Researcher finds fake data could trigger Japan’s national emergency alert system

Japan’s nationwide J-Alert emergency warning system lacks encryption and a mechanism to authenticate the source of data transmitted via satellite, creating the potential for specially crafted fake data to trigger false emergency alerts, according to a Kyodo News report.

Yudai Kirishiki of Tokyo-based cybersecurity firm Unknown Technologies identified the issue after analyzing a J-Alert receiver previously used by a local government that was sold on the secondhand market. Testing found that the receiver could not distinguish fake information formatted like legitimate J-Alert data, demonstrating that a third party could potentially transmit a false warning.

J-Alert distributes urgent information about earthquakes, tsunamis, ballistic missile launches and other emergencies from government agencies via satellite to receivers operated by municipalities and other public organizations.

A source at Japan’s Ministry of Internal Affairs and Communications acknowledged the security issue, while an official said the government continues to work to ensure stable operation of the system.

ㅤLarry Pesce, VP of Services, Finite State:

“Two things in this J-Alert story jump out. First, the claim that satellite attacks “weren’t considered a real threat” in 2007. Brazilian pirates had been hijacking US Navy satellite transponders for decades by then, and Captain Midnight took over HBO’s satellite feed in 1986. Unauthenticated satellite traffic being spoofable was not a new idea.

“Second, and more important: the researcher got a decommissioned receiver off the secondhand market. Disposal instructions went out after the fact. Once an adversary has the hardware, “we can’t share details for security reasons” stops being a control. They can pull the firmware, reverse the protocol, and test spoofed alerts against the real parser until it works. This is supply chain and lifecycle risk in its plainest form: sensitive hardware will leave your control, so design as if it already has.

“The fix here isn’t exotic. Public alerts don’t need to be secret, they need to be signed. Receivers that verify the source would make a drone and a stolen receiver far less useful. For a system that can move an entire population, that should have been in the original design.

“Once a decommissioned receiver shows up for sale, the government’s decision not to share details ‘from a security standpoint’ stops meaning much. An attacker with the hardware in hand can extract the firmware, reverse engineer the protocol, and test fake alerts against the real thing until one works. Sensitive hardware will eventually leave your control, so you have to design as if it already has.”

“Re authentication: public emergency alerts don’t need to be secret, they need to be trustworthy. A receiver that can’t verify who sent a message will believe anyone with a transmitter. Digital signatures are a well-understood fix. Leaving them out of a system that can move an entire population was a design choice, not a technical limitation.

“The problem isn’t that J-Alert is unencrypted. It’s that it can’t tell the government’s warning from anyone else’s.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“A satellite link delivers data. It does not prove who sent it. If a receiver validates only the packet format, an attacker can impersonate the system from the ground.

“Japan’s J-Alert system exposes that gap. Kyodo reported that data sent through its satellite channel is unencrypted, and the receiver has no way to verify its source. Yudai Kirishiki of Unknown Technologies tested a receiver formerly used by a local government and found no electronic signature checks. The receiver accepted J-Alert-formatted data transmitted from an elevated location, such as a drone.

“Brazil had its own emergency-alert failure in June, when credentials tied to two Pará Civil Defense agents were used to send false alerts through the national platform to areas those accounts were not authorized to reach.

ㅤJapan and the rest of the world needs to figure this out. Unencrypted communications in 2026 are bad and need to be killed off quickly. Because this is a horrible place to be in.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading