IDCF Cloud ransomware attack disrupts service for 495 Japanese companies and local governments
IDC Frontier, a leading Japanese cloud and digital infrastructure company, has disclosed a ransomware attack against its IDCF Cloud service that caused an outage in a data center cluster serving eastern Japan.
The company said the attack began at 3:40 a.m. local time on October 7 and forced it to shut down the affected network and systems.
“Our investigation revealed that the disruption in East Japan Region 1 was caused by a third-party ransomware attack.” Read the IDCF Cloud announcement.
IDC Frontier said it is continuing to investigate the exact cause and scope of the incident. The attack affected 495 companies and local governments that use the cloud provider’s services.
Attack forces IDCF Cloud to isolate East Japan Region 1
IDCF Cloud is an infrastructure-as-a-service platform operated by IDC Frontier, a subsidiary of SoftBank Group, a Tokyo-based multinational investment holding company.
The company provides virtual servers, storage, and networking that customers use to operate websites, applications, and business systems in data centers across Japan.
After detecting the ransomware attack, IDC Frontier isolated and shut down the affected systems in East Japan Region 1 to prevent the incident from spreading.
“We are currently working to identify and block intrusion routes and confirm the safety of other areas,” the company said.
IDCF Cloud also said it would proactively disable customer access to the Admin Console in all regions while it validates the security of the platform. Access will be restored once the company determines that it is safe.
Attackers claim to have encrypted 225 databases
A screenshot taken by a customer before access to the console was blocked shows a message from the attackers claiming that they compromised the IDCF Cloud East Japan Region 1 infrastructure in seven minutes.
The attackers claim to have encrypted 225 databases containing 3.6 petabytes of data, accessed 239 hypervisors, sealed 16,000 virtual machine disks, and wiped 554,153 snapshots. These claims have not been independently verified.

Source: j416dy
Nissui logistics systems also disrupted
Japanese seafood company Nissui Co., Ltd. also reported a systems outage at Nissui Logistics, its logistics subsidiary. The company said the disruption was caused by suspected unauthorized access to a third-party data center used by the business.
As a result, products could not be shipped or received. Nissui is investigating whether personal information or customer data was exposed.
Nissui is a Japanese seafood and food group with approximately 11,500 employees and an international supply chain spanning fishing, aquaculture, processing, and sales.
It remains unclear whether the Nissui outage is related to the ransomware attack against IDCF Cloud.
Cyberattacks against Japanese companies continue to rise
Several major Japanese companies have recently been targeted by cybersecurity attacks, according to Macnica researcher Yutaka Sechiyama.
Since the beginning of this year, Macnica has recorded 119 cybersecurity incidents. The company identified 83 incidents involving identity theft and data breaches between July 1 and October 6.
Using the same criteria, Macnica recorded 84 incidents in 2025, compared with 62 incidents during all of 2024.

Source: Macnica
Analysis of these incidents shows that attackers are targeting weaknesses in website and API access controls, security configurations, and authentication systems. They are also exploiting known, or n-day, vulnerabilities.
Sechiyama told BleepingComputer that identifying unique weaknesses in individual websites has traditionally required considerable time and effort, making smaller targets less attractive to attackers.
However, the rise of powerful and inexpensive artificial intelligence tools may be changing the situation by enabling attackers to conduct broader and more detailed searches for security weaknesses.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



