A major ransomware attack on Japanese cloud provider IDC Frontier has disrupted services across the country, affecting 495 companies and local government organizations, including railway operators, police services, food logistics businesses, and online platforms. The incident has also raised concerns about customer data that may be impossible to recover.
IDC Frontier, owned by SoftBank, provides cloud infrastructure for businesses and public-sector organizations in Japan. The incident highlights the risks of relying on a single cloud provider, where an attack against one part of the infrastructure can trigger widespread disruption across multiple industries.
In an update published on Thursday, IDC Frontier confirmed that four cloud zones had suffered severe damage. Some customers may need to rebuild their systems in other environments and recover their information using their own backups.
The company warned that recovering customer data stored in part of its East Japan Region 1 could be difficult. It said restoration would depend on backup data held by individual customers, raising the possibility of permanent data loss for organizations without usable copies.
The attack reportedly occurred in the early hours of Wednesday, taking some servers offline. IDC Frontier has not publicly confirmed how the attackers gained access, who was responsible, whether a ransom was demanded, or whether customer information was stolen in addition to being encrypted.
Meanwhile, screenshots circulating on social media and attributed to the attackers contain the message “Your Cloud is Ours.” The alleged attackers claimed they compromised 239 systems running virtual machines, encrypted 3.6 petabytes of data across 225 storage systems, locked more than 16,600 virtual machine disks, and deleted 554,153 backup snapshots. They also claimed the operation took just seven minutes.
These figures remain unverified claims attributed to the alleged attackers and should not be treated as independently confirmed findings.
Among the affected organizations, Japanese railway operator JR East and its credit-card subsidiary View Card reported potential exposure involving email-delivery services hosted on IDCF Cloud. The companies said up to 6.09 million records may have been accessed. Both stated that credit card numbers, home addresses, and telephone numbers were not exposed. Railway operator JR Kyushu also reported an impact involving approximately 1.3 million emails.
The incident has also affected businesses involved in Japan’s food distribution network. Nissui Logistics, a frozen-food warehouse operator, reported a system failure that prevented it from receiving and shipping goods. The company operates 17 cold-storage and distribution centers with a combined capacity of around 400,000 tonnes, serving manufacturers, retailers, wholesalers, shops, and restaurants.
Other organizations reported or believed to be affected include Ibaraki Prefectural Police, news agency Jiji Press, travel booking company Adventure, karaoke operator Daiichikosho, e-commerce platform FutureShop, and a fan messaging service associated with the Japanese girl group SKE48. The full extent of the disruption remains unclear as more customers investigate their exposure.
The incident demonstrates how a cyberattack against a cloud provider can spread beyond digital services and affect transportation, logistics, communications, and other essential operations. When several organizations depend on the same infrastructure, a single incident can create a wider supply-chain crisis.
Japan’s National Cybersecurity Office has also urged government ministries, local authorities, and private companies to strengthen their cybersecurity defenses. Its recommendations include keeping security protections updated, using strong passwords, and improving security across supply chains.
The office warned that cybersecurity threats are becoming increasingly complex, including as artificial intelligence changes the threat landscape. For organizations using cloud infrastructure, the incident also underscores the importance of maintaining independent backups, testing recovery procedures, and preparing plans to restore critical services if a provider becomes unavailable.
IDC Frontier continues to investigate the incident and its impact. Until the company and affected customers complete their assessments, the total amount of data lost or exposed, the attackers’ identity, and the full extent of the disruption remain uncertain.
Ransomware Attack on Japanese Cloud Provider Disrupts 495 Organizations



