IDCF Cloud ransomware attack hits 495 Japanese customers

IDCF Cloud ransomware attack hits 495 Japanese customers

IDC Frontier, a large Japanese cloud and digital infrastructure provider, has confirmed that a ransomware attack knocked out part of its IDCF Cloud service. The outage hit a data center cluster serving eastern Japan, and the company says 495 companies and local governments use the affected service.

The attack began on October 7 at 3:40 AM local time. IDC Frontier responded by shutting down the network and systems involved.

"Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party," the company said in its announcement. It added that it is "continuing to investigate the precise cause and the scope of the impact."

A SoftBank-owned IaaS platform

IDCF Cloud is an infrastructure-as-a-service (IaaS) platform. Customers rent virtual servers, storage and networking hosted in Japanese data centers, and use them to run websites, applications and business systems. IDC Frontier is a subsidiary of SoftBank Group, the Tokyo-based multinational investment holding company.

Once the intrusion was detected, IDC Frontier isolated and powered down the affected systems in "East Japan Region 1" to stop the compromise from spreading. The company is now trying to find and block the route the attackers used to get in, and is checking the security of its other regions.

As a precaution, IDCF Cloud has also cut off customer access to management consoles across all regions, not only the affected one. Access will be restored once the company has confirmed it is safe.

Attackers claim a seven-minute breach

Some customers took screenshots of their consoles before they were locked out. These show a message from the threat actor, who claims it needed only seven minutes to break into the East Japan Region 1 infrastructure.

According to the attackers' own figures, they:

  • encrypted 225 databases holding 3.6 PB of data
  • reached 239 hypervisors
  • sealed 16,000 VM disks
  • wiped 554,153 snapshots

These claims come from the attackers and have not been confirmed by IDC Frontier. If accurate, the wiped snapshots would be especially damaging, since snapshots are often used to restore systems after an incident.

Nissui logistics arm also down

In a separate announcement, Japanese marine products company Nissui Corporation said its logistics subsidiary, Nissui Logistics, suffered a system outage after suspected unauthorized access to a third-party data center it relies on.

Goods are currently not being shipped or received, and Nissui is investigating whether personal information or customer data was leaked. The group has around 11,500 employees and a supply chain that covers fishing, aquaculture, processing and sales worldwide.

It is not clear whether the Nissui outage is linked to the IDCF Cloud attack.

A sharp rise in Japanese incidents

The incident adds to a series of attacks on major Japanese organizations, said Yutaka Sejiyama, a researcher at security firm Macnica. Since the start of the year, Macnica has recorded 119 incidents involving stolen or exposed personal data, 83 of which took place between July 1 and October 6. Using the same criteria, the firm counted 84 such incidents in all of 2025 and 62 in 2024.

Macnica's analysis shows attackers probing websites and APIs for weak access controls, misconfigurations and authentication flaws, and exploiting known (n-day) vulnerabilities.

Sejiyama told BleepingComputer that hunting for weaknesses specific to individual websites used to take significant time and effort, which made smaller targets less attractive. Cheap and capable AI tools may now be changing that, by making broad and detailed searches for security gaps much easier.

Why It Matters

For organizations that rely on cloud providers, the IDCF Cloud incident shows how a single breach at the infrastructure layer can hit hundreds of customers at once, including local governments. The attackers' claims about hypervisors and wiped snapshots suggest a focus on destroying recovery options, not only encrypting data. Customers may want to check whether their backups exist outside their provider's environment.

The attack also fits a wider pattern. Japan has seen a run of incidents this year, including the suspected ransomware attack on Osaka Metropolitan University and the Nikkei account compromise. Macnica's numbers point in the same direction, and its view on AI matches other cases where AI-discovered flaws were later exploited. It is worth watching whether IDC Frontier names the intrusion route, whether any group publicly claims the attack, and whether the Nissui outage turns out to be connected.