すぐわかる
← Back to list
Published: 2026-10-02Daily

📡 Home IoT Devices Abused as Proxies: MIC Publishes Recommendations

Published October 2, 2026 | Recommendations on residential proxies, with results of the public comment (22 comments)

Article updated: 2026-10-03

❓ What was published?

On October 2, 2026, MIC published recommendations on residential proxies that abuse household IoT devices. Malicious programs in devices such as home streaming equipment can relay cyberattack traffic using household IP addresses. The consultation ran from July 22 to August 4, 2026 and received 22 submissions, counted by submitter. MIC published the comments and responses (Attachment 1) and recommendations (Attachment 2). The main proposals are cooperation among police, NICT, ICT-ISAC and other relevant bodies, and ISPs to warn affected users; and sharing lists of attacker command-and-control (C2) servers with ISPs so their DNS services can block name-resolution requests for those servers and disrupt attack relaying. The document says stakeholders must consider the details of implementation. October 2 is the publication date of recommendations, not the start of a new legal obligation for household users.

👥 Who does this affect?

  • ●Anyone using IoT devices such as routers or network cameras at home
  • ●Foreign residents with an internet contract in Japan (fiber, home router, etc.)
  • ●People who have not confirmed whether their devices still receive support and updates
  • ●People warned by their ISP about suspicious traffic from their equipment
  • ●Telecom carriers, device manufacturers and other parties addressed by the recommendations

🌏 Impact on foreign residents

Foreign residents using home internet and IoT equipment in Japan also have an interest in preventing device abuse. The recommendations describe ISPs identifying and warning affected users. They do not announce a warning to every subscriber or blanket disconnection of home internet from October 2. If contacted about suspicious traffic, verify directly with your contracted provider’s official support instead of immediately following an email link. If Japanese instructions are difficult, ask what language or setup assistance is available. For specific action, follow the instructions for your device from your contracted ISP or manufacturer. These recommendations do not impose a new legal duty on users to change settings.

💡 What to check

1The recommendations and the summary of submitted comments with MIC's responses are available as Attachments 1 and 2 of the MIC press release; the same documents are posted in the Public Comment section of e-Gov.
2The public comment period ran from July 22 to August 4, 2026 and has already closed. 22 comments were submitted, and the finalized recommendations reflecting them were published on October 2, 2026.
3Your provider may contact you to say suspicious traffic has been seen from your equipment. Do not ignore Japanese-language emails or letters; if you are unsure, check directly with your provider's support desk (and watch out for scams imitating such notices).
4The official contact is the study group secretariat in MIC’s Cybersecurity Office (03-5253-5749). For help configuring a particular device, contact its manufacturer or your ISP through official support channels.

🔗 Related Issues