Join our Newsletter — 33% off our NHI Course

Tokuryū

A Japanese term for anonymous and fluid criminal groups that hide organisers, recruit through social media and job sites, and repeatedly form and disband. These networks create screening challenges because they may lack stable names or memberships, making conduct-based review and relationship analysis more important than static list matching.

Expanded Definition

Tokuryū refers to anonymous, loosely connected criminal networks that avoid stable hierarchies, fixed names, and durable membership. In NHI security terms, the important feature is not just anonymity, but operational fluidity: organisers can recruit, direct, and discard participants through digital channels without exposing a persistent identity graph. That makes tokuryū especially relevant to investigations that rely on account lists, known aliases, or static watchlists.

Definitions vary across vendors and public-safety contexts, but the security pattern is consistent: conduct-based assessment matters more than name-based matching. This is closely aligned with identity-risk thinking in the NIST Cybersecurity Framework 2.0, where organisations are expected to understand assets, relationships, and anomalous behavior rather than depend only on known-good registries.

The most common misapplication is treating tokuryū as a single group name, which occurs when analysts assume a fixed membership list can capture a network that is deliberately reconstituted after each operation.

Examples and Use Cases

Implementing tokuryū detection rigorously often introduces a screening burden, requiring organisations to weigh faster onboarding against deeper behavioural review and richer telemetry.

  • Recruitment over social media or job sites where the apparent contact changes frequently, but the tasking pattern remains similar across incidents.
  • Fraud or extortion campaigns that use disposable accounts, temporary infrastructure, and short-lived communications to obscure the organiser chain.
  • Cross-case linkage analysis that focuses on payment rails, device fingerprints, and repeated tradecraft instead of relying on stable group names.
  • Platform trust and safety workflows that flag coordinated behaviour when accounts are newly created, highly transient, or operated in bursts across regions.
  • Analyst review that correlates communications, logistics, and timing to separate opportunistic actors from structured, repeatedly reassembled networks.

For security teams building investigation playbooks, the Ultimate Guide to NHIs is useful because it frames why identity assurance must extend beyond static identifiers. In adjacent identity governance work, the same logic appears in NIST Cybersecurity Framework 2.0 when organisations map relationships and detect anomalous activity across changing entities.

Why It Matters in NHI Security

Tokuryū matters because anonymous, re-forming groups create a screening problem that looks similar to NHI sprawl: the entity of concern may not remain stable long enough to be managed by a simple list, yet it can still coordinate harmful activity through transient identities and disposable access paths. That is why conduct, provenance, and relationship analysis become more important than label matching.

This issue also mirrors the governance challenge described in Ultimate Guide to NHIs, where weak visibility into non-human identities leads to blind spots in who or what is actually operating inside the environment. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts, which is a useful reminder that unknown or unstable actors are harder to govern than well-inventoried ones.

Practitioners should treat tokuryū as a warning about identity systems that assume permanence where none exists. Organisations typically encounter the operational impact only after repeated abuse patterns emerge across fresh accounts or newly created channels, at which point tokuryū-style investigation becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 Anonymous, shifting identities stress inventory and discovery controls for non-human actors.
NIST CSF 2.0 ID.AM-1 Tokuryū-like networks require asset and relationship awareness to spot repeated patterns.
NIST Zero Trust (SP 800-207) SP 800-207 Zero Trust assumes no implicit trust in identities that change form or provenance.
NIST SP 800-63 IAL2 Identity assurance concepts help distinguish claimed identity from observed behavior.
OWASP Agentic AI Top 10 LLM-01 Tool-enabled autonomous actors can mask provenance and change behavior rapidly.

Continuously identify, correlate, and review changing identities instead of relying on static allowlists.