TRAFEED

Typical Export Control Violations | From Toshiba-COCOM to Recent Russia Cases, Prevention Read Through METI's FY2024 Data

Published2026-04-24Updated2026-07-19濱本 隆太

From the 1987 Toshiba Machine COCOM case to recent illicit exports to Russia, this article organizes Japanese corporate export control violations chronologically. For practitioners, we explain the new violation structure revealed by METI's FY2024 data (skipped classification and false assumptions now the top cause, structural deficiencies expanding, and 60% of cases surfacing through customs post-clearance audits), along with prevention measures grounded in the shift to unified imprisonment penalties and the expansion of the Foreign End User List to 835 entities.

Typical Export Control Violations | From Toshiba-COCOM to Recent Russia Cases, Prevention Read Through METI's FY2024 Data
シェア

Hello, this is Hamamoto from TIMEWELL. Today I want to walk chronologically through the export control violations that Japanese companies have committed over the years — all the way up to the "single most dangerous pattern right now" that METI's latest data reveals — and think together about what your own organization should take from them for its risk management.

"We don't make weapons or military equipment, so this doesn't apply to us." To any executive or corporate management professional who thinks this way, there is something I want to say emphatically. Most of the companies that ended up committing violations held exactly the same view at first. Machine tools, industrial helicopters, measurement instruments — even the engine of a jet ski — can one day suddenly be treated as dual-use goods (items usable for both civilian and military purposes), and a practitioner's momentary lapse in judgment can result in the company receiving a ban on exporting all of its goods. This is not a story about the past; it is a reality that is still unfolding right now.

What's more, the most common cause of violations today is no longer "getting the classification wrong." In the latest analysis METI published in December 2025, "not classifying at all, or assuming the item was non-controlled" became the single largest cause on its own. If you want to grasp, in a short time, how much risk is hidden in your own export transactions, start by taking stock of where you stand with our Export Control Compliance Check. In this article, after organizing chronologically from the 1987 Toshiba Machine COCOM incident to the recent illicit exports to Russia, I dig into the new risk structure that the FY2024 data brings into focus, and into prevention measures grounded in the 2025 regulatory tightening.

The Lessons Left by the Toshiba Machine COCOM Incident (1987)

In any account of the history of export control violations, the Toshiba Machine COCOM violation is impossible to skip. Between December 1982 and 1984, Toshiba Machine, working through a trading house, exported high-performance machine tools capable of simultaneous nine-axis control, along with NC units and dedicated software, via Norway to a Soviet machinery import organization. All of these were items embargoed under COCOM (the Coordinating Committee for Multilateral Export Controls).

At the end of 1986, a report by an employee of the trading house involved brought the situation to the attention of the US side. The US Department of Defense concluded that these machine tools had contributed to quieting the propellers of the Soviet Navy's attack nuclear submarines, and the incident escalated into a serious political issue between Japan and the US. On April 30, 1987, the Public Security Bureau of the Metropolitan Police Department carried out a search; on May 15, the Ministry of International Trade and Industry (now METI) handed down an administrative order suspending exports to the communist bloc for one year; and on May 27, two executives were arrested for violating FEFTA. In the US Congress, lawmakers staged a demonstration smashing a Toshiba radio-cassette player with hammers, and a bill was even introduced to restrict Toshiba's access to US government procurement.

This case is still cited as a lesson today because, within a multi-layered transaction structure involving a manufacturer, a trading house, and a transit country, verification of the true end user of the destination did not function adequately. Such multi-layered transaction forms — which are not a judgment on any company's rights or wrongs — remain instructive today as a factor that makes end-user screening difficult. The reason METI repeatedly instructs companies to "verify the true end user of the destination" is that this is the greatest lesson from this case. And there is one more thing not to overlook: the fact that an internal report became the trigger for the case coming to light. Where more than one person is involved, there is a limit to containing risk through confidentiality alone. Compliance is not something protected by confidentiality; it is protected by a structure that keeps violations from happening in the first place. This case taught us that 40 years ago.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

