Hello, this is Ryuta Hamamoto from TIMEWELL.
When breach disclosures pile up the way they have in Japan this autumn, a tempting thought comes up: why not just block all traffic from outside the country? If you look after a website, you have probably seen the switch for it in your CDN or WAF (web application firewall) settings, a list of countries you can tick and block.
Then, on July 21, 2026, Japan's National Police Agency, the Ministry of Internal Affairs and Communications and the National Institute of Information and Communications Technology (NICT) published a joint fact sheet that addressed exactly this. Attackers who relay their traffic through hijacked home IoT devices, it said, can even reach servers that companies have locked down against overseas access as a defense against foreign attacks, which makes corporate security controls easy to sidestep1. That is a government agency stating, in writing, that country blocking can be walked around.
I wrote about Japan's recent run of breaches and how to close the obvious entry points in Part 1 and Part 2 on September 30, and looked at the same attacks from an export control angle on October 4. This piece sits one step earlier: where do attacks appear to come from? I covered the procurement and national security side of foreign-made routers in my piece on the TP-Link debate, so here the focus is not who made the device but how traffic is routed, and how much a country rule really buys you.
My conclusion up front. Country blocking is not useless. It cuts down automated scanning and DDoS noise. But it is not your main line of defense, because attackers who mean business route through relays inside your country or close to it. What works better is allowing only the countries you need instead of listing the ones you fear, protecting admin panels with both location and authentication, and making sure your own devices don't become someone else's relay. One more thing: I won't describe how TIMEWELL itself handles traffic by country. I'll explain why near the end.
Key points (as of October 4, 2026)
- Most suspicious scans picked up by the National Police Agency's sensors came from abroad, but the top source countries were the United States, the Netherlands, Bulgaria, the United Kingdom and Germany. An IP address's country tells you where a server or line sits, not where the attacker is
- Japanese authorities recommend restricting foreign IP addresses for websites that only serve domestic users, as a DDoS measure. It removes a lot of noise, but it can also block search crawlers and overseas customers
- Residential proxies, which relay traffic through ordinary home devices, were used in about 44% of Japan's online banking fraud cases in 2024 (at least 1,918 cases). Country blocking does nothing against them
- An advisory co-sealed by agencies in ten countries, Japan included, recommends allow lists over deny lists. Local relays still get through, so combine them with phishing-resistant MFA and device certificates
- If your VPN appliance, router or the streaming stick in a meeting room is hijacked, your company becomes the exit point for attacks on others
Where do attacks appear to come from?
Start with the numbers. Japan's National Police Agency runs sensors that watch for suspicious traffic such as vulnerability probing. In the first half of 2026 they logged 13,687 suspicious accesses per IP address per day, up 50.7% year on year, and the agency says most of it came from overseas2.
So far that sounds like an argument for blocking foreign traffic. The country breakdown is where it gets interesting. The top sources were the United States, the Netherlands, Bulgaria, the United Kingdom and Germany, in that order. A year earlier it was the United States, China, Bulgaria, the Netherlands and Germany. Traffic from the Netherlands jumped 501.3%, which the agency attributes to large volumes sent from IP addresses assigned to one Dutch organization across a wide range of ports, probably to survey for vulnerabilities2.
I read that ranking as a map of where servers are easy to rent, not a list of attacker nationalities. Every IP address is registered to an organization and a country. Addresses in countries with lots of data centers and cloud regions can be rented and used from anywhere. Legitimate research scanning and attackers' reconnaissance run on exactly the same infrastructure.
