Japan had an exceptionally heavy week of cybersecurity news. Companies disclosed data breaches affecting tens of millions of records, a ransomware attack on a domestic cloud provider spread to hundreds of its customers, and the government responded with warnings and requests from eight agencies. This is our summary of the week, with links to our full coverage.

The week in numbers

  • Disclosures this week covered more than 50 million records in total. Most figures are maximums or "may have leaked", and many overlap, so the number of people affected is lower. It is still larger than any week we have covered.
  • 495 companies and local governments were hit by the IDCF Cloud ransomware attack.
  • 8 government agencies issued warnings or requests, most of them between October 7 and 9.
Disclosure Records (maximum) Status
skyticket (travel booking) 14.64 million Taken
Yakiniku King (restaurant app) 10.79 million Taken
Daiichikosho (karaoke) 8.72 million Possible
IDCF Cloud customers: JR East, View Card, JR Kyushu 7.39 million Possible
Bookoff (used goods) 6.43 million Taken
Lawson (convenience stores) 2.16 million Taken
Mr Max (discount stores) 1.74 million Taken
infoQ (surveys) 948,000 Taken
i-ask (FAQ system, 5 clients) 713,000 Possible
Seicomart (convenience stores) 575,000 Viewed
Asahi Kasei Therapeutics (pharma) 514,000 Possible

The IDCF Cloud ransomware attack#

The biggest single incident of the week was the ransomware attack on IDCF Cloud, a public cloud run by SoftBank's IDC Frontier, from about 03:40 on October 7. It affected 495 companies and local governments, including the websites of Ibaraki Prefecture and its police, business phone services and Nissui's cold-chain logistics subsidiary. IDC Frontier says customer data in four zones of its East Japan Region 1 is unlikely to be recoverable, and that customers can restore only from their own backups.

By October 9, JR East, its card unit View Card and JR Kyushu said email delivery services hit by the attack may have exposed data for up to about 7.39 million records, mostly email addresses. E-commerce platform FutureShop said its email servers on IDCF Cloud held recipient addresses and parts of email bodies. IDC Frontier itself has not said whether any data was taken.

Large breaches at consumer services#

  • Yakiniku King: member numbers, names, emails and phone numbers of almost every user of the restaurant chain's app, 10.79 million accounts.
  • Bookoff: names, birth dates, addresses and password hashes for up to 6.43 million member numbers. The company says it fixed a vulnerability.
  • Lawson: data tied to 2.15 million Lawson ID accounts, taken in mid-September through "a security mechanism" meant to show app users their own data, and found only on October 7.
  • Seicomart: the Hokkaido convenience store chain confirmed that data on 574,647 members was viewed through its app's server.
  • infoQ: every member record of GMO Research & AI's survey site was taken, and 611 members' points were cashed out as Amazon gift codes.
  • Rakuten Drive: attackers used stolen administrator credentials to view files of 15,382 users for eight months.

Breaches through vendors#

  • i-ask: a breach of Scala Communications' FAQ system exposed up to 713,000 customer inquiries stored for up to five clients, including Daiwa Securities, Citizen Watch and Sompo Japan.
  • Asahi Kasei Therapeutics: data on up to 514,000 healthcare professionals in Japan was exposed through the vendor running its information site for doctors. It was the company's second contractor-related leak this year.
  • Nikkei: Japan's business daily disclosed two more account takeovers, in Microsoft 365 and Google Workspace. Phishing from one of them reached group company Nikkei BP.

Other disclosures this week#

We did not cover most of these separately. Each is based on the company's own notice.

  • skyticket: Adventure, Inc., operator of the travel booking site, disclosed three separate intrusions. The largest, on October 2–4, involved manipulation of some admin functions, then access to other servers and cloud storage, exposing about 14.64 million customer records: names including passport spellings, birth dates, emails, phone numbers and addresses, plus hashed passwords for about 4.13 million members. Passport numbers were not taken. A separate attack on September 20 exposed refund bank account details for 17,780 records, and bus booking pages were viewable without logging in for two months. The company has stopped payments with saved cards and is asking members to change their passwords.
  • Daiichikosho: the operator of the Big Echo karaoke chain said a PC belonging to an employee at a contractor, Nippon Columbia Group, was infected with malware. It held data on about 8.72 million customers and employees: names, birth dates, emails and phone numbers. A leak has not been confirmed.
  • Mr Max: the discount store chain said attackers misused functions of the software behind its app and online store and took member IDs, names, emails and phone numbers for up to 1.74 million members.
  • NewsPicks: Uzabase said a business tool used by its news app was accessed without authorization, possibly exposing users' names, employers, emails, addresses, phone numbers and the last digits of card numbers. It has not said how many users are affected.
  • H.I.S.: the travel agency said a file server at its Thai subsidiary, breached in December 2025, held passport details for up to 627 customers who traveled to Thailand.

Arrests and investigations#

  • Qilin: Japan's National Police Agency and Germany's North Rhine-Westphalia confirmed that a 28-year-old Russian believed to be a leading member of the Qilin ransomware group was detained in Japan in May and handed to Germany on October 2, despite the lack of an extradition treaty. German investigators say they had infiltrated the group.
  • Osaka Metropolitan University: the university confirmed ransomware took down about 500 servers and most backups. Classes resumed on October 9 on temporary systems.
  • Ransomware statistics: we updated our explainer with the NPA's data on which groups are behind Japan's cases, and the police's decryption tools, used for 41 victim companies so far.

The government responds#

  • October 7: the Personal Information Protection Commission warned companies holding large volumes of personal data, and added API abuse to its list of breach patterns.
  • October 8: JPCERT/CC described the attack patterns behind the wave, including abuse of internal APIs found by analyzing smartphone apps, and published attacker IP addresses. On October 9 it added web shells planted on Java application servers. The government held an inter-ministerial meeting.
  • October 9: the National Cybersecurity Office, IPA, METI, MIC and the Financial Services Agency issued their own warnings. The FSA asked banks to stop accepting uploaded ID photos for online identity checks before the April 2027 deadline, after millions of license images leaked in the Times Car breach. Our summary of the government's response covers each one.

What to watch next week#

  • IDCF Cloud: whether IDC Frontier says if data was taken, and whether more customers of the same email delivery services come forward
  • Times Car: individual notices on what was taken for each member, expected around October 13
  • skyticket, Bookoff and Lawson: how many people are affected, and how the attackers got in
  • The government: how the National Cybersecurity Office will collect information from victims, and the rental car industry's report to the transport ministry, due October 30

If you have been a customer of any of these services, expect phishing emails, SMS and calls that use your real details. Change any password you reused, and reach companies through their official websites or apps rather than links in messages.