EN Japan's Ground Self-Defense Force unknowingly used USB drives loaded with malware for close to a year, according to internal documents obtained by the Nikkei. The breach was only discovered after a soldier reported his computer was running unusually slow.
KO 일본 육상자위대가 악성코드가 심어진 중국산 USB를 약 1년간 사용해왔다는 사실이 내부 문건을 통해 드러났다. 한 대원이 '컴퓨터 속도가 계속 느리다'고 신고하면서 문제가 발각됐다.
EN This incident is a textbook case of supply-chain hardware risk, and the one-year detection gap is the most alarming detail. Modern air-gapped defenses are meaningless if contaminated removable media walks right through the front door. For Japan, which is rapidly expanding its cyber-defense budget, this is a painful reminder that hardware provenance — knowing exactly where every device comes from — is just as critical as network perimeter security.
KO 1년이라는 탐지 공백이 이 사건의 핵심이다. 망 분리나 방화벽은 오염된 하드웨어가 내부로 들어오는 순간 무력화된다. 방위 예산을 공격적으로 늘리고 있는 일본 입장에서 이번 사건은, 사이버 방어의 출발점이 소프트웨어가 아니라 '기기의 출처 검증'임을 다시 일깨워주는 뼈아픈 사례다.
- malware — 악성 소프트웨어 — 시스템을 손상시키거나 정보를 탈취하기 위해 설계된 프로그램
- air-gapped — 물리적으로 외부 네트워크와 분리된 보안 환경
- supply-chain risk — 제품 제조·유통 과정에서 발생하는 보안 위협