A Case From the 2000s: Unlicensed Export of an Industrial Unmanned Helicopter and Classification

A case that drew major coverage in 2006 concerned the export of the industrial unmanned helicopter "RMAX Type II G" to a company in China. An industrial unmanned helicopter falls into a category of items usable for both civilian and military purposes, and the issue was that the contract moved forward before the destination and end use had been sufficiently confirmed. The destination was a company in Beijing, and by 2005 the contract was moving forward without an export license having been obtained. The origin of the case lay in an unexpected place. In April 2005, when Fukuoka Prefectural Police cracked down on two Chinese intermediaries on suspicion of aiding illegal employment, documents on the unmanned helicopter export were seized from related parties. It surfaced not through the export control function but by being traced, chain-like, from a separate criminal case.

In January 2006, Shizuoka and Fukuoka prefectural police conducted a joint search, and in January 2007 three employees were referred to prosecutors (with the indictment ultimately suspended). Yamaha Motor as a legal entity received a summary order from the Hamamatsu Summary Court to pay a fine of JPY 1 million, and in May of the same year METI imposed an administrative order of a nine-month export ban. The day after the reports, Yamaha Motor's share price hit its limit-down. Even with a fine of JPY 1 million, the economic sanction handed down by the market was on an entirely different scale.

The reason this case is repeatedly cited when thinking about internal control is that it shows how an operation that depends on a small number of staff for "classification" — the determination of whether goods or technology fall under the control list, and thus whether the approval of the Minister of Economy, Trade and Industry was required for the export — is a risk that can arise at any manufacturing company. A structure in which, without layered review, delivery-deadline pressure from the sales side flows straight through to the classification is not something limited to any particular company. Even for a product that could clearly be judged dual-use, such as an unmanned helicopter, a single practitioner's interpretation could lead to the conclusion "this is for civilian use, so it's fine." The same pattern lurks in nearly every manufacturing company. The moment you hear the words "our classification lead is excellent, so we're fine," you should regard that itself as a danger signal.

The 2010s to 2020s: Violations Spreading to Research Institutions and Small Businesses

From the 2010s onward, the front line of export control violations broadened from heavy industry to research institutions and smaller companies. Emblematic is the international student's FEFTA violation finalized in February 2018. In this case, technical information handled in a university's research activities was taken out to mainland China via Hong Kong without the approval of the Minister of Economy, Trade and Industry; a guilty verdict with a JPY 1 million fine was finalized, and in April 2018 METI imposed an administrative order of a three-month export ban. This case sharply accelerated the debate over "deemed export" management at universities and research institutions.

Deemed export is the idea that the act of providing technology to foreign researchers or international students within Japan becomes subject to regulation when it has, in substance, the same effect as exporting overseas. In November 2021, METI issued a directive on "clarifying deemed export management," introducing a new framework that determines not only the distinction between residents and non-residents but also whether someone falls under a "specific category." In August 2023, a casebook responding to the operational clarification was published, and universities and research institutions nationwide scrambled to revise their rules and build technology-provision management ledgers. In contrast to some universities that had established dedicated management offices early on, smaller research institutions without such organizations were saddled with a heavy burden.

On the corporate side as well, crackdowns on unlicensed exports came one after another during this period. In November 2021, it was reported that individuals had been arrested for exporting high-performance sonar (underwater acoustic equipment) without a license. On June 30, 2023, METI issued an administrative order warning a company for a FEFTA violation. A warning is a disposition under which the company's name is, in principle, made public — not something to be dismissed as "minor." And on July 10, 2024, Osaka Prefectural Police arrested the president of a trading company of Russian nationality on suspicion of unapproved export. The allegation was that the company had exported jet skis and other goods to Russia. Under the export restrictions on Russia following the invasion of Ukraine, even seemingly civilian products such as jet skis and general-purpose engines are subject to strict approval. METI's materials for small and mid-sized companies also feature a case in which the president himself received one year and six months of imprisonment, a JPY 1.2 million fine, and a one-year-and-one-month ban on exporting all goods to all destinations. Here, too, the structure in which the smaller the company, the less "an oversight" can be excused, repeats itself.

