Cyber Security Report -July 2026
- 3 days ago
- 12 min read
Research by OSINT Monitoring Team, NTT Security Japan K.K
Link to original report: https://jp.security.ntt/insights_resources/cyber_security_report/csr202607/
Table Contents
Threats and Background of Residential Proxies
1.1. Overview
1.2. Exploitation of Third-Party Resources by Attackers
1.3. Methods for Constructing Residential Proxy Infrastructure by Attackers
A Stone Shot by Canadian Intelligence: Disclosure of Active Cyber Operations
2.3. Details of published cases of active cyber operations
Security Organization Transparency and Continuous Improvement: Lessons from the US CISA Incident Disclosure
3.2. Contents Published by CISA
3.3. Lessons Learned from CISA's Publication
Disclaimer
This report selects and summarizes three particularly important topics from various incidents and events related to information security that occurred during July 2026, as well as the changes in the surrounding environment. The main points of each topic are as follows.
Chapter 1: 'Threats and Background of Residential Proxies'
Cyberattacks that exploit household IoT devices and lines to conceal attackers' identities and locations have become a problem, making detection and tracking of attacks difficult.
Attackers have traditionally used botnets to expand the scale of attacks and conceal their origins. In recent years, the use of ORBs (Operational Relay Boxes) with enhanced anonymity has been confirmed, and residential proxies, which easily blend into legitimate users' communications, have been exploited as critical attack platforms.
Because residential proxies are formed through various channels such as vulnerability exploitation, user deployment, and supply chain approaches, organizations need to be aware not only of the risk of becoming victims of attacks but also of the risk of their own devices and networks being exploited as a stepping stone for attacks.
Chapter 2: 'A Stone Played by Canadian Intelligence: Disclosure of Active Cyber Operations'
The Canadian Communications Security Agency (CSE) published three cases of "active cyber operations" in its 2025-2026 annual report.
In all three cases, CSE responded to criminal and extremist groups based on information analysis, reducing their operational capabilities.
It is rare for intelligence agencies to disclose the specific details of active cyber operations. This CSE report holds great significance in that it more concretely presents the cases and outcomes of the initiative, contributing to greater transparency in activities.
Chapter 3: "Security Organization Transparency and Continuous Improvement: Lessons from the US CISA Incident Disclosure"
On July 9, 2026, the U.S. CISA (Cybersecurity and Infrastructure Security Agency) disclosed a credential breach incident that occurred within its organization.
CISA disclosed not only the background from the incident's discovery to response, investigation findings, and recurrence prevention measures, but also the lessons learned from the response, highlighting the significance of sharing knowledge across organizations.
This case reaffirmed the importance of incident response not merely as a resolution but as an opportunity for organizational improvement.
Threats and Background of Residential Proxies
1.1. Overview
In recent years, IoT devices and network devices used in ordinary households have become a problem of being misused by third parties and used as stepping stones for cyberattacks. Attackers carry out crimes such as unauthorized access and unauthorized money transfers while making it difficult to identify themselves by passing through these devices. Such devices that are abused as stepping stones are called "residential proxies." On July 21, 2026, the National Police Agency, the Ministry of Internal Affairs and Communications, and the National Institute of Information and Communications Technology (NICT) jointly published a report titled "Current Status of Residential Proxies Misusing Home IoT Devices."[1]
This article explains the background behind the use of residential proxies as a foundation for cybercrime and the threats they pose.
1.2. Exploitation of Third-Party Resources by Attackers
Attackers have traditionally exploited third-party devices and networks to expand the scale of attacks and conceal their own activities. A representative example is botnets (systems that remotely control numerous devices infected with malware), which have been used to carry out large-scale attacks and distribute attack sources.
In recent years, state-sponsored attack groups such as those in China have been operating relay infrastructure with enhanced anonymity using multi-layered communication routes (multiple relay points). This mechanism is called ORB (Operational Relay Box).[2]
On the other hand, IP addresses used in data centers and cloud services are relatively easy to detect due to communication patterns and usage characteristics, and are more likely to be registered on blacklists and similar purposes.
Against this backdrop, attackers began exploiting residential proxies that use IP addresses assigned to subscribers of general household ISPs and mobile lines as relay platforms to evade detection and blocking, making it easier to blend in with legitimate users' communications.
Status of Residential Proxy Damage in Japan
According to an analysis by the National Police Agency, among the fraudulent remittance cases related to internet banking that occurred in 2024, 1,918 cases (about 44% of the total) involved the use of residential proxies (see the figure on the left below). Furthermore, the total amount of these damages reached approximately 2.89 billion yen, accounting for about 33% of the total damage (see the figure below). These results show that residential proxies are widely used as attack bases in cybercrime.
