Skip to content
Security & Trust

One ransomware attack on a Japanese cloud affects 495 customers

IDCF Cloud has locked customers out of consoles in every region. Your recovery plan depends on your provider's choices.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
One ransomware attack on a Japanese cloud affects 495 customers
In brief
  • IDC Frontier says ransomware hit its East Japan Region 1 on October 7, affecting 495 companies and local governments, and it has suspended management consoles in other regions.
  • The lockout shows that a customer's recovery depends on the provider's decisions. An attacker claims to have wiped snapshots, which IDCF has not confirmed.
  • Ask your team where backups live, whether they can be restored without the provider's console, and what your contract says about notice.

A cloud region is shared ground. When something goes wrong in one room, every tenant in that room is affected, and the provider may lock the hallways too. The attack on IDCF Cloud in Japan shows a second point: your resilience plan ends where your provider's control panel begins.

What happened

IDC Frontier (IDCF), a SoftBank Group subsidiary, says ransomware caused an outage in its IDCF Cloud service. The trouble began around 3:40 am Japan time on Wednesday, October 7, in a cluster called East Japan Region 1. IDCF says 495 companies and local governments contract the service. It says it has contacted them individually.

IDCF cut the region off from the network and then shut its systems down. It says this was to prevent secondary damage and data leaks. It is still investigating the cause and the full scope.

495
Companies and local governments contracting IDCF Cloud
Source: IDC Frontier incident notice (October 7, 2026)

The lockout reaches past the damaged region

IDCF also suspended the customer-facing management consoles for regions other than East Japan Region 1. A management console is the web control panel where customers start, stop and restore their servers. IDCF says it will reopen the consoles once it confirms they are safe.

That caution is reasonable. It also has a cost. While the consoles are closed, customers cannot act on their own systems. The notice does not say whether workloads outside East Japan Region 1 are still running.

The lesson here is that in a provider-side incident, your recovery runs on someone else's timetable. You can have a good plan and still be unable to carry it out.

What the attacker claims

BleepingComputer reports that customers saw a message from the attacker before they were locked out. The message claims it took seven minutes to breach East Japan Region 1. It also claims 225 databases holding 3.6 PB of data were encrypted, 239 hypervisors were reached, 16,000 VM disks were sealed and 554,153 snapshots were wiped.

These are the attacker's claims. IDCF's notice does not confirm them.

Some terms help here. A hypervisor is the software that runs many virtual servers on one physical machine. A VM disk is the storage a virtual server uses. A snapshot is a saved copy of a disk at one moment in time.

If the snapshot claim is true, it illustrates a point for any customer. Copies kept inside the same environment as the live data can be reached by the same intruder. In our view, a snapshot is a convenience, not a backup. A backup needs to sit somewhere the same credentials cannot touch.

7 minutes
Time the attacker claims it needed to breach the region (unverified claim)
Source: threat actor message, as reported by BleepingComputer (October 8, 2026)

A rising count, and an open question on cause

Macnica researcher Yutaka Sejiyama told BleepingComputer that his firm logged 119 incidents this year involving stolen personal information or exposed data at Japanese organisations. Of those, 83 occurred between July 1 and October 6. Using the same criteria, Macnica recorded 84 incidents in 2025 and 62 in 2024.

83
Japanese data-theft or exposure incidents logged by Macnica, July 1 to October 6, 2026
Source: Macnica, via BleepingComputer (October 8, 2026)

Two cautions apply. The count covers personal-data theft and exposure, not only ransomware. And IDCF has not said how the attackers got in, so no link to Macnica's findings is established.

BleepingComputer reports that Macnica's review of those incidents points to a common pattern. Attackers test web pages and APIs (the connections that let software talk to software) for gaps in who is allowed in, how systems are set up and how users prove identity. They also go after flaws that are already publicly known.

Sejiyama said that finding the weak spots on any one site used to take a lot of effort. That made small targets less appealing. BleepingComputer's report adds that cheap, capable AI tools may be changing the picture. That is the report's suggestion, not a finding about IDCF.

BleepingComputer also reports that Nissui Logistics halted shipping and receiving after suspected unauthorised access to a third-party data center. It is unclear whether that is connected to the IDCF attack.

Questions to put to your team

First, which cloud providers and regions do our systems and our suppliers' systems depend on? Second, where do our backups sit, and could the credentials that reach our live systems also delete them? Third, can we restore or reroute if the provider's console is closed for days? Fourth, what does our contract say about how fast the provider must tell us, and what we may do on our own? Fifth, have we ever tested a restore without the provider's help?

A cloud region is shared ground. Resilience is whatever you can still do after the landlord locks the door.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: IDC Frontier (IDCF), a SoftBank Group subsidiary.

Share this insight