What METI's FY2024 Data Reveals as the Real "Biggest Risk"

Here is the part I most want to convey in this article. In December 2025, METI published the FY2024 edition of its "Analysis of FEFTA Violation Cases (Related to Security Trade Control)." It covers cases for which dispositions were decided between April 1, 2024 and March 31, 2025. Reading this latest edition, you can see that the conventional wisdom — that "70% of violation causes are classification" — has been clearly rewritten.

When I wrote the first version of this article, the figures that many practitioners, myself included, relied on came from FY2023. There, violations attributable to classification made up about 70% of the total, and "not getting the classification wrong" was treated as the top priority. In FY2024, however, the picture changes. The single largest cause became "failing to run the classification or assuming the item was non-controlled," at 32% (up from 21% the previous year). Conversely, "misclassification or misinterpretation of law" halved to 15% (from 30% the previous year), and "taking another company's incorrect classification at face value" also fell to 5% (from 18% the previous year). The three combined — classification-related causes — total 52%; still the largest single block, to be sure, but considerably smaller than 70%.

What increased instead were problems on the management-structure side. "Missing management rules or framework" rose to 19% (from 9% the previous year), "deficient or hollowed-out export control structure" to 8% (from 3%), and "misapplication of a license" to 9% (from 3%), so that management-structure-related causes combined reached about 36%. Read carefully, this tells us that the protagonist of today's violations is no longer "the person who gets the classification wrong" but "the person who assumes without classifying" and "the organization that has no framework in the first place." The structure in which unlicensed exports of goods make up the bulk of violations did not change in FY2024 either. That is exactly why I feel the very act of the classification step dropping out of day-to-day operations has become the biggest hole.

60% of Cases Surface Through Customs Post-Clearance Audits

Another thing in the FY2024 data not to be missed is the change in "how violations get caught." As for how violations first came to light, cases stemming from customs findings — that is, post-clearance audits — surged to 59% (from 43% the previous year), a majority. Internal discovery, such as through self-audits, accounts for only about 30%. A post-clearance audit is an investigation that retroactively scrutinizes an exporter's books and the actual substance of transactions after clearance. Even if the paperwork was in order at the very moment of export, findings can come later when the destination, the end user, and the actual end use are cross-checked. The sense that "it cleared customs, so there's no problem" is what most easily pulls the rug out from under you.

What a post-clearance audit asks is not only whether classification was "done." Why was the item judged non-controlled? Which item number on which list was it checked against? Who is the end user, and how was the end use confirmed? Whether records of that reasoning remain becomes decisive. Put the other way around, keeping the classification history and its basis as evidence is the strongest defense against a post-clearance audit.

Looking at the content of FY2024 dispositions, the most common was the minor "report" at 69%, followed by "submission of a statement of circumstances plus verbal caution" at 26%, and "submission of a statement of circumstances plus written stern warning" at 5%. There were no heavy dispositions — such as administrative sanctions or warnings against willful, malicious violations — recorded in FY2024. Looking at these figures alone, it is tempting to conclude that "most cases end lightly." But that is only because the majority happened to be negligence-type cases; it does not mean at all that the maximum the law provides for is light. For reference, here is the penalty regime the current law prescribes, laid out on a single sheet.