1.3. Methods for Constructing Residential Proxy Infrastructure by Attackers
Although the forms of abuse of residential proxies are diverse, based on confirmed cases, they are classified into the following three categories.
1) Vulnerability Exploitation Type
It exploits known vulnerabilities in IoT devices and network devices connected to the network, directly infiltrating from outside without user intervention, and installs software with communication relay functions.
Major Cases
Proxy software (software used to relay third-party communications) was illegally installed on security camera devices, causing the device to function as a residential proxy.[4]
2) User Implementation
Software distributed with services such as free VPNs or bandwidth sharing is equipped with SDKs (software development components) that enable proxy functionality and backdoors (functions for unauthorized external access). When users install the software, the terminal operates as a residential proxy, and without fully recognizing its existence or impact, it may be used as a relay point for third-party communications.
Major Cases
The large-scale residential proxy service "911 S5" was known for providing third parties with access rights to the IP addresses of infected devices. When general users installed the free VPN app on their devices, third parties could communicate via the IP address assigned to that device.[5]
3) Supply Chain Type
Software or malware with communication relay functions is embedded during the manufacturing and distribution stages before IoT devices reach users. When a user connects a purchased device to the network, a third party can use that device as a residential proxy.
Major Cases
Some inexpensive Android TV boxes known under the brand name H96 (devices connected to TVs to access internet services) came pre-installed with apps with relay functionality. The app relayed communications via home lines without the user's awareness, functioning as a resident proxy. Additionally, some devices have been reported to have been exploited by advertising scam networks.[6]
Thus, the pathways through which devices are abused as residential proxies extend not only to device vendors, app providers, telecommunications providers, and distributors, but also to users' devices and network environments, making it difficult for a single entity to fully implement these measures.
1.4. Summary
Residential proxies serve as a crucial foundation for cybercrime by exploiting household devices and lines to conceal the identity and location of attackers. This has made it harder to detect and track attacks, leading to an expansion of damage, including financial crimes. Organizations need to be aware not only of the risk of attacks themselves, but also of the risk that their devices and networks could be turned into residential proxies and exploited for attacks on others. These challenges cannot be solved by a single company alone; there is a demand for strengthening measures across society, including collaboration among the government, businesses, and users.
[1] Source: Ministry of Internal Affairs and Communications, 'Promoting Public-Private Joint Countermeasures Against Cyberattacks Exploiting Home IoT Devices'https://www.soumu.go.jp/menu_news/s-news/01cyber01_02000001_00293.html
[2] Source: Google Cloud Blog (Mandiant) 'IOC Extinction?' China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders』https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks/?hl=en
[3] Source: National Police Agency, Ministry of Internal Affairs and Communications, National Institute of Information and Communications Technology (NICT) 'Current Status of Residential Proxies Exploiting Home IoT Devices' (NICT Cybersecurity Laboratory)https://www.nicter.jp/report/20260721_residential_proxy_overview.pdf
[4] Source: NICTER Blog 'Observations of Residential Proxy Exploitation of Known Vulnerabilities in Xiongmai DVRs'https://blog.nicter.jp/2026/03/iot_proxyware/
[5] Source: FBI Internet Crime Complaint Center (IC3) 'Guidance on the 911 S5 Residential Proxy Service'https://www.ic3.gov/PSA/2024/PSA240529
[6] Source: Krebs on Security 『Read This Before You Buy That TV Streaming Stick』https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
A Stone Shot by Canadian Intelligence: Disclosure of Active Cyber Operations
2.1. Overview
The Communications Security Establishment Canada (CSE) published three cases of "active cyber operations" in its 2025-2026 annual report.[7]
This provided a glimpse into the actual activities of intelligence agencies, where details are usually not disclosed.[8]

2.2. CSE's Cyber Operations
The CSE is a Canadian government agency responsible for external SIGINT activities (intercepting and analyzing overseas communications and electronic signals to obtain information), cyber operations, and cybersecurity support.[9]The scope and authority of CSE activities are defined by the CSE Act, which defines the frameworks for external cyber operations as "Defensive cyber operations" and "Active cyber operations."
What is Defensive Cyber Operations?
Aimed at protecting critical systems for Canada, such as energy grids, communication networks, medical databases, banking systems, and election infrastructure.[10]This is implemented in cases where large-scale cyber incidents cannot be resolved by conventional response alone.[7]CSE lists possible measures such as disabling overseas servers used by attackers to prevent information theft from government networks. Implementation requires approval from the Minister of Defense and consultation with the Minister of Foreign Affairs.
What is Active Cyber Operations?
Implemented to undermine the capabilities of foreign terrorist organizations, cybercriminals, and state-sponsored actors before harm to Canada's international relations, defense, and security interests. For example, measures are envisioned to disable communication equipment used by foreign terrorist organizations and disrupt communication and attack plans. To implement this, a 'two-key' system is adopted, requiring approval from the Minister of Defense and consent from the Minister of Foreign Affairs.[7]
2.3. Details of published cases of active cyber operations
Of the proactive cyber operations conducted in fiscal year 2025, CSE has disclosed three cases.
Case 1: Response to RaaS (Ransomware-as-a-Service) Operations Group
RaaS (Ransomware-as-a-Service) is a criminal business model in which ransomware operators provide attack tools and infrastructure as a service and share profits with affiliates who use these tools to carry out attacks.CSE has identified with high accuracy the technologies and methods of a prominent RaaS operating group involved in over 25 attacks in Canada's transportation, healthcare, pharmaceutical, and business sectors.[7]Subsequently, in cooperation with Five Eyes (a partnership for external information sharing among the US, UK, Canada, Australia, and New Zealand), the group disabled the group's infrastructure and removed a large amount of stolen data sold on the dark web.
Case 2: Handling Intermediaries Selling Fentanyl Raw Materials
Fentanyl is a powerful analgesic used for medical purposes.[11]On the other hand, unauthorized manufacturing, sale, and possession are illegal, and they are used for non-medical purposes as well. Additionally, because fentanyl is colorless and odorless, there have been confirmed cases where fentanyl has been mixed into other illegal drugs, causing users to ingest it without knowing it. Because even very small amounts of this drug can have fatal effects, overdose deaths are on the rise, making it a serious social problem in Canada.In 2025, CSE identified cybercriminals based outside Canada who were mediating the buying and selling of fentanyl raw materials.[7]Subsequently, these individuals were analyzed, measures to be disrupted were formulated, and law enforcement agencies were coordinated to reduce their operational capabilities.
Case 3: Dealing with Violent Extremist Groups
CSE analyzed foreign extremist organizations that were spreading violent ideology and recruiting in Western countries, including Canada, analyzing their personal networks, scope of activities, and weaknesses. Based on this, they took disruptive measures against the organization's online activity base and technical infrastructure, reducing its ability to operate, recruit personnel, and disseminate harmful content.
2.4. Summary
In cybersecurity, the so-called "attacker-favoring asymmetry" continues, where the attacker's burden and risk are relatively lower than that of the defender. In recent years, active efforts by cybersecurity and intelligence agencies in various countries have increased efforts to pose appropriate risks to attackers and impose restrictions on their activities, raising expectations for correction of the situation. However, the actual nature of activities involving cyberattacks carried out under legal authority has remained largely unclear. Although the details of individual operations remain unclear, this CSE report holds great significance in that it has published more concrete examples and results than before, thereby enhancing transparency in intelligence agency activities.
[7] Source: Government of Canada 'Communications Security Establishment Canada Annual Report 2025-2026'https://www.cse-cst.gc.ca/sites/default/files/cse-annualreport-2025-2026-e_2.pdf
[8] Source: TechCrunch 'Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year'https://techcrunch.com/2026/07/06/canadian-spy-agency-says-it-hacked-drug-traffickers-extremists-and-a-ransomware-gang-last-year/
[9] Source: Government of Canada 'Foreign intelligence'https://www.cse-cst.gc.ca/en/mission/foreign-intelligence
[10] Source: Government of Canada 'Cyber operations'https://www.cse-cst.gc.ca/en/mission/cyber-operations
[11] Source: Government of Canada 'Fentanyl'https://www.canada.ca/en/health-canada/services/substance-use/controlled-illegal-drugs/fentanyl.html
Security Organization Transparency and Continuous Improvement: Lessons from the US CISA Incident Disclosure
3.1. Overview
On July 9, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a blog post titled "Lessons from CISA's Cyber Incident," reflecting on credential breaches that occurred within its organization.[12]The document explains the process from discovery to response to the formulation of measures to prevent recurrence of this incident, which occurred at the national cybersecurity agency. This paper organizes the published content and considers the implications derived from it.
