October 8, 2026

Ransomware attack disrupts Japan’s IDCF Cloud used by govt clients

IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country.

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country.

The company says that the attack started on October 7 at 3:40 AM local time, forcing a shutdown of the network and system.

“Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party,” reads IDFC Cloud’s announcement.

“We are continuing to investigate the precise cause and the scope of the impact,” the company added.

The firm said the attack impacts 495 companies and local governments using its cloud service.

The IDCF Cloud infrastructure-as-a-service platform is operated by IDC Frontier, a subsidiary of SoftBank Group, a multinational investment holding company based in Tokyo.

The firm rents out virtual servers, storage, and networking that customers use to run websites, applications, and business systems in Japanese data centers.

After detecting the attack, IDC Frontier isolated and shut down impacted systems in ‘East Japan Region 1’ to prevent the compromise from spreading.

Currently, the company is working to identify and block the intrusion route and check security in other regions.

IDCF Cloud has proactively disabled customer access to management consoles for all regions while it verifies their security, and will restore access after confirming it is safe to do so.

Screenshots from customers before they were locked out of the console show a message from the threat actor claiming that it took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure.

The threat actor claims they encrypted 225 databases corresponding to 3.6 PB of data, reached 239 hypervisors, sealed 16,000 VM disks, and wiped 554,153 snapshots.

Note

Message seen by IDFC Cloud clients on the platform console

Source:

j416dy

Nissui also hit

Japanese marine products company Nissui Corporation announced yesterday that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.

As a result, goods are not being shipped or received, and the company is currently investigating whether personal information or customer data was leaked.

Nissui is a Japanese seafood and food group with approximately 11,500 employees and an international supply chain spanning fishing, aquaculture, processing, and sales.

It is unclear if the outage at Nissui is connected to the attack on IDCF Cloud.

Recently, several major Japanese companies were targeted in cybersecurity attacks, Macnica researcher Yutaka Sejiyama says.

Since the start of the year, Macnica logged 119 cybersecurity incidents involving personal information theft or exposed data, 83 occurring between July 1 and October 6.

For comparison, the security firm recorded 84 incidents in 2025 using the same criteria, and just 62 throughout 2024.

Number of confirmed cyberattacks against Japanese entities

Number of confirmed cyberattacks against Japanese entities

Source: Macnica

Analysis of these incidents shows that attackers are probing websites and APIs for access-control, configuration, and authentication weaknesses, and exploiting known (n-day) vulnerabilities.

Sejiyama told BleepingComputer that finding weaknesses specific to individual websites has traditionally required considerable time and effort, making small targets less attractive.

The rise of capable, cheap AI tools may be the reason why broad, detailed exploration of security weaknesses is now changing the landscape.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Originally published on BleepingComputer