Japan moves to let police read suspects' phones remotely to prevent crimes

25.09.2026 7 min 45

On 24 September an expert panel at Japan's National Police Agency signed off on a proposal that would let police read the contents of a suspect's smartphone remotely, under a court warrant, before a crime has been committed. The agency plans to put a bill to the extraordinary session of the Diet expected in early October.

The detail that matters is which law they intend to change. This is not an amendment to criminal procedure, the body of law that governs gathering evidence in a case that already exists. It is the Police Duties Execution Act, the law about what police may do to prevent harm. That places the whole measure on the preventive side of the line, where the target is not a proven offence but an expected one.

In short

  • The panel proposes remote access to phones used by organisers of "tokuryu" groups, loosely assembled crews recruited through social media.
  • Each device would need its own warrant, and only officers designated by the agency could carry out the analysis.
  • Anything outside the warrant is to be deleted, and the phone's owner is to be told afterwards.
  • Encryption is not broken anywhere in this plan. It is bypassed at the device, which is where the messages are already readable.

What is actually being proposed

The panel was convened on 10 August and met five times, ending on 24 September with its formal recommendation. Its subject was narrow: technical measures against crime by anonymous, fluid criminal groups. Those groups, known in Japan as tokuryu, do not look like the old syndicates. People are recruited for single jobs through social media, the organisers often sit abroad, and coordination runs through apps with strong encryption and messages that delete themselves on a timer.

That last part is the stated problem. Once a phone has been identified as belonging to someone giving instructions, police want to reach into it and read what the group is planning: which victims have been picked, when, and how many people are involved. The purpose written into the proposal is prevention of the crime, not proof of one.

Nobody is breaking the encryption

It is worth being precise, because the headline version of this story will be "Japan cracks encrypted messengers", and that is not what is happening. End-to-end encryption protects a message while it travels. On the two devices at either end, the message is plain text, because otherwise the person could not read it. Reach the endpoint and the encryption is intact, irrelevant and bypassed all at once.

This is the direction states have been moving in for several years, precisely because the cryptography holds. We wrote about the same move in a different form when the UK proposed scanning images inside the phone, and about the version that failed at the protocol level when Chat Control passed in the EU with an exception for encrypted services. Japan's version skips the argument with the maths entirely.

The limits written into the proposal

The safeguards are more specific than is usual in this kind of measure, which is itself worth noting.

LimitWhat it means
Warrant per deviceA judge authorises access to one identified phone, not to a category of people
Who may do itOnly officers with specialist expertise, designated by the National Police Agency
ThresholdProposed only where there is a risk of serious harm and no other way to get the information
Scope of dataLimited to what concerns the planned crime, such as timing, targets and number of participants
AfterwardsData outside the warrant is deleted and the phone's user is notified
ReviewThe National Public Safety Commission examines every case after the fact

Notification of the person whose phone was read is the unusual one. Most surveillance powers of this type never tell the subject anything. Whether that survives contact with a parliament and a police budget is a separate question, and it is the clause worth watching as the bill is drafted.

The part that is genuinely contested

Japan's constitution protects the secrecy of communications in Article 21, in language that is short and absolute. A power to read private messages, granted for prevention rather than prosecution, runs directly at that text, and the proposal's own safeguards read like an attempt to answer the objection in advance.

There is also the ordinary problem with preventive powers, which is that the category never stays where it was drawn. This one begins with organisers of fraud and robbery rings. Every element of the definition, from "serious harm" to "no other means", is a judgement call made by the people who want the access. That is not an argument that the power is wrong. It is an argument for reading the final text rather than the press release.

Losses from special fraud in Japan grew sharply in 2025. By how much, in percent, compared with the year before?

National Police Agency figures: losses rose 96.8% to 141.4 billion yen, while the number of cases rose 31.9% to 27,758. This is the scale the panel was asked to respond to.

Does any of this change what a reader should do

For almost everyone reading this, no, and it is worth saying so plainly rather than attaching a recommendation to a story that does not carry one. A VPN is irrelevant here. It protects traffic in transit; this measure reaches the device, after decryption, where a tunnel has no role at all. The same goes for choosing a messenger with better cryptography: the proposal is indifferent to which app the messages sit in.

What does matter is device security, which is the actual surface being discussed: an up to date operating system, a strong passcode rather than a four digit one, and awareness that a phone holds the plain text of everything its owner has ever sent. That is true regardless of what Japan's Diet decides. The same lesson turned up this week in a very different jurisdiction, when researchers described per-account surveillance switches in Russia's state messenger.

Does this mean Japan is banning encrypted messengers?
No. The proposal contains nothing about banning, weakening or backdooring encryption. It works by reaching the device where messages are already decrypted, which is why it does not need to touch the cryptography.
Can police do this to anyone?
As proposed, no. A judge must authorise access to a specific phone already identified as belonging to someone directing a criminal group, and only where serious harm is at risk and other methods have failed.
Would the person ever find out?
The proposal says yes: data outside the warrant is deleted and the user is notified afterwards. That clause is unusual for a power of this kind, and the bill has not been published yet.
Would a VPN protect against this?
No. A VPN encrypts traffic between your device and the VPN server. This measure operates on the device itself, past the point where anything is encrypted. It is the wrong tool for this threat.
When does it take effect?
Nothing has been enacted. The agency plans to submit a bill to the extraordinary session of the Diet expected in early October 2026, and the text of the bill is what will settle the questions above.

japanpolicesurveillanceencryptionprivacysmartphonesmessengerscourt warrantlegislationfraudpersonal datamobile appsvpndigital rightscybersecurity

Read also