Email shows a similar pattern. The agency analyzed about 360,000 messages it classified as phishing, received between August 2025 and July 2026. The sending servers were most often located in China, then Japan, then Brazil. And most sending IP addresses delivered just one to three messages over one to three days. The agency concludes that phishing groups swap out their sending infrastructure quickly and rarely reuse it2. Japan coming second, and addresses being thrown away within days: keep both in mind for what follows.
| Source | What the origin looked like |
|---|---|
| National Police Agency sensors (first half of 2026) | 13,687 suspicious accesses per IP per day (up 50.7%). Mostly from abroad; top countries were the US, Netherlands, Bulgaria, UK and Germany2 |
| National Police Agency phishing analysis (about 360,000 emails) | Sending servers located in China, Japan and Brazil, in that order. Most IPs dropped out of use within one to three days2 |
| Police and national cybersecurity center analysis of DDoS attacks (September 2022) | About 99% of attacking IP addresses were assigned to overseas networks3 |
| National Police Agency analysis of online banking fraud (2024) | At least 1,918 cases (about 44%) used residential proxies routed through home connections inside Japan1 |
The first three rows and the last one tell very different stories. High-volume, automated traffic tends to come from abroad. But in targeted attacks aimed at stealing money, more than four in ten cases blended in with legitimate users by routing through domestic connections. Any discussion of country blocking has to keep those two apart.
Where country blocking helps, and the side effects
Country rules work most naturally against the first three rows, the attacks that rely on volume. In May 2023, the National Police Agency and Japan's National center of Incident readiness and Strategy for Cybersecurity (NISC, the predecessor of today's National Cybersecurity Office) put this first on their list of DDoS countermeasures: if a website only serves users in Japan, restrict access from IP addresses assigned overseas. In a string of DDoS attacks on government-related and critical infrastructure websites in September 2022, about 99% of the attacking IP addresses were foreign3.
The US Cybersecurity and Infrastructure Security Agency (CISA) lists geolocation-based filtering in its catalog of countermeasures for evicting intruders, describing it as a way to restrict reconnaissance and initial access from regions of concern4. Stop traffic at the CDN or WAF and whatever never arrives also never loads your servers or fills your logs. For a small company where one person reads the logs, less noise is worth a lot.
The same CISA entry is candid about the downsides. Geo-blocking can produce false positives and block legitimate users, especially people who connect through a VPN. It cuts off every legitimate interaction with the blocked region. Some jurisdictions, particularly in the EU, may restrict it legally. CISA asks organizations to confirm with business leadership that the block will not stop critical activities4.
Three practical traps are worth spelling out. The first is search. Google says Googlebot's default IP addresses appear to be based in the United States, and asks sites that vary content by country to treat a US-based Googlebot like any other US visitor5. Block the US because it "looks suspicious," and you may drop out of search. The second is business traffic: overseas customers, staff on business trips, and callbacks from payment providers and other external services. The third is accuracy. AWS documentation says CloudFront maps IP addresses to countries using a third-party database, with overall accuracy of 99.8%, and that if it can't determine a user's location, it serves the requested content anyway6. Traffic it can't place gets through by design.
Even with those side effects, I think narrowing access by country makes sense for systems that only domestic users touch. Just treat it as noise reduction, a pre-filter. The moment you believe it has made you safe, the routes in the next section become your blind spot.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Three routes that get past country blocking
The first is the residential proxy I mentioned at the start: an IoT device on an ordinary home connection that relays a third party's traffic, usually without the owner knowing. The destination server records the household's IP address, so the company on the receiving end can't see the real source and struggles to tell the traffic apart from legitimate users1.
The scale is real. NICT has observed up to roughly 27,000 IP addresses a day acting as residential proxy exit points since January 2026, and estimates there are at least tens of thousands of such devices in Japan. In 2024, at least 1,918 online banking fraud cases involved residential proxies, with losses of about 2.89 billion yen, which was about 44% of cases and 33% of losses1. In 2025, the agency counted at least 737 such cases (about 1.39 billion yen) out of 4,747 fraud cases worth about 10.4 billion yen. Both figures are floors, counting only cases the agency could confirm2. In a newsletter for the public, the agency puts it simply: cyberattacks from overseas are being disguised as access from private homes in Japan7.
The devices named include streaming boxes marketed as a way to watch Japanese and foreign video on your TV for free, digital photo frames, routers and network cameras. Some shipped with malware planted during manufacturing or distribution. Others picked up relay functions from wallpaper apps or free VPNs, or from apps that promise income for sharing your unused bandwidth1.
