
Cyberattack on Japanese cloud provider disrupts 495 organizations, railways and police
A ransomware attack on Japanese cloud provider IDC Frontier has affected 495 companies and local government services, disrupting railways, police, food logistics and e-commerce across the country.
Ransomware hits Japanese cloud provider
A ransomware attack on IDC Frontier (IDCF) Cloud, a Japanese cloud provider owned by OpenAI investor SoftBank, has affected 495 companies and local government services. IDCF Cloud is one of the main domestic alternatives to AWS, Microsoft Azure and Google Cloud, aimed at companies and public bodies that want their systems run on sovereign turf.
IDCF said the breach took place in the early hours of Wednesday, knocking some servers offline. In an update on Thursday, the company confirmed that four cloud zones were so badly damaged that customers would need to rebuild their systems elsewhere and restore data from their own backups. IDC Frontier has not said how the attackers got in, who was responsible, whether they demanded money, or how much information was stolen rather than just encrypted.
Millions of records potentially exposed
JR East, Japan's largest railway operator, and credit card company View Card confirmed that up to 6.09 million records may have been accessed through email delivery services using IDCF Cloud, while JR Kyushu reported 1.3 million emails. Both say credit card numbers, home addresses and telephone numbers were not exposed.
Screenshots claiming to be from the attackers have been circulating on social media, showing messages stating "Your Cloud is Ours." The messages claim the attackers accessed 239 systems running virtual machines, locked 225 large storage systems holding 3.6 petabytes of data, sealed more than 16,600 virtual machine hard drives and deleted 554,153 backup snapshots. The threat actor claims the attack took just 7 minutes.
Supply chain disruption spreads
The fallout has disrupted services tied to railways, police, food logistics, travel, karaoke and e-commerce. Frozen food warehouse operator Nissui Logistics has reportedly suffered a systems outage preventing it from receiving and shipping goods. Nissui operates 17 cold storage and distribution centers with around 400,000 tonnes of capacity.
Other organizations thought to be caught up in the attack include Ibaraki Prefectural Police, news agency Jiji Press, messaging app for the Japanese girl band SKE48, travel booking company Skyticket, karaoke operator Daiichikosho and e-commerce platform FutureShop. Only a handful of firms have gone public so far, and more customer data breaches are likely to be disclosed as companies investigate their exposure.
Government urges stronger defenses
On Friday the National Cybersecurity Office sent instructions to government ministries, which will distribute them to local public bodies and private companies. It warned that this is no longer just a problem for the information systems department, urging organizations to carry out basic cyber security hygiene such as updated security protections, strong passwords and tighter cybersecurity guards throughout supply chains. The office also warned that AI is making vulnerabilities increasingly complex.
Sources: Cybernews
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.