Category Content Basis
Criminal penalty (individual) Up to 10 years imprisonment, or a fine of up to JPY 30 million (may be imposed concurrently). Where five times the value of the goods exceeds JPY 30 million, up to five times the value FEFTA (Japan's revised Penal Code, effective June 2025, unified imprisonment with and without labor into a single form of imprisonment)
Criminal penalty (legal entity, dual-liability) A fine of up to JPY 1 billion, or up to five times the value of the goods FEFTA dual-liability provisions
Administrative sanction Export ban of up to three years, a warning with the company name disclosed in principle, revocation of bulk licenses FEFTA Article 53
US risk (ECRA / EAR) Criminal penalty of up to 20 years imprisonment and up to USD 1 million per case. Administrative fine of USD 374,474 per case (as of January 2025) or twice the transaction value, whichever is greater US ECRA (50 U.S.C. §4801 et seq.)
Circumvention / overseas-group risk Subsidiaries in which an Entity List company holds 50% or more also become subject to controls (BIS Affiliates Rule, 2025) US BIS regulations

What I want to emphasize here is that looking only at Japan's FEFTA is not enough. The US EAR (Export Administration Regulations) and ECRA (Export Control Reform Act) also reach the re-exports of Japanese companies and transactions routed through group companies. With the so-called 50% subsidiary rule that BIS introduced in 2025, the regulatory net now extends even to subsidiaries in which a listed company holds a majority stake. The idea that routing through an overseas group company makes it safe no longer holds. Even if the domestic penalty ends up minor, you must always keep in mind the double risk of being hit on the US side with a sanction or a suspension of transactions on an entirely different scale.

Prevention Measures Companies Should Take: Renewing the CP, Responding to 2025 Regulations, and Systematizing With TRAFEED

So what should you do? The foundation is renewing your internal export control rules (the CP, or Compliance Program). Taking the standard CP published by METI as a base, you rebuild the operational handbook tailored to your actual transactions, the classification workflow, the end-user screening checklist, the training plan, the internal audit cycle, and even the initial-response protocol for when a violation comes to light. If a company's CP has not been updated for several years, it is safer to assume it has not kept up with the recent regulatory tightening.

2025 in particular saw a concentration of institutional changes. The Foreign End User List (a list of foreign end users of concern for involvement in weapons of mass destruction and the like) was revised on September 29, 2025 and, upon taking effect on October 9, expanded to 835 entities, adding — on top of the existing concerns over weapons of mass destruction — concerns over the development of conventional weapons as grounds for listing. In April 2025, the Export Trade Control Order and related regulations were revised, adding so-called critical and emerging items to the scope of controls. Regulations surrounding semiconductors and advanced technology should now be assumed to be updated almost every year. End-user screening standards, too, need to be reviewed in step with these revisions.

On top of that, the heart of the matter is transforming classification and end-user screening into a system that does not rely on "a person's memory and experience." What the FY2024 data showed is the reality that, more than getting the classification wrong, "the classification step dropping out" is what's frightening. To prevent that dropout, there is no choice but to replace person-dependent operations with operations in which anyone performing them follows the same procedure and leaves a trail of evidence.

A Classification Checklist to Cover at Minimum

When inspecting your own operations, I always recommend checking in the following order. First, confirm list controls. Cross-check items 1 through 15 of Appended Table 1 of the Export Trade Control Order and the corresponding item numbers of the Appended Table of the Foreign Exchange Order against your items, and examine whether the specs touch the control thresholds. Second, confirm catch-all controls. Even general-purpose items not on the lists require a license if there is concern they will be used for the development of weapons of mass destruction or conventional weapons. Third, confirm the end use. Check whether the end use declared by the end user is consistent with the item's performance and actual nature. Fourth, confirm the end user. Cross-check against the Foreign End User List and each country's lists of parties of concern, tracing capital relationships to make sure there is no circumvention or disguise. And finally, keep the basis for every judgment up to this point as a record. Only when these five are in place does a classification stand up to a post-clearance audit. Frankly, there is a limit to doing all of this by hand, in Excel and PDF, every single time.

Voluntary Disclosure and the First Response When Something Happens

If you discover a violation, or a suspected one, internally, I believe you should prioritize the path of voluntary disclosure rather than concealment. Companies that promptly present the facts and their corrective measures to METI and customs tend, as a result, to have their dispositions shortened. Conversely, panicking only after being flagged from the outside in a post-clearance audit is the worst-case development. This is where, again, the classification evidence pays off. If the classification history, the grounding provisions, and the lists referenced are all in place, you can objectively explain that "this was an exceptional event, not a structural deficiency." That makes a decisive difference when negotiating an administrative disposition.

