On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform, announced the (re)launch of #OpJapan, a DDoS campaign against Japanese entities. Motivation is cited as Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war.
NoName057(16) announcement of #Opjapan, August 24
A Recurring Campaign Against Japanese Organizations
NoName057(16) has targeted Japanese organizations multiple times since the war began, dubbing the attacks under the #OpJapan tag; the most recent prior instance ran in mid-February 2026, motivated by the deepening of Japan’s military cooperation with NATO and its support for Ukraine. In that February wave, NoName057(16) was not the only group involved: additional hacktivists joined the campaign with different motivations of their own – for example, BD Anonymous cited the Japanese government’s lack of support for Palestine. A similar pattern is repeating in the current campaign: Dark Storm Team, a pro-Palestinian hacktivist group with a documented history of joint operations with NoName057(16), joined this #OpJapan wave shortly after it was announced on August 24. Such coalition-building is a common hacktivist tactic, projecting an image of coordinated action and echoing each group’s publicity; further hacktivist groups may still join in the days ahead, following the same playbook.
Dark Storm Team taking part in #Opjapan, August 24
BD Anonymous taking part in the Feb. #Opjapan, February 16
Targets and Attack Activity
So far, NoName057(16) has publicly claimed on their Telegram channel to have carried out 66 attacks against 26 distinct Japanese organizations between August 24 and 30, backed by check-host.net links as proof. Targeting is concentrated across five sectors, with maritime/logistics and government portals being the most affected targets.
Technically, the campaign combines simple traffic floods with more targeted requests aimed at costlier site functions, such as search, contact forms, and login pages, rather than just the homepage, and it varies the details of each request to make the traffic harder to filter out automatically.
The majority of activity observed so far in this campaign has been DDoS attacks, with a single claimed intrusion to the video surveillance system of a commercial parking complex in Japan. This mirrors a claim from the February campaign, where the group similarly claimed access to a spa complex’s surveillance system. As in February, these breaches appear to be opportunistic, carried out against small- to medium-sized businesses when an exploitable vulnerability is identified, rather than planned, targeted intrusions. Moreover, no data theft, defacement, or backend compromise has been observed throughout this campaign.
Validate which exposures are exploitable in your environment with an Agentic Exposure Validation scan.
Since August 31, the group has posted no new Japan-specific claims, and activity has noticeably slowed. Its attention appears to have shifted to a new campaign, #OpEstonia, again citing support for Ukraine as motivation.
Campaign Outlook
As Japan strengthens its security cooperation with NATO and deepens its strategic engagement with Western nations, it is likely to face an increased risk of information disruption operations conducted by pro-Russian and other opportunistic or politically motivated hacktivist actors.
Such activity is expected to align with geopolitical developments, diplomatic milestones, and high-profile public statements, reflecting broader efforts to shape narratives and signal opposition to Japan’s evolving foreign policy posture.
Recommendations
- Confirm DDoS protection (cloud scrubbing, CDN, rate limiting/IP filtering) is active on all internet-facing domains and subdomains, as well as non-production/UAT/test environments
- Implement stricter timeout, connection-limit, and request-handling policies on web servers and reverse proxies. These controls can help defend against Slowloris-style denial-of-service attacks that attempt to monopolize available connection slots through numerous slow, persistent HTTP requests
- Apply caching and rate limits to computationally expensive endpoints specifically (search/filtered-query pages, form submissions, authentication APIs)
- Rate-limit high-traffic endpoints (login, search, API) and monitor for abnormal spikes from residential IP ranges, a signature of DDoSia’s volunteer-node model
- Maintain an incident response and communications plan for DDoS events, including a holding statement for customer- or public-facing outages
- Apply MFA and least-privilege access as standard hygiene on exposed portals; this campaign shows no intrusion follow-through to date, but the same baseline controls limit downstream risk
- Review access controls, default credentials, and internet exposure of building-management and IoT systems (CCTV, parking, access-control platforms).
About Check Point Exposure Management
Threat intelligence into campaigns such as #OpJapan helps security teams understand the adversaries and activity targeting their organizations. Check Point Exposure Management combines threat intelligence, exposure prioritization, Agentic Exposure Validation, and safe remediation to help teams identify relevant risks and move from visibility to remediation.
Ready to turn threat intelligence into action? Learn more about Check Point Exposure Management →


Leave A Comment