Fujitsu Limited launched a three-component cybersecurity service on September 25, 2026, combining dark web monitoring, attack surface management, and threat hunting. It’s powered by a new MSSP and reseller agreement with KELA Co. Ltd., which contributes dark web criminal community intelligence. The service is positioned to help Japanese enterprises comply with Japan’s government-led active cyber defense initiatives, with particular focus on critical infrastructure operators. A companion “Cyber Security Nerve Center” is set to launch in October 2026.
The Tokyo-headquartered technology giant announced today the launch of a comprehensive active cyber defense service, built through a partnership with KELA, a specialist dark web threat intelligence firm, and delivered by Fujitsu’s own Uvance Wayfinders security team. It’s designed specifically for Japanese enterprises and critical infrastructure operators now facing regulatory pressure under Japan’s new Active Cyber Defense legislation to move from reactive security to proactive threat detection.
The timing isn’t accidental. The service and the law are built for each other.
What Japan’s Active Cyber Defense Law Actually Changed
Before the 2026 legislation, Japan’s cybersecurity posture was almost entirely defensive by law. Organizations could respond to attacks but couldn’t legally monitor adversary infrastructure or take preemptive countermeasures. Japan was, in practice, waiting to be hit before it could do much.
The Active Cyber Defense Law changed that framework. It authorizes government agencies and private sector operators, particularly those running critical national infrastructure like power, transport, telecommunications, and finance, to monitor for attack indicators outside their own networks, collect threat intelligence from external sources including the dark web, and implement protective measures before damage occurs.
This is a significant policy shift for Japan. And it creates an immediate compliance problem for thousands of enterprises: they now need capabilities they haven’t historically had to build. Few large Japanese companies have internal teams that continuously monitor criminal communities on the dark web, manage external attack surfaces at scale, and hunt for threats that haven’t triggered any existing alarm.
That’s the gap the Fujitsu–KELA service is built to fill.
Who KELA Is and Why It Matters Here
KELA isn’t a general threat intelligence provider. It specializes specifically in what happens inside criminal communities- the closed forums, invite-only markets, and attacker channels that exist on the dark web and deep web and that don’t appear in standard threat feeds or news cycles.
The difference matters because generic threat intelligence platforms aggregate publicly disclosed breach data and known malware signatures. KELA’s intelligence comes from inside the communities where attacks are planned, access is auctioned, and stolen credentials are sold before most companies know they’re exposed.
This is the same intelligence model that underpins Nasdaq Verafin’s partnership with Q6 Cyber, using visibility inside criminal markets to give organizations a head start measured in days or weeks before fraud or an attack reaches them directly. The same early-warning principle applies here, scaled to enterprise network security rather than financial fraud.
For Fujitsu’s service, KELA provides the raw intelligence layer: leaked credentials from underground forums, emerging attack campaigns targeting specific sectors, and intelligence on threat actors building campaigns against Japanese organizations. Fujitsu’s security experts then assess what that intelligence means specifically for each client and propose countermeasures.
The Three-Part Structure and Why Each Piece Matters
The service has three functional components, and the design hinges on understanding why all three together are more valuable than any one alone.
Dark web monitoring is the listening function. KELA continuously monitors underground forums and attacker communities for mentions of client organizations, leaked credentials, and early indicators of upcoming attacks. Without this layer, an enterprise only learns about a breach after it has happened, or when a dark web monitoring tool flags that its credentials are already circulating. The CRIF Cyber Observatory data released this week shows just how many credentials are in circulation: 2.5 billion unique records in H1 2026 alone. Monitoring your organization’s data in that pool requires continuous, specialized surveillance.
Attack surface management is the scanning function. Everything an enterprise exposes to the internet, login portals, APIs, cloud infrastructure, VPNs, customer-facing applications, is an attack surface. KELA’s intelligence, combined with Fujitsu’s analysis, identifies which exposed assets have known vulnerabilities and which threat actors are actively discussing as potential entry points. The CenterPoint Energy breach, where a hacker exploited an unprotected external-facing API that the company apparently didn’t know was reachable, is a near-perfect illustration of what attack surface management exists to prevent.
Threat hunting is the investigation function. Even with strong monitoring and scanning, some attacks are designed to evade automated detection. Fujitsu’s Uvance Wayfinders white-hat hacker team actively hunts for threats that haven’t triggered any alert, analyzing logs, cloud audit trails, and communication records inside client systems for subtle indicators that a sophisticated attacker has already gained access and is moving quietly.
Crucially, the Uvance Wayfinders team does this using knowledge from Red Team operations. Fujitsu runs simulated attacks against organizations to test their defenses, and that experience gives their threat hunters an attacker’s perspective on what actual intrusions look like inside a network. It’s the difference between looking for what you expect to find and looking for what attackers actually do.
The Context Fujitsu Doesn’t Mention in Its Own Press Release
Fujitsu’s announcement focuses entirely on the new service. It doesn’t mention that Fujitsu suffered a significant breach in 2024, when a cyberattack on its internal project management tool exposed data from Japanese government agencies and other clients.
That breach matters here because it shapes how Fujitsu’s customers will receive this launch. Building and selling a comprehensive security monitoring service from a company that recently needed one is either a conflict or a credibility story, depending on how you look at it. Fujitsu has been open about rebuilding its security posture since 2024. Partnering with KELA, one of the more respected specialist names in dark web intelligence globally, is partly about bringing genuinely external capability rather than claiming expertise Fujitsu builds entirely in-house.
The dark web intelligence market is growing at over 21% annually precisely because companies are recognizing this gap; the intelligence needed to detect early-stage threats isn’t something most can build internally. Fujitsu is using KELA to close its own gap and offering that combination to Japanese enterprises facing the same challenge.
The October Expansion
Fujitsu’s press release notes that a “Cyber Security Nerve Center” is scheduled to commence operations in October 2026. The center will provide additional support from peacetime monitoring to emergency response, functioning as a coordination hub for Fujitsu’s broader cybersecurity service portfolio.
This positions the KELA partnership service as the intelligence input layer that feeds into a larger operational security framework. Dark web monitoring catches the early signals. Attack surface management identifies exposure. Threat hunting investigates internal compromise. The Nerve Center then coordinates the response when any of those layers surfaces a real incident.
It’s worth comparing this to what South Korea is building at the government level: a 700-billion-parameter AI foundation model specifically trained on dark web data, involving 33 organizations and a government mandate. Japan’s approach is commercially driven rather than government-built, with Fujitsu serving as the integrator and KELA as the intelligence partner. Both reflect the same regional recognition: Asia-Pacific organizations can no longer treat dark web monitoring as optional for critical infrastructure security.
Why This Matters Beyond Japan
The Fujitsu–KELA deal is a Japan-specific launch, but it reflects a broader shift in how enterprises are approaching threat intelligence.
The pattern we’ve documented across 2026’s major incidents is consistent: supply chain attacks show up on dark web forums before they reach public disclosure, breach data circulates in criminal markets before victims are notified, and attack surfaces that organizations don’t know they’re exposing get exploited by criminals who found them through routine scanning.
A service that combines continuous dark web visibility with external asset discovery and internal threat hunting addresses all three entry points simultaneously. The market for this, valued at nearly $1 billion globally in 2026 and growing at 21% annually, is growing fast because enterprise security teams are finally accepting that waiting for an alert from their own systems is no longer a complete security strategy.
Frequently Asked Questions
What did Fujitsu launch?
Fujitsu launched a three-component active cyber defense service on September 25, 2026, combining dark web monitoring, attack surface management, and threat hunting for Japanese enterprises and critical infrastructure operators.
What is KELA’s role?
KELA provides the dark web and underground forum intelligence layer under an MSSP and reseller agreement. It specializes in monitoring closed criminal communities that aren’t visible in standard threat feeds.
What is Japan’s active cyber defense initiative?
Japan’s 2026 Active Cyber Defense Law authorizes enterprises and government agencies to proactively monitor for cyberattack indicators, shifting away from the previous defensive-only approach.
Who is the service designed for?
Critical infrastructure operators are the primary target, with enterprise organizations broadly as the wider audience. The regulatory mandate under Japan’s ACD law is the specific compliance driver.
What comes next?
A Cyber Security Nerve Center is scheduled to launch in October 2026, expanding Fujitsu’s security service portfolio from monitoring into coordinated incident response.