What supports this kind of systematization is the export control AI agent we at TIMEWELL provide, TRAFEED (formerly ZEROCK ExCHECK). As the world's first AI agent specialized for Japan's security export control domain (as of March 2026, per our own research), TRAFEED provides one-stop support for item classification, matching against the Entity List and lists of parties of concern, end-user due diligence, and multilingual document analysis. It comes standard with a classification workflow compliant with METI standards and also supports consistency checks against the US EAR and China's Export Control Law, so judgments that used to depend on individuals can be accumulated as organizational knowledge. Because classification results are saved as logs, you can immediately trace the history later in preparation for an internal audit or a customs post-clearance audit. Of course, the premise is that the final classification is made by your company's export control manager. But even on the single point of reducing missed classifications and reliably leaving evidence, I believe it is a realistic countermeasure against the biggest risk that the FY2024 data revealed.

If you are interested in improving export control operations or making classification more efficient, check the feature overview in the TRAFEED service catalog (PDF), or reach out via our contact form.

Summary: Three Things You Can Change Starting Today

From Toshiba Machine in 1987 to the recent Russia cases, the substance of violations has barely changed across nearly 40 years. Single-person processes, insufficient verification, and lag in keeping up with regulatory change — all of them begin with the assumption that "it could never happen to us." What has changed is how that complacency shows up. Where "getting the classification wrong" used to dominate, today "assuming without classifying" and "having no framework in the first place" have become the biggest causes — and on top of that, 60% of violations now come to light through customs post-clearance audits.

Here are three things you can begin changing today. First, check the date on which your CP was last updated, and confirm whether the 2025 changes — the expansion of the Foreign End User List to 835 entities, the addition of critical and emerging items, and the US BIS 50% subsidiary rule — are reflected in it. Second, examine whether classification is still entrusted to a single person, and put in place a mechanism that keeps the basis for each judgment as evidence. What a post-clearance audit asks is not whether you classified, but whether the records remain. Third, inventory the past three years of export transactions and reassess the risk of end users and end uses. Just these three moves will visibly reduce violation risk for most companies.

Export control violations are more familiar, and come with heavier penalties, than executive teams tend to realize. And once a case becomes public, the secondary damage — share price declines, suspended business relationships, impact on recruiting — can exceed the formal penalty itself. From a risk management perspective, investment in this area should be treated not as a "cost" but as an "insurance premium." If TRAFEED is relevant to your situation, please feel free to reach out. Using past cases and the latest data as the reference, we will work through together what level of capability your organization needs.

For related reading, see The Full Picture of Penalties and Risks for Export Control Violations, China's Export Controls on Japan and the New Reality of 2026, The Penalty Structure Under FEFTA, and Economic Security Through the Lens of the Makino Milling Acquisition Halt for a more three-dimensional understanding.

References

  • METI, "Analysis of FEFTA Violation Cases (Related to Security Trade Control) (FY2024)," December 2025
  • METI, "Analysis of FEFTA Violation Cases (Related to Security Trade Control) (FY2023)," December 2024
  • METI, "Post-Clearance Review of Security Trade (on FEFTA Violations)"
  • METI, "Overview of the Revisions to the Foreign Exchange Order, the Export Trade Control Order, and Related Regulations (Critical and Emerging Items)," April 2025
  • Foreign Exchange and Foreign Trade Act (e-Gov Law Search)
  • Ministry of Finance, "Recent Amendments to FEFTA"
  • Center for Information on Security Trade Control (CISTEC), "FEFTA Violation Cases"
  • U.S. Bureau of Industry and Security (BIS), "Enforcement / Penalties"
  • METI, "On the Clarification of Deemed Export Management," November 2021
  • METI, "Near-Miss Casebook on Security Trade Control in Universities and Research Institutions," updated August 2023

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles