This page lists ransomware attacks on organizations in Japan disclosed in 2026, as confirmed by the victims themselves. We update it as new attacks are disclosed and as victims publish follow-up reports.

Key takeaways

  • 26 notable attacks so far in 2026, from a cloud provider used by 495 organizations and a railway group to hospitals, universities and a prefecture's radiation monitoring system.
  • Many of the largest data exposures came through IT vendors and contractors: IDCF Cloud, YCC Information System, Ryomo Systems, Medica Publishing and Japan Telenet. One attack on a vendor puts many clients' data at risk.
  • Ransomware groups have claimed 10 of the 26 on their leak sites, most often Qilin (3), according to ransomware.live. These are the attackers' claims, not confirmed by the victims. The other 16, including IDCF Cloud and Keio, have not appeared on the leak sites it tracks.
  • VPN and other network devices keep appearing as the way in, as in the police statistics.
  • This is not a complete list. Japan's police recorded 123 ransomware cases in the first half of 2026 alone, and most victims are never publicly named.

2026 attacks#

Newest first. "Disclosed" is the date of the organization's first public notice. Where an organization has only said ransomware may have been involved, we say so.

* Claimed by shows the ransomware group that listed the organization on its leak site, as recorded by the tracking site ransomware.live. These are the attackers' own claims. They are unverified, and the organizations have not confirmed them. A dash means we found no listing as of October 10, 2026; it does not mean no group was involved.

Disclosed Organization What happened Claimed by*
Oct 7 IDCF Cloud (SoftBank's IDC Frontier, cloud) Virtual servers in its East Japan region stopped, affecting 495 companies and local governments. Data in four zones is likely unrecoverable. JR East, View Card and JR Kyushu say up to about 7.4 million email records may have leaked. –
Oct 2 Osaka Metropolitan University About 500 servers stopped and most backups were encrypted. Classes were cancelled for a week and resumed on October 9 on temporary systems. –
Sep 26 Keio (Tokyo rail and retail group) Business systems at some group companies were disrupted, including card payments at some stores. Trains were unaffected. –
Sep 25 Saga University Files on a network storage device used by administrative staff were encrypted. Work resumed on September 28. Teaching, research and hospital systems were unaffected. –
Sep 24 Ikegami Tsushinki (broadcast and security cameras) Files on some servers were encrypted. The company later found data believed to be its own published on the dark web. Qilin
Sep 3 Tottori Prefecture The main server of the prefecture's environmental radiation monitoring system was encrypted. Monitoring continued through a backup station. The system is separate from the prefecture's administrative network. –
Aug 28 T&K TOKA (printing inks) Ransomware on some systems. Some operations were halted. –
Aug 15 Ryomo Systems (IT services for local governments and companies) Attackers got in through a VPN account. Business and personal data on some servers may have leaked, affecting clients including the city of Isesaki. SafePay
Aug 10 REXT Holdings (WonderGOO, WonderREX, Shinseido stores) Servers and PCs at its headquarters and stores were encrypted, closing some stores and stopping cashless payments. 310 files were later published. Data on about 1.04 million members is treated as possibly leaked. RansomHouse
Aug 6 CEC (IT services) An outage at its Tokyo No. 2 data center. The final report says no data leaked and customer systems are kept in a separate area. –
Jul 14 Five Foxes (Comme Ça fashion brands) Said ransomware infection was possible. Data on up to 73,185 customers and employees may have leaked. –
Jul 2 Meitetsu Kyosho (Nagoya Railroad group, parking and car sharing) Servers stopped and some services were suspended. Customer data for its Kariteko car-sharing service may have leaked. –
Jun 30 Musashino University Restored from backups without disruption, but files containing names and addresses were later found to have leaked. Qilin
Jun 10 Kyushu University A research lab's computer was infected. Names of 43 patients and surgery video data may have leaked. –
May 14 Aoyama Zaisan Networks (wealth and real estate advisory) Files were encrypted at two group companies. SafePay
Apr 3 YCC Information System (IT vendor, Yamagata) A file server was encrypted and a ransom note left. Data it held for clients may have leaked, including about 500,000 records from the city of Yamagata, among them health data. –
Mar 30 Kota (hair care products) A system outage, later confirmed as ransomware, delayed its annual results. Data on employees, shareholders, customers and others may have been viewed. –
Mar 23 Omikenshi (textiles) Core systems stopped and files were encrypted, delaying its financial closing. The Gentlemen
Mar 17 Medica Publishing (medical and nursing publisher) Some data was confirmed leaked. About 772,000 personal records may have leaked, affecting universities and other organizations that used its services. The Gentlemen
Mar 17 Japan Telenet (call center subcontractor) Server files were likely encrypted. Clients' car-sharing customer data may have been viewed. A later investigation found no trace of data being transferred out. –
Mar 3 Shiraume Toyooka Hospital Electronic medical records and other hospital systems were infected. The health ministry sent its initial response team. Data on patients and their families was later published on a dark web site, according to ScanNetSecurity. Netrunner
Feb 19 Advantest (chip test equipment) Detected unusual activity on February 15. Its preliminary investigation suggests an attacker may have deployed ransomware. –
Feb 14 Washington Hotel (hotel chain) Attackers got in through an external connection device and encrypted some servers. Card terminals at some hotels stopped. The final report found no clear sign of data theft. –
Feb 13 Nippon Medical School Musashi Kosugi Hospital (Kawasaki) Nurse call system servers were hit, reportedly through a VPN device used for medical equipment maintenance. Data on about 130,000 patients leaked. Netrunner
Feb 12 Gala Yuzawa (JR East group ski resort) The lift ticket system failed. Encrypted servers held personal data. –
Feb 3 Anabuki Housing Service and Anabuki Kosan (condominium management and real estate) Attackers got in through a group company's network device and encrypted servers. Data on 207,773 people may have leaked, including tenants of Matsuyama city housing. Qilin

Attacks where ransomware is not confirmed#

These organizations confirmed a cyberattack with major disruption or data theft, but have not said it was ransomware. All of them have been listed on a ransomware group's leak site; we do not treat those claims as confirmation.

Disclosed Organization What happened Claimed by*
Oct 2 The Japan Times Servers managed by a group company were accessed without authorization, after a ransomware group listed it. Eclipse
Sep 29 Unirita (IT software) Data was stolen from an internal document management system. Everest
Jul 13 Nichirei (frozen food and cold storage) Cold storage operations and frozen food shipments were disrupted. 53,866 records on customers, business partners and employees leaked. RansomHouse
Jul 13 Nihon Kotsu (taxi and hire car operator) Unauthorized access and malware disrupted taxi dispatch and hire car bookings. Some files leaked. AiLock
Feb 3 Hosokawa Micron (powder processing equipment) Files believed to be from the company appeared online. Personal data, including My Number, leaked. Everest

How we compile this list#

  • What counts: the organization has said publicly that it was hit by ransomware, or that its files or servers were encrypted. Claims on ransomware groups' leak sites alone do not count.
  • Group names: we show which group claimed an attack only as recorded by ransomware.live, which monitors leak sites. We checked every organization on this page against its 2026 listings on October 10, 2026. Leak site claims can be exaggerated or false, and groups sometimes list victims they did not attack themselves.
  • Which cases: notable attacks disclosed in 2026 by organizations in Japan: major companies and groups, hospitals, universities, local governments, IT vendors whose attack reached their clients, and cases affecting 100,000 people or more. Many smaller cases, such as attacks on small manufacturers and local firms, are not listed.
  • Not included: attacks on overseas subsidiaries of Japanese companies, such as Sumitomo Metal Mining's nickel plant in the Philippines; and attacks first disclosed in 2025, such as those on Asahi Group and Askul, even if follow-up reports came out in 2026.
  • Sources: each organization's own notices where available, and Japanese security news sites ScanNetSecurity and INTERNET Watch, which report on those notices. All sources are listed at the end of this page.

For the national picture, see our ransomware statistics explainer, based on the National Police Agency's reports, and our weekly review.

Japanese terms at a glance#

Japanese Reading Meaning
ランサムウェア ransamuwea Ransomware
暗号化 angōka Encryption
脅迫文 kyōhakubun Ransom note
不正アクセス fusei akusesu Unauthorized access
委託先 itakusaki Contractor, vendor
漏えいのおそれ rōei no osore May have leaked
第三報 / 最終報 daisanpō / saishūhō Third report / final report