The second route is covert networks of hijacked SOHO (small office, home office) routers and IoT devices. On April 23, 2026, agencies from ten countries, including Japan's National Cybersecurity Office, co-sealed an advisory written by the UK's National Cyber Security Centre (NCSC)89. The advisory focuses on China-nexus actors using these networks, but the mechanism is what matters here. Traffic enters at an on-ramp node, passes through several compromised devices, and leaves from an exit node "usually in the same geographic region as the target"8. The advisory notes that one such network infected more than 200,000 devices worldwide in 2024, and that new nodes are added as old devices are patched or retired, which makes static malicious IP block lists less effective8. I covered how the group known as Volt Typhoon used routers this way in my article on foreign-made routers.
The third route is remote control of machines placed inside the country, or of servers rented for the purpose. On September 18, 2026, the National Police Agency and the National Cybersecurity Office, together with US, Australian and German agencies, published findings on a North Korea-linked cyber group and on North Korean IT workers. They reported confirming, for the first time in Japan, a "laptop farm" operated remotely by North Korean IT workers10. According to the full advisory, the workers had supporters living in Japan host remote-controlled PCs in their homes, and used virtual private servers rented by supporters, to disguise where they actually were11. In one case, an applicant to a Japanese crypto exchange used VPN and proxy services when submitting the application (the company spotted the warning signs and handled it properly; no hiring or damage resulted). The agency suggests checking whether the source IP matches the applicant's stated location, while warning that these workers appear to rely heavily on VPNs11. An IP address's country is a clue, not proof.
| Route | Origin recorded in your logs | Does country blocking stop it? |
|---|---|---|
| Residential proxies | An ordinary home connection in your country | No |
| Covert networks of hijacked routers | An exit device in the same region as the target | Rarely |
| Remote control of in-country machines or rented servers | A domestic line, or a server rented by a supporter | No |
| Commercial VPNs and proxies | Wherever the provider's servers are | Depends on that country |
On October 1, the main parts of Japan's active cyber defense law took effect, and the government can now access and neutralize servers used in attacks. Even the government's own briefing on the law describes cyberspace as a place where stepping-stone servers are easy to come by12. The state, too, works on the assumption that attackers can swap their apparent origin at will.
Allow lists over deny lists, then authentication
So what should you do? The ten-country advisory asks every organization to map its network edge devices and understand what should be connecting to them, to baseline normal connections, especially to corporate VPNs, and to require multi-factor authentication for remote connections. Next to the baselining advice sits a pointed question: would you expect connections from consumer broadband ranges?8
For larger or higher-risk organizations it goes further: use IP address "allow lists rather than deny lists" for remote workers connecting to corporate VPNs, use geographic allow lists or profile connections by operating system, time zone and organization-specific settings, adopt zero trust policies (verify every connection, inside or outside the network), enforce machine certificates, and shrink your internet-facing footprint8.
I think the difference between deny and allow lists is bigger than it looks. A deny list is a list of countries you fear. As the previous section showed, targeted attacks arrive from the target's own region or from home connections inside the country, so everything not on your list still gets in. An allow list admits only the countries you need. For a system used only by domestic staff, overseas scanning simply disappears. The Japanese authorities' advice to restrict access from overseas IP addresses is, in effect, an allow list containing one country3.
Allow lists still let domestic relays through, though. That is why authentication is the last line. Put phishing-resistant MFA on admin panels and internal systems, and where you can, require device certificates so only company-issued machines get in. I went through how to choose MFA methods in Part 2. The way you read logs changes too. A login from inside the country still deserves suspicion if it comes over an unusual kind of connection, at an odd hour, or from an unfamiliar device. Treat location as one input among several, no more.
| What you're protecting | Role of country rules | Main defense |
|---|---|---|
| Public website anyone can visit | Useful against noise and DDoS if users are domestic. Check the effect on crawlers and overseas customers first | CDN or WAF, per-IP rate limits, keeping software updated |
| Admin panel | Allow only the countries you need | Phishing-resistant MFA. Ideally reachable only from the office network or VPN, never exposed publicly |
| Staff remote access (VPN and similar) | Allow list plus a baseline of normal connections | Device certificates, MFA, verify-every-connection design |
| Job application and vendor intake forms | Treat IP country as a hint only | Identity checks, verification in interviews, minimal data and access for contractors |
Now, the promised explanation of why I won't share TIMEWELL's own settings. Which countries you block and what you allow tells an attacker exactly which relays to rent. It is tempting to write up a clever configuration on a tech blog, but I wouldn't. Share the thinking, and keep the specific conditions in internal runbooks.
Don't let your own devices become someone else's relay
Everything so far has been about defending. Let me flip the view. If someone's home router can be used as a relay, so can yours.
On October 31, 2025, Japan's Information-technology Promotion Agency (IPA) issued two alerts at once, warning that VPN appliances, home routers and IoT routers can be hijacked and turned into ORBs (operational relay boxes) used as stepping stones for attacks on others1314. Beyond data theft and long-term footholds, the listed impacts include becoming complicit in attacks and social and legal risks such as lost trust, lawsuits and suspended business relationships. The router alert adds that reconnaissance ahead of intrusions is on the rise14. To other companies, your hijacked device looks like a legitimate Japanese business connection. You end up, without knowing it, on the side that slips past everyone else's country rules.
The National Police Agency's sensors have also seen a surge since May 2026 in traffic with the hallmarks of Mirai, malware that infects home routers and IoT devices2. The countermeasures are not exotic. IPA lists strong, non-default passwords, prompt patching and replacement of unsupported devices, keeping management interfaces off the internet, and regular reboots to clear malicious processes that live in memory14. Tokyo's Metropolitan Police Department asks people to check their router's admin screen regularly for VPN or dynamic DNS features they never enabled, settings that expose the admin screen to the internet, and VPN accounts they don't recognize, and to reset the router if they find any15. The reason is a technique it found during an investigation: once attackers change those settings, the usual fixes such as changing passwords and updating firmware no longer undo the compromise. If your check turns up signs of a takeover or intrusion, our guide to what to do if you are hit by a cyberattack in Japan walks through the first steps for individuals and companies.
The devices people forget are the ones in meeting rooms and at reception. The fact sheet asks businesses to stop unapproved devices from joining business networks, to separate business networks from IoT networks, and to run firewalls and access controls properly1. Is the streaming stick plugged into the meeting-room TV, or the digital photo frame at reception, on the office Wi-Fi? It is worth a walk around to find out. When the National Police Agency examined digital photo frames and projectors that may have been used as relays, it found unsupported operating systems and administrator privileges that were trivially easy to enable. It recommends choosing new devices that carry a label under JC-STAR, Japan's public scheme for evaluating and labeling the security features of IoT products216. IPA itself notes that a label marks a minimum baseline and does not guarantee complete security16. For how far Chinese manufacturers have gone in obtaining labels, our piece on JC-STAR and Chinese products checks the IPA register.
| Device | What to check |
|---|---|
| VPN appliances, firewalls | Are updates applied? Is the management interface visible from the internet? Any suspicious relayed traffic?13 |
| Office and home-office routers | Unexpected VPN, dynamic DNS or remote admin settings, unknown VPN accounts. Is the device still supported?1415 |
| Streaming boxes, photo frames, cameras | Are they on the business network? Any "watch everything free" boxes or bandwidth-sharing apps?1 |
| IoT devices you plan to buy | JC-STAR label, the maker's support period and security information216 |
Staff working from home are part of the same picture. If a device in an employee's home is acting as a relay, suspicious traffic can reach your systems from that connection, and other companies may start treating that line as a bad source. Whether your people know any of this comes down to how you train them. If you want a rough read on where your team stands on AI and security basics, our AI literacy check is a quick place to start.
