The Case for Canada-Japan-Republic of Korea Trilateral Cybersecurity Cooperation

Photo by: Cpl Hugo Montpetit, Canadian Forces Combat Camera, Canadian Armed Forces Photo

POLICY PERSPECTIVE

by Jeehye Kim and Tae Yeon Eom

October 2026

DOWNLOAD PDF


Table of Contents


Introduction

In February 2025, the Lazarus Group stole an estimated US$1.5 billion in Ethereum from the cryptocurrency exchange Bybit, marking the largest cryptocurrency theft on record. The Federal Bureau of Investigation identified North Korea’s TraderTraitor cluster as responsible within days. The stolen funds moved across thousands of wallet addresses and several blockchains within hours, faster than any single national authority could trace or freeze them. Exchanges and investigators in the United States, Japan, and South Korea (ROK) each held part of the picture, yet no standing mechanism existed to fuse that intelligence in real time. A multilateral mechanism for pooling signals intelligence on North Korean infrastructure, operating at the same speed as the theft itself, could have shortened the interval between attack and asset freeze.

As the Bybit theft shows, fragmented national responses cannot keep pace with North Korean cyber operations that move across borders in hours. Canada has signed a series of bilateral cybersecurity agreements with Japan and South Korea over the past year to strengthen its cyber resilience. With Japan, Canada signed the Security of Information Agreement (SIA) in July 2025, the Equipment and Technology Transfer Agreement (ETTA) in January 2026, and sent the Team Canada trade mission to Japan in June 2026. With Korea, Canada signed the Security and Defence Cooperation Partnership (SDCP) in October 2025, and the Agreement on the Protection of Military and Defence Classified Information in February 2026. This agreement significantly expanded upon the two countries’ first-ever Agreement on the Exchange and Protection of Classified Military Information back in 1998. Yet real operational and strategic gaps remain between these tracks.

This article argues that trilateral cooperation among Canada, Japan, and South Korea can close those gaps in ways bilateral action alone cannot. The article first documents these limits through three cases of North Korean cyber operations, then examines how institutional norm-building and operational cooperation could work in practice and finally addresses the practical challenges to building this framework before concluding with a series of policy recommendations.

TOP OF PAGE


The limits of a fragmented cooperation on cyber crime in the Indo-Pacific

Major North Korean cyber operations have steadily exposed the limitations of fragmented national responses in Japan and South Korea. From the cross-border disruption caused by WannaCry to repeated attacks on their cryptocurrency networks and the emergence of North Korean IT-worker infiltration, both countries have faced a common adversary whose operations crossed jurisdictions faster than their security institutions could coordinate. These experiences helped create the rationale for the post-Camp David trilateral mechanism focused specifically on North Korean cyber threats.

Case 1: the 2017 Wannacry incident

The WannaCry ransomware campaign, attributed by the United States and other governments to North Korean actors, spread globally in May 2017. Although Canada evaded severe losses, it served as a dire warning, as it disrupted organizations across more than 150 countries including Japan and South Korea. The campaign demonstrated how a North Korean operation could spread simultaneously across allied countries, disregarding national boundaries. As Japan and South Korea lacked anything resembling today’s Trilateral Diplomatic Working Group on North Korea’s Cyber Threats in 2017, each was limited to investigating domestic infections and sharing information separately with the United States, leaving them unable to coordinate quickly with one another. WannaCry was a revelation that countering North Korean cybercrime demands a networked regional response.

Case 2: Cryptocurrency theft

Since the COVID-19 pandemic, North Korean hacking groups, particularly Lazarus, have accelerated attacks on cryptocurrency markets in Japan and South Korea. North Korean cyber theft is estimated by US and UN sources to fund between one-third and one-half of its weapons and missile programmes. Major South Korean incidents included the 2017–18 attacks on exchanges such as Youbit and the 2019 theft of approximately US$42 million in Ethereum from Upbit, which South Korean authorities attributed to Lazarus and Andariel. Japan was also a major target of North Korean cryptocurrency activity, such as the US$308 million theft from DMM Bitcoin in 2024, which Japan, the United States and South Korea later jointly attributed to North Korean actors. In the absence of trilateral working groups, responses to cryptocurrency thefts remained isolated incidents involving separate domestic law-enforcement and regulatory systems by country while the source of the problem: North Korean malware, cryptocurrency wallets, laundering infrastructure, and AI-enabled social-engineering techniques, evaded physical borders.

Case 3: North Korea IT workers

Finally, a more recent North Korean cyber crime threat involves operators who use false or stolen identities to pose as remote workers, often operating through third-country facilitators, taking advantage of generative AI to gain legitimate access to foreign governments and companies. Canada first alerted this problem in 2025 through an RCMP advisory, warning that small businesses are especially vulnerable to North Korean fake IT workers due to need for cheaper labour and lack of vetting mechanisms. 

Compared with the previous two cases, the US, Japan, and South Korea have begun to mobilize their nascent trilateral framework to produce joint statements in both 2025 and 2026 (joined by nine additional countries including Canada). Further institutionalization of this framework could improve the joint tracking of North Korea-controlled cryptocurrency wallets, faster sharing of malware indicators and attack signatures; identification of common social-engineering techniques that utilize AI tools; and synchronize the three states’ efforts to freeze or trace stolen assets.

TOP OF PAGE


Institutional Implementation

One need not look further than the existing US-Japan-ROK trilateral cooperation to understand why trilateral cooperation has higher payoffs than bilateral ones. The core institutional framework emerged most clearly from the Camp David trilateral summit in August 2023, and subsequent initiatives have increasingly focused on North Korean cryptocurrency theft, remote IT workers, ransomware, critical infrastructure, and cyber-enabled sanctions evasion. Similarly, Canada, Japan and South Korea can develop a layered network of trilateral leaders’ commitments, security dialogues and working groups, law-enforcement and sanctions coordination, and regular joint cyber exercises against North Korean cyber activity.

On institutional norm building, a trilateral framework involving Canada, Japan, and South Korea could align their public positions at multilateral venues such as the UN Open-Ended Working Group and G7 cyber statements, coordinate the timing of sanctions designations against North Korea-linked wallets and front companies, and set shared reporting standards for exchanges and financial institutions operating across the three jurisdictions. Canada’s experience leading the G7’s Data Free Flow with Trust initiative (DFFT) gives it a practical role in this work: harmonized data standards would let the three countries share information on stolen-asset tracking without duplicating one other’s regulatory systems. The three states could also issue joint public attribution statements, building on the precedent set by the 2025 and 2026 IT-worker advisories, which raise the political cost of North Korea cyber operations more than statements issued by any single country.

On strengthening operational capacity, a trilateral framework involving Canada, Japan, and South Korea could move beyond the largely bilateral and retrospective channels used today toward near-real-time sharing of telemetry data, malware indicators, and attack signatures. Canada’s Five Eyes access to signals intelligence on North Korean infrastructure combined with its Arctic and undersea-cable monitoring data are two assets it can bring to this table that neither Japan nor South Korea currently has on its own. Building on precedents such as the Canada-Japan MASAKARI exercises, the three countries could run joint incident-response exercises focused specifically on North Korean threat scenarios, and pool forensic capabilities so that public attribution of an incident like the 2025 Bybit occurs in days instead of months. The three states could also extend capacity-building support to smaller Indo-Pacific states with weaker cyber defenses, closing off the third-country facilitation points that North Korean IT-worker schemes currently exploit.

TOP OF PAGE


Conclusions: Geopolitical and Structural Challenges 

The first challenge for a Canada-Japan-ROK trilateral framework on cybersecurity is avoiding potential redundancy, as Japan and Korea may see a Canada-initiated trilateral cyber framework as unnecessary alongside the existing US-Japan-ROK trilateral that took years of diplomatic investment to build. Thus, it is important to highlight the assets unique to Canada that the existing US-Japan-ROK trilateral does not currently draw on, such as the Five Eyes-sourced signals intelligence on North Korean infrastructure, and Arctic and undersea-cable monitoring capabilities built for NORAD and NATO missions. These specialized, niche contributions complement Washington’s role and provide independent technical value in maritime domain awareness or undersea-cable resilience. In both areas Canada possesses a genuine comparative advantage, and neither Tokyo nor Seoul is likely to read the offer as duplicating or diluting the existing trilateral with the US Starting with these lower-friction forms of cooperation would help build mutual trust and would provide a foundation for broader trilateral engagement over time.

In order to sufficiently distinguish itself from the existing US-Japan-ROK trilateral, a Canada-Japan-ROK initiative could begin by enhancing the cooperation that is already underway, such as the protection of critical-mineral and battery supply chains and cyber threats to Arctic–Indo-Pacific infrastructure. An additional consideration is that Canada, Japan, and South Korea currently operate under different privacy and data-sovereignty regimes. None of the niche areas identified above can work effectively if wallet-tracking and exchange data cannot move across those regimes in real time. Closing that gap would be a compliance and legal-harmonization task as much as a diplomatic one.

First, eliminating domestic legal barriers remains a priority. While Japan has passed a major cybersecurity law in May 2025, marking a significant departure from its traditionally defensive posture by allowing it to take proactive measures against foreign cyber threats, South Korea has yet to do the same. These gaps in information-security standards warrant more than passing consideration. They help explain why the Five Eyes alliance has not admitted a new member in decades, as common standards for handling classified information are a prerequisite for deeper intelligence sharing. Closing that gap for a Canada-Japan-ROK cyber mechanism will take time, but actionable first steps are available in the near term. These include a Minister-to-Minister meeting dedicated specifically to cybersecurity information-sharing standards, and structured working-level dialogues, modeled on existing bilateral security consultations, where technical agencies compare data-handling and classification practices and identify where they diverge before attempting to harmonize them.

The second challenge is securing a shared understanding that cybersecurity cooperation, like efforts on denuclearization, would be grounded in shared values that transcend domestic political preferences of Japan and South Korea, and accounting for historical tensions stemming from Japanese colonization of Korea. Domestic political transitions in either Japan or South Korea can introduce friction into bilateral security commitments; therefore, both nations must recognize that cybersecurity is vital to state survival and demands consistent collaboration across the ideological spectrum. The recent resumption of Japan and South Korea’s naval search and rescue exercise after a nine-year hiatus demonstrates how easily security cooperation between the two can stall when domestic politics intervene. An earlier example is even more relevant to the kind of cooperation proposed here. In August 2019, Seoul gave formal notice that it would withdraw from GSOMIA, the bilateral intelligence-sharing pact with Tokyo, during an escalating trade and history dispute. South Korea reversed course only hours before the agreement was due to lapse in November of that year.

GSOMIA is exactly the kind of mechanism on which Canada-Japan-ROK cyber framework would need to rely. Its near-collapse therefore serves as a warning that intelligence-sharing arrangements between Japan and Korea can become hostage to disputes that have nothing to do with the threat they were built to address. As Canada has no formal alliance treaty with either country and, as a liberal democracy, has no stake in their shared colonial history, it holds a small advantage: cooperation routed partly through Ottawa may be less vulnerable to a future GSOMIA-style suspension than a purely bilateral channel.

The third challenge is one of organizational scope. The three countries’ threat perceptions overlap significantly, but they are not identical; South Korea understandably places North Korea at the centre of its threat environment and is careful not to alienate China, while Japan is increasingly less concerned about North Korea and more worried about China and the latter’s threats to regional infrastructure. Similar to Japan, Canada’s concern for North Korea have centred on the latter’s nuclear programme, and unlike the US, Canada has yet to place North Korea’s cybersecurity threat on par with that emanating from China and Russia.

Given these divergent threat perceptions, an initial trilateral cyber partnership can centre narrowly on North Korean digital finance (cryptocurrency) theft and IT-worker activity as opposed to a mandate that broadly addresses all state-sponsored cyber threats. This narrow mandate functions as an initial phase, as China and Russia already pose comparable cyber threats to critical infrastructure, intellectual property, and supply chains in all three countries, even where governments differ on how loudly to say so in public. In this phase, Canada could also consider ranking North Korea as a higher threat in its cybersecurity strategy to reflect the recent changes in the potency of North Korean hackers.

Once this phase is complete, a workable second phase could shift the mandate toward attribution-agnostic hybrid threats, such as supply-chain compromises and undersea-cable disruptions, where the three states share exposure regardless of which state or non-state actor is responsible. Framing a North Korea-focused mandate as a deliberate starting point, while clearly leaving room for future expansion, would allow the partnership to evolve without requiring Seoul, Tokyo, and Ottawa to reach immediate agreement on how to characterize Beijing or Moscow.

In conclusion, a trilateral partnership among Canada, Japan, and South Korea, drawing on Canada’s signals-intelligence access and collective cybersecurity experience alongside Japan and Korea’s technological advantage, holds real promise. Canada’s optimal role in this partnership would be as a signals-intelligence provider to Japan and South Korea. As Canada continues to pursue cooperation with Japan and Korea on critical minerals, advanced manufacturing of batteries and semiconductors, and frontier technologies, a trilateral framework that can safeguard supply chains from state-sponsored hybrid threats will become invaluable.

TOP OF PAGE


Policy Recommendations

  • Integrative efforts should begin with functional, niche Canadian contributions, such as maritime domain awareness and undersea-cable resilience. These lower-friction entry points for cooperation helps position the initiative as complementary to the existing US-Japan-ROK framework rather than as a broader trilateral dialogue that could be perceived as duplicative.
  • Institutionalize norm-building by synchronizing public positions at the UN Open-Ended Working Group and G7 cyber statements, coordinating the timing of sanctions designations against North Korea-linked wallets and front companies, and establishing shared reporting standards for exchanges and financial institutions.
  • Strengthen operational capacity through near-real-time sharing of telemetry data, malware indicators, and attack signatures; joint incident-response exercises building on the Canada-Japan MASAKARI and the Canada-Korea LOCKED SHIELDS exercises; and pooled forensic capabilities to accelerate public attribution efforts.
  • Clarify institutional lead roles within the Canadian government: designate CSE and the Canadian Centre for Cyber Security for technical intelligence and attribution, CAF Cyber Command for military exercises, Global Affairs Canada for diplomatic and sanctions coordination, and the RCMP for law-enforcement cooperation on IT-worker fraud.
  • Support Japan and South Korea’s domestic cybersecurity capacity building, by extending observer roles and participation in Five Eyes framework, similar to Japan’s hosting the 2024 Five Eyes senior meeting for the first time as a non-member nation. 
  • Address the compliance gap early by convening a trilateral Minister-to-Minister meeting on cybersecurity information-sharing standards, followed by structured working-level dialogues to compare data-handling and classification practices across all three countries.
    • Strengthen defense-industrial cooperation among Canada’s DIA, Japan’s ATLA and Korea’s DAPA by prioritizing defence supply-chain cybersecurity procurement.
  • Phase the mandate deliberately by focusing initially on North Korea-specific cryptocurrency theft and IT-worker activity, while treating attribution-agnostic hybrid threats, such as supply-chain compromises and undersea-cable disruptions, as a clearly defined second phase of cooperation.

Reflect North Korea’s growing AI-enabled cyber capabilities by elevating its prominence within Canada’s national cybersecurity strategy and establishing a trilateral working group on AI-enabled cyber operations focused on crisis response, threat assessment, and operational coordination.

TOP OF PAGE


About the Author

Dr. Jeehye Kim is the Senior Program Manager of Northeast Asia at the Asia Pacific Foundation of Canada, and oversees the research program related to Japan, Mongolia, North and South Korea, and Taiwan. She has a PhD in Government from Harvard University, specializing in International Relations. Prior to joining the APF Canada, she was a postdoctoral fellow and Director of the Centre for Korean Research at the University of British Columbia. 

Tae Yeon Eom is the Project Manager of the "Where Technology Meets Security: A Canada–South Korea Policy Brief Series," funded by a Korea Foundation Policy-Oriented Research Related to Korea grant. He is a former Research Scholar with APF Canada’s Northeast Asia team. Tae Yeon’s work sits at the intersection of technology and security policy, covering AI, quantum, cybersecurity, and space, with a geopolitical focus on Canada, Japan, and South Korea. He connects government, academia, and industry to advance Canada's technology and security co-operation across the Indo-Pacific.

TOP OF PAGE


Canadian Global Affairs Institute

The Canadian Global Affairs Institute focuses on the entire range of Canada’s international relations in all its forms including trade investment and international capacity building. Successor to the Canadian Defence and Foreign Affairs Institute (CDFAI, which was established in 2001), the Institute works to inform Canadians about the importance of having a respected and influential voice in those parts of the globe where Canada has significant interests due to trade and investment, origins of Canada’s population, geographic security (and especially security of North America in conjunction with the United States), social development, or the peace and freedom of allied nations. The Institute aims to demonstrate to Canadians the importance of comprehensive foreign, defence and trade policies which both express our values and represent our interests. 

The Institute was created to bridge the gap between what Canadians need to know about Canadian international activities and what they do know. Historically Canadians have tended to look abroad out of a search for markets because Canada depends heavily on foreign trade. In the modern post-Cold War world, however, global security and stability have become the bedrocks of global commerce and the free movement of people, goods and ideas across international boundaries. Canada has striven to open the world since the 1930s and was a driving factor behind the adoption of the main structures which underpin globalization such as the International Monetary Fund, the World Bank, the World Trade Organization and emerging free trade networks connecting dozens of international economies. The Canadian Global Affairs Institute recognizes Canada’s contribution to a globalized world and aims to inform Canadians about Canada’s role in that process and the connection between globalization and security. 

In all its activities the Institute is a charitable, non-partisan, non-advocacy organization that provides a platform for a variety of viewpoints. It is supported financially by the contributions of individuals, foundations, and corporations. Conclusions or opinions expressed in Institute publications and programs are those of the author(s) and do not necessarily reflect the views of Institute staff, fellows, directors, advisors or any individuals or organizations that provide financial support to, or collaborate with, the Institute.

TOP OF PAGE


Showing 1 reaction

Please check your e-mail for a link to activate your account.
SUBSCRIBE TO OUR NEWSLETTERS
 
UPCOMING EVENTS

CALGARY OFFICE
Canadian Global Affairs Institute
Suite 2700, 525–8th Avenue SW
Calgary, Alberta, Canada T2P 1G1

 

ACCOUNTING
Canadian Global Affairs Institute
P.O. Box 2554, Station M
Calgary, Alberta, Canada T2P 2M7

 

Calgary Office Phone: (587) 574-4757

 

OTTAWA OFFICE
Canadian Global Affairs Institute
8 York Street, 2nd Floor
Ottawa, Ontario, Canada K1N 5S6

 

Ottawa Office Phone: (613) 288-2529
Email: [email protected]
Web: cgai.ca

 

Making sense of our complex world.
Déchiffrer la complexité de notre monde.

 

©2002-2025 Canadian Global Affairs Institute
Charitable Registration No. 87982 7913 RR0001

 


Sign in with Email