Breaking
Cyber CrimeDeveloping Story

Ransomware Hits Japanese Cloud Serving 495 Orgs

IDC Frontier says a ransomware attack on its IDCF Cloud disrupted East Japan Region 1 and locked 495 companies and local governments out of management consoles.

··1 hour ago·6 min read
cable network
Photo by Taylor Vick on Unsplash

A ransomware attack on a major Japanese cloud provider forced an outage at a data center cluster serving the eastern part of the country, the company has disclosed. IDC Frontier, a subsidiary of SoftBank Group, said the disruption at its IDCF Cloud service began on October 7 at 3:40 AM local time and prompted a shutdown of the network and system. The firm said the attack impacts 495 companies and local governments that rely on the platform.

What IDCF Cloud Actually Runs

IDCF Cloud is an infrastructure-as-a-service platform operated by IDC Frontier, which rents out virtual servers, storage, and networking to customers who use them to run websites, applications, and business systems in Japanese data centers. Because the service underlies other companies' operations rather than serving consumers directly, an outage at the infrastructure layer can ripple outward to every tenant hosted on it.

According to IDC Frontier, the disruption was confined to a single cluster, labeled East Japan Region 1. The company said it moved to isolate and shut down the affected systems after detecting the intrusion, in an effort to stop the compromise from spreading further.

The Attack Timeline

IDC Frontier dates the start of the incident to October 7 at 3:40 AM local time. In the days since, the company said it has been working to identify and block the intrusion route and to verify security in its other regions.

“Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party,” reads the company's IDFC Cloud announcement.

“We are continuing to investigate the precise cause and the scope of the impact,” the company added.

Consoles Locked While Checks Continue

Beyond the regional outage, IDCF Cloud has disabled customer access to management consoles across all regions while it verifies their security. The company said it will restore that access only after confirming it is safe to do so — a step that extends the disruption beyond the region that was directly hit.

Screenshots captured by customers before they were locked out of the console show a message from the threat actor. In that message, the attacker claims it took seven minutes to breach the East Japan Region 1 infrastructure.

What the Attacker Claims

The same message attributes a list of specific figures to the intrusion. According to the threat actor's claim, as seen in the screenshots, the attackers encrypted 225 databases corresponding to 3.6 PB of data, reached 239 hypervisors, sealed 16,000 VM disks, and wiped 554,153 snapshots.

Those numbers come from the attacker's own message, not from IDC Frontier, which has not confirmed them. The company's public statements so far describe an ongoing investigation into the cause and scope of the incident rather than a completed damage assessment.

A Second Outage at Nissui

The IDCF Cloud incident is not the only disruption reported in Japan around the same period. Japanese marine products company Nissui Corporation announced yesterday that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.

As a result, goods are not being shipped or received, and the company said it is investigating whether personal information or customer data was leaked. Nissui is a Japanese seafood and food group with approximately 11,500 employees and an international supply chain spanning fishing, aquaculture, processing, and sales.

It is unclear whether the outage at Nissui is connected to the attack on IDCF Cloud. Neither company has stated that the two incidents are linked.

A Rising Incident Count in Japan

The two disclosures arrive against a backdrop of increased attack activity against Japanese organizations. Macnica researcher Yutaka Sejiyama says several major Japanese companies were targeted in cybersecurity attacks recently.

Since the start of the year, Macnica logged 119 cybersecurity incidents involving personal information theft or exposed data, with 83 of those occurring between July 1 and October 6. For comparison, the security firm recorded 84 incidents in 2025 using the same criteria, and just 62 throughout 2024.

Analysis of the incidents shows attackers probing websites and APIs for access-control, configuration, and authentication weaknesses, and exploiting known — so-called n-day — vulnerabilities. Those categories describe flaws that are already publicly documented, which means the barrier to exploiting them is lower than finding a new bug from scratch.

Sejiyama told BleepingComputer that finding weaknesses specific to individual websites has traditionally required considerable time and effort, which made small targets less attractive to attackers. He suggested the rise of capable, cheap AI tools may be the reason broad, detailed exploration of security weaknesses is now changing that calculation.

Where the Investigation Stands

IDC Frontier has not said how the attackers got in, how long they were present before the October 7 disruption, or whether customer data was taken. Its statement says only that the investigation into the precise cause and the scope of the impact is continuing, and that work is underway to identify and block the intrusion route.

For the 495 affected companies and local governments, the practical situation is twofold: the region hosting their workloads was shut down, and management access to other regions was suspended as a precaution. Restoration of console access depends on the company completing its security checks.

Because IDCF Cloud is a subsidiary operation of SoftBank Group, the incident also touches an infrastructure provider with a large corporate parent — though SoftBank Group has not issued a separate statement in the material reviewed here.

Why This Matters Beyond One Provider

Cloud outages tied to ransomware put two distinct pressures on customers at once. The first is continuity: when a provider shuts down a region to contain an intrusion, tenants can lose access to systems they did not directly compromise. The second is trust in the shared security model — customers renting virtual servers, storage, and networking are relying on the provider to keep the underlying platform sound, and an incident at that layer is largely outside their control.

The decision to disable management consoles in all regions, not just the affected one, suggests how cautious providers can become when the intrusion route is still unknown. For customers, that precaution cuts both ways: it may limit further damage, but it also extends the window in which they cannot administer their own environments.

The broader incident data from Macnica suggests that many attacks are succeeding through mundane, already-known weaknesses in websites and APIs rather than novel exploits. If that pattern holds, the exposure facing Japanese organizations may have less to do with sophisticated new tooling and more to do with unpatched n-day flaws and misconfigured access controls that attackers can scan for at scale. The suggestion that cheap AI tooling is lowering the cost of that scanning is an observation from one researcher, not a measured industry-wide trend, but it points to a practical question for defenders: whether their internet-facing systems would survive a broad, automated sweep for known weaknesses.

For now, the two Japanese incidents remain under investigation, and the figures describing the IDCF Cloud damage come from the attacker rather than the victim. Until IDC Frontier completes its review, the confirmed facts are narrower than the claims: a ransomware attack, a regional shutdown, suspended console access, and 495 affected customers.

#ransomware#cloud security#japan#idcf cloud#data center outage

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories