring them. Pasco is the space-relevant party, as a supplier of satellite imagery to the Ministry of Defense, and Pasco reports no evidence that anything was exfiltrated. Kobe Steel is where files may have been taken, and Kobe Steel is a submarine-parts supplier. That is why both edges are low confidence and derived. The two sources also disagree on the Kobe Steel intrusion dates, BleepingComputer giving June 2015 and August 2016 and SecurityWeek giving August 2016 and June 2017, and neither is obviously the better witness; the disagreement is recorded and date_occurred is set to the one month both agree on, flagged uncertain. SPARTA cites this incident at REC-0008 and REC-0009; REC-0008 survives at low confidence and REC-0009 does not. Record confidence moved from low to moderate on 2026-08-18 under decisions entry 157, on the reading in docs/audits/2026-08-18-entry-148-confidence-value-audit.md: the account is established and what is missing is not the account. Entry 148 puts the actor and any one mapping outside this axis.
Attack vector
Not established. Unauthorised network access and malware infections are reported at Pasco; no cited source describes the initial access method at either company.
Operational impact
None reported against missions, spacecraft or defence systems. Both companies and the Ministry of Defense state that no classified government information was compromised.
Data compromised
Kobe Steel: files may have been stolen; BleepingComputer reports 250 files containing Ministry of Defense-related data and personal information, a figure SecurityWeek does not carry. Pasco: no evidence of exfiltration of personal or business information.
Affected segments
supply_chain
Disclosed
2020-02-06
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
EXF-0008 covers breaching development or integration environments at the mission owner, contractor or partner to reach documentation and configuration material. Both victims here are contractors, and Kobe Steel's disclosure is that files may have been stolen. The edge is derived because no cited source describes the compromised environments as development or integration environments rather than corporate IT, and low because the exfiltration itself is stated only as a possibility at Kobe Steel and is expressly not evidenced at Pasco. It is recorded rather than dropped because the contractor-as-route-to-customer-material shape is what the incident is, and dropping it would leave that unstated.
The adversary compromised two contractors to Japan's Ministry of Defense in a campaign that also reached Mitsubishi Electric and NEC, and at Kobe Steel files may have been taken, reported by BleepingComputer as 250 files containing Ministry-related data. REC-0008's subject is mapping the pathway by which hardware, software, data and people move to a customer, correlated with procurement artefacts and service contracts. Compromising suppliers and taking customer-related files is that activity as an outcome. The edge is derived and low: no cited source characterises the taken files beyond 'Ministry of Defense-related', both companies and the Ministry state no classified information was compromised, and the one company where files may have moved is a submarine-parts supplier rather than a space supplier.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
The technique the incident type most resembles by name, and the wrong one. SPARTA's IA-0001 is an Initial Access technique: achieving first execution on the spacecraft before it flies by inserting malicious code, data or configuration during manufacturing, integration or delivery. No cited source reports anything being inserted into a delivered product. These were intrusions to take information, not to plant it.
SPARTA scopes IMP-0006 to data gathered, processed and sent from the victim spacecraft. And here the theft itself is stated only as a possibility.
The only company with a space role is Pasco, which supplies satellite imagery to the Ministry of Defense, and Pasco is precisely the company that reports no evidence of exfiltration. The company where files may have moved supplies submarine parts. Mapping REC-0009 would require transferring the space relevance of one victim onto the data loss of the other.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
A source marked contradicting disputes the account above rather than supporting it. It is listed because a reader assessing this record should see it.
Tier 2: Established security trade press, named author, reporting the companies' own disclosures and the Ministry of Defense position.
Tier 2: Established security trade press, named author, published a day earlier. This is the URL SPARTA's own bibliography cites for this incident at two techniques.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.