Summary
- Most suspicious traffic does come from abroad, but the source country reflects where servers and lines are, not where attackers are
- For domestic-only systems, restricting foreign traffic is a sound way to cut scanning and DDoS noise. Check the impact on crawlers, overseas customers and external services first
- Targeted attacks arrive through home connections in your own country or relays near the target. About 44% of Japan's 2024 online banking fraud cases did exactly that
- Allow the countries you need instead of listing the ones you fear, and protect admin panels and remote access with phishing-resistant MFA and device certificates
- Audit your VPN appliances, routers and meeting-room gadgets so they don't become someone else's relay. That is part of defense too
Drawing a line at the border feels like protection, but for an attacker a border is something one rented relay can cross. So my advice is simple: on the day you switch on country blocking, start reviewing admin authentication and taking stock of your devices as well. A good first step is to count the internet-connected gadgets in your meeting rooms and at reception. You may find one that nobody remembers buying. If you are working on internal rules and training, that is what our WARP SECURITY program covers, and you can reach me through a one-on-one consultation.
References
The facts in this article are based on the public documents below (as of October 4, 2026).
Footnotes
-
The Current State of Residential Proxies Exploiting Home IoT Devices — National Police Agency, Ministry of Internal Affairs and Communications, and NICT — July 21, 2026 (Japanese) (overview on the National Police Agency's page) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Threats in Cyberspace, First Half of 2026 — National Police Agency — September 2026 (Japanese) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
Countermeasures Against DDoS Attacks — National Police Agency Cyber Affairs Bureau and NISC — May 1, 2023 (Japanese) ↩ ↩2 ↩3
-
Enable Geolocation-based Traffic Filtering (CM0037) — CISA Eviction Strategies Tool — March 14, 2025 ↩ ↩2
-
Locale-adaptive pages — Google Search Central — updated December 10, 2025 ↩
-
Restrict the geographic distribution of your content — Amazon CloudFront Developer Guide (AWS) ↩
-
Cyber Police Agency Letter 2026 Vol. 9: Devices in Your Home Are Being Exploited — National Police Agency — August 2026 (Japanese) ↩
-
Defending against China-nexus covert networks of compromised devices — UK NCSC and partner agencies (16 agencies in 10 countries, including Japan's National Cybersecurity Office) — April 23, 2026 (announcement on the UK NCSC site) ↩ ↩2 ↩3 ↩4 ↩5
-
On Co-sealing the Advisory on Defending Against China-linked Covert Networks of Compromised Devices — National Cybersecurity Office — April 23, 2026 (Japanese) ↩
-
Public Attribution by Japan, the US, Australia and Germany Regarding the North Korean Cyber Group "WaterPlum" and North Korean IT Workers (press release) — National Police Agency and National Cybersecurity Office — September 18, 2026 (Japanese) ↩
-
Cyberattacks Targeting IT Engineers by the North Korean Cyber Group "WaterPlum," and the Activities of North Korean IT Workers in Japan, the US and Europe — National Police Agency and National Cybersecurity Office — September 18, 2026 (Japanese) ↩ ↩2
-
On the Entry into Force of the Cyber Response Capability Enhancement Act and Related Laws — Cabinet Secretariat National Cybersecurity Office and Cabinet Office — September 2026 (Japanese) ↩
-
Risk of Network-Penetrating Attacks Turning VPN Appliances and Similar Devices into ORBs (Operational Relay Boxes) — Information-technology Promotion Agency, Japan (IPA) — October 31, 2025 (Japanese) ↩ ↩2
-
Risk of Home Routers, IoT Routers and Other Network-Edge Devices Becoming ORBs (Operational Relay Boxes) — IPA — October 31, 2025 (Japanese) ↩ ↩2 ↩3 ↩4
-
Warning About the Misuse of Home Routers — Tokyo Metropolitan Police Department — updated April 5, 2023 (Japanese) ↩ ↩2
-
Labeling Scheme based on Japan Cyber-Security Technical Assessment Requirements (JC-STAR) — IPA (Japanese) ↩ ↩2 ↩3






