Skip to content

Security2 publishersAlso reported elsewhere2 min readPublished

Ransomware in one IDCF Cloud region hits 495 companies and local governments

IDC Frontier says ransomware in its IDCF Cloud East Japan Region 1 has affected 495 companies and local governments using the service. The SoftBank Group subsidiary has also locked customers out of management consoles in every region while it verifies their security.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Ransomware in one IDCF Cloud region hits 495 companies and local governments
Generated illustration

What happened

  • The attack began at 3:40 AM local time on October 7 and forced a shutdown of the network and systems in East Japan Region 1.
  • Screenshots customers took before the console lockout show a message in which the attacker claims it needed seven minutes to breach the region.
  • The attacker also claims it encrypted 225 databases holding 3.6 PB, reached 239 hypervisors, sealed 16,000 VM disks and wiped 554,153 snapshots.
  • Nissui Logistics stopped shipping and receiving goods after suspected unauthorized access to a third-party data center it uses.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint IDC Frontier's own containment is part of the outage: shutting the region to stop the spread took tenants' hosted systems offline whether or not the attacker reached each one.
  • cost If the snapshot claim holds, tenants that used IDCF Cloud snapshots as their backups have lost those recovery points and must restore from copies kept off the platform.
  • exposure Until the intrusion route is identified and blocked, customers in IDC Frontier's other regions cannot rule out the same path into their own environments.

IDC Frontier has confirmed the ransomware and the customer count [1][4]. "Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party," the company said in its announcement [3]. "We are continuing to investigate the precise cause and the scope of the impact," it added [19].

The company did not publish figures for encrypted data, hypervisors or snapshots. Those numbers come from the attacker's own message, which customers captured in screenshots [10][11]. They are the attacker's claims until IDC Frontier confirms or disputes them.

IDCF Cloud rents out virtual servers, storage and networking, and customers use them to run websites, applications and business systems in Japanese data centers [6]. The attacker says it reached 239 hypervisors [11]. If that is accurate, the intruder was working at the layer that runs those virtual servers. One breach there was enough to disrupt 495 companies and local governments [4].

For tenants, the snapshot claim matters most because it decides how they recover. Set 554,153 wiped snapshots against 16,000 sealed disks and the attacker is claiming about 35 recovery points destroyed for every disk it locked [20].

BleepingComputer reports that it is unclear whether the Nissui Logistics outage is connected to the IDCF attack [14]. Nissui, a seafood and food group with about 11,500 employees, is investigating whether personal information or customer data leaked [13].

The wider count from Macnica covers a different kind of incident: personal-data theft or exposed data [15]. The security firm logged 119 such incidents since the start of the year, 83 of them between July 1 and October 6 [15]. That leaves 36 for the first six months [21]. Under the same criteria it counted 84 in all of 2025 and 62 in 2024 [16].

In those incidents, attackers probed websites and APIs for access-control, configuration and authentication weaknesses and exploited known vulnerabilities, according to Macnica's analysis [17]. Macnica researcher Yutaka Sejiyama told BleepingComputer that finding weaknesses specific to individual websites has traditionally taken considerable time and effort. That effort made small targets less attractive, he said [18]. BleepingComputer suggests that cheap, capable AI tools may be why that is changing [22].

What to watch

  • IDC Frontier's finding on the intrusion route, and the results of its security checks in regions outside East Japan Region 1.
  • Whether IDC Frontier confirms or disputes the attacker's hypervisor, disk and snapshot figures, and whether customer data was taken as well as encrypted.
  • Whether Nissui names the third-party data center behind its logistics outage.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    IDC Frontier disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving eastern Japan, East Japan Region 1.

    ReportedSupportedView cited source
  2. [2]

    The attack started on October 7 at 3:40 AM local time, forcing a shutdown of the network and system.

    ReportedSupportedView cited source
  3. [3]

    "Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party,"

    ReportedSupportedSource: IDC Frontier announcementView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 8, 2026

    Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
  2. dev.to

    1 article · October 7, 2026

    What Are You Sacrificing for Convenience? Rethinking Backups After the IDCF Outage

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories