Japan’s IDCF Cloud Hit by Ransomware Attack, Disrupting Services for 495 Government Clients and Companies
A devastating ransomware attack has struck Japan’s IDCF Cloud, a major cloud and digital infrastructure service provider that caters to government clients and over 495 companies. The attack, which began on October 7 at 3:40 AM local time, forced the shutdown of a data center cluster serving the eastern part of the country, causing widespread disruptions.
IDC Frontier, the company behind IDCF Cloud, has confirmed that the attack was caused by a ransomware assault by an unidentified third-party threat actor. The firm’s investigation is ongoing to determine the precise cause and scope of the impact. However, it’s clear that the attackers claimed responsibility for encrypting 225 databases corresponding to 3.6 petabytes of data, reaching 239 hypervisors, sealing 16,000 virtual machine disks, and wiping out 554,153 snapshots.
The IDCF Cloud infrastructure-as-a-service platform is operated by IDC Frontier, a subsidiary of SoftBank Group, a multinational investment holding company based in Tokyo. The firm rents out virtual servers, storage, and networking services that customers use to run websites, applications, and business systems within Japanese data centers.
As a result of the attack, IDCF Cloud has taken measures to isolate and shut down impacted systems in ‘East Japan Region 1’ to prevent further compromise. The company is also working to identify and block the intrusion route and verify security in other regions. In the meantime, customer access to management consoles for all regions has been disabled proactively while they are being checked.
The attack highlights a concerning trend in cybersecurity attacks targeting Japanese companies. According to Macnica researcher Yutaka Sejiyama, several major Japanese firms have been targeted recently, with 119 incidents logged since the start of the year involving personal information theft or exposed data. The analysis suggests that attackers are exploiting known vulnerabilities and probing websites and APIs for weaknesses in access-control, configuration, and authentication.
The rise of capable, cheap AI tools may be driving this surge in attacks, making it easier for threat actors to identify and exploit security weaknesses. This shift changes the cybersecurity landscape, requiring defenders to adapt quickly to stay ahead of attackers.
In light of these developments, businesses using cloud services should take immediate action to review their security posture and ensure they are prepared for potential AI-powered attacks. This includes conducting regular vulnerability assessments, implementing robust access controls, and staying up-to-date with the latest security patches and updates.
With the increasing reliance on cloud infrastructure, it’s essential that companies prioritize cybersecurity measures to prevent similar disruptions in the future. As we continue to navigate the evolving threat landscape, one thing is clear: businesses must be proactive in protecting themselves from these types of attacks or risk facing significant downtime and potential data breaches.
Source: Bleeping Computer — 2026-10-08