US, Japan, South Korea weigh cyber cooperation
Experts discuss deepening US-Japan-South Korea trilateral cybersecurity cooperation to counter North Korean, Chinese, and Russian cyber threats.
This Atlantic Council 5x5 expert roundtable examines the state of trilateral cybersecurity cooperation between the United States, Japan, and South Korea, prompted by Deputy National Security Advisor Anne Neuberger's visit to Seoul. Contributors highlight North Korea's use of offensive cyber operations, particularly cryptocurrency theft and cyber-enabled money laundering, to fund its weapons programs, alongside Chinese state-sponsored cyberespionage targeting public and private sector networks in all three countries. Ransomware groups and other non-state actors are also cited as shared concerns.
The discussion covers the potential expansion of US Cyber Command 'Hunt Forward' operations into the Indo-Pacific, weighing benefits against risks of escalation, blowback, and complicating relations with China. Experts note that historical tensions and mistrust between Japan and South Korea, rooted in colonial-era grievances, continue to hinder deeper intelligence sharing and joint defense cooperation, even as both nations face common threats. Economic dependence on China is flagged as a factor discouraging public attribution or hawkish responses to Chinese cyber intrusions from Tokyo and Seoul.
Overall, the piece is a policy-analysis and trend discussion rather than a report on a specific incident, campaign, or new malware. It emphasizes the need for improved information sharing, cybercrime law enforcement cooperation (especially on cryptocurrency-based crime), and diplomatic efforts to bridge Japan-South Korea distrust in order to strengthen collective cyber defense against shared state and non-state threats.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-the-us-japan-south-korea-trilateral-cybersecurity-relationship
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free