3.2. Contents Published by CISA
In May 2026, researchers at the U.S. security company GitGuardian discovered confidential CISA-related information on a public GitHub repository.[13]Although attempts were made to contact those involved, it took time to identify the appropriate reporting destination, and ultimately, the information was relayed to CISA via the press.[14]
From Impact Assessment to Formulation of Recurrence Prevention Measures
Upon receiving the report, CISA took the repository private, shut down the development environment, invalidated and reissued credentials, and began an impact investigation using log analysis and forensics (methods to collect evidence and analyze entry routes and impact areas).
![Figure 3: The repository named "Private-CISA" (currently private) [14]](https://static.wixstatic.com/media/a5aeba_dc7f51e0aaee4be9b733ecf1ea371d1d~mv2.png/v1/fill/w_874,h_412,al_c,q_90,enc_avif,quality_auto/a5aeba_dc7f51e0aaee4be9b733ecf1ea371d1d~mv2.png)
The investigation revealed that the repository contained authentication credentials for AWS GovCloud (a cloud service for U.S. government agencies), development/operation-related code, and configuration information. It was also revealed that although this repository was created in November 2025 and used to build infrastructure on cloud services, it was managed not on CISA's official GitHub account but on a GitHub account owned by the contractor's individual employee.Subsequent investigations found no evidence of external misuse of the leaked credentials, nor was there any impact on customer data or critical systems.After the case was resolved, CISA has been implementing measures to prevent recurrence, including changes and reissuance of credentials, strengthened controls on the use of public repositories, reviewed monitoring systems, and improved the reception system for external reports.
3.3. Lessons Learned from CISA's Publication
The lessons from this case go beyond technical issues such as credential management and incident response. A particularly noteworthy point is that CISA, a national-level cybersecurity agency, has independently published the details of incidents, response status, and improvement measures that occurred within its organization.
Publication of Incident Information
While many organizations consider post-incident response and recurrence prevention measures, the insights gained during the process are rarely shared externally. Meanwhile, CISA stated in its recent release, "Now, it is our turn." This demonstrates an organizational stance that has long emphasized the importance of sharing incident information and actively discloses its own cases.Such information sharing not only prompts other organizations to recognize similar risks and review countermeasures and operations, but also contributes to the accumulation of knowledge within the entire security community. In particular, in this case, not only the incident itself but also the background of discovery, the investigation process, and the details of improvement measures were disclosed, providing a wealth of useful information from a practical perspective.
Establishment of Incident Response System
This case also highlights the "difficulty of completely preventing incidents." Even advanced security specialists cannot completely eliminate human factors and operational challenges. The important thing is not that incidents do not occur, but that after they occur, the facts are understood, the impact is assessed, and processes are established to lead to improvement. The results of the investigation conducted by CISA and the publication of its recurrence prevention measures are examples of such efforts.
Organizational Improvement Activities
Rather than pursuing individual responsibility, CISA reviewed multiple management processes, including credential management, monitoring systems, and external reporting reception systems, implementing organizational improvement measures. This serves as a model for reviewing organizational operational challenges triggered by incidents. It is also important to view security measures not only as technical but also as a comprehensive initiative that includes operations and communication.In recent years, with the expansion of cloud services and SaaS usage, organizations are no longer limited to managing only their own internal systems. Therefore, continuously reviewing operational rules, including those of contractors, and establishing mechanisms for information sharing across organizations have become important challenges. The stance CISA presented in this case is also useful for many companies.
3.4. Summary
This case demonstrates that even technologically advanced organizations find it difficult to completely prevent incidents caused by human factors or operational challenges. Meanwhile, CISA demonstrated organizational accountability and a commitment to continuous improvement by actively sharing insights gained during the process, in addition to investigating cases and implementing recurrence prevention measures.
It is desirable to re-examine whether the system for connecting lessons learned from incidents to continuous improvement within one's own organization is functioning.
[12] Source: CISA 'Lessons from CISA's Cyber Incident'https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident
[13] Source: GitGuardian Blog 'What CISA Got Right After Its GitHub Leak: Lessons Every Organization Should Copy'https://blog.gitguardian.com/cisa-github-leak-incident-response-lessons/
[14] Source: Krebs on Security 'CISA Admin Leaked AWS GovCloud Keys on Github'https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
Disclaimer
Please note that while we do our best to ensure that the content of this article is accurate, we do not guarantee the content and do not compensate for any damages or losses incurred as a result of the use of this article. If you have any inquiries such as typographical errors, content errors, or other points in the article, please contact us at the following address.
Inquiries
NTT Security Japan Corporation
Professional Services OSINT Monitoring Team




