Key takeaways

  • Japan's National Police Agency (NPA) recorded 123 ransomware cases in the first half of 2026, the most for any six-month period since it started counting in the second half of 2020. There were 226 in all of 2025.
  • About six in ten victims are small and medium-sized businesses. Manufacturing is the most affected industry, by a wide margin.
  • Attackers mostly get in through internet-facing equipment: VPN devices account for about half of known entry points, and remote desktop for another quarter. Malicious email is now rare.
  • Almost every attack with a known method is double extortion: data is stolen as well as encrypted.
  • Recovery is slow and expensive. Only just under half of victims recovered within a month, and six in ten spent ¥10 million (roughly US$65,000) or more.
  • Backups mostly did not save victims. Of those who tried, nearly three in four could not restore, most often because the attackers had encrypted or deleted the backups too.

Where these numbers come from#

Twice a year, the NPA publishes a report on threats in cyberspace, known in Japanese as サイバー空間をめぐる脅威の情勢等について. It covers the full year each spring and the first half each September. The ransomware figures are cases reported to the police by companies and organizations. The details on entry points, recovery and backups come from a survey of those victims, so they are based on a smaller number of responses.

The NPA publishes an English edition of the annual report. The half-year figures below are from the Japanese edition published in September 2026.

How many attacks#

Reported ransomware cases, by half-year

Period Ransomware No-ware ransom*
H2 2020 21 –
H1 2021 61 –
H2 2021 85 –
H1 2022 114 –
H2 2022 116 –
H1 2023 103 9
H2 2023 94 21
H1 2024 114 14
H2 2024 108 8
H1 2025 116 8
H2 2025 110 9
H1 2026 123 9

* "No-ware ransom" (ノーウェアランサム) is the NPA's term for extortion where attackers steal data and demand payment without encrypting anything. The NPA started counting it in 2023.

After a jump in 2021 and 2022, reported cases have stayed at roughly 100 to 120 every six months. The first half of 2026 is the highest yet. Annual totals were 146 in 2021, 230 in 2022, 197 in 2023, 222 in 2024 and 226 in 2025.

Who gets hit#

By organization size

Period Small & medium businesses Large companies Other organizations Total
2021 79 49 18 146
2022 119 65 46 230
2023 102 71 24 197
2024 140 61 21 222
2025 143 64 19 226
H1 2026 79 31 13 123

Small and medium-sized businesses have made up around 60% of victims for the past two and a half years. The attacks that make headlines, such as those on large manufacturers, railways and retailers, are the minority.

By industry, first half of 2026

Industry Cases
Manufacturing 37
Wholesale and retail 15
Information and communications 9
Real estate and leasing 9
Medical care and welfare 9
Construction 8
Other 36

Manufacturing accounted for about 30% of cases, down from about 40% in 2025 (91 of 226), but still far ahead of any other industry.

How attackers get in#

Entry point H1 2026 Past five years
VPN devices 18 293
Remote desktop 9 105
Malicious email or attachments – 24
Other 9 63
Valid responses 36 485

Over five years, VPN devices were the entry point in about 60% of cases where the victim could say, and remote desktop in about 22%. Phishing email accounted for only 5%. The NPA describes the typical attack as a remote intrusion through exposed equipment, using unpatched vulnerabilities or leaked credentials. The attackers then take administrator rights, disable security tools, hunt for important data and backups, steal data, and only then encrypt.

How they extort#

Among cases where the method was known, double extortion, where data is stolen before encryption and the victim is threatened with its publication, accounted for:

  • 61 of 66 cases in the first half of 2026 (92%)
  • 136 of 153 in 2025 (89%)
  • 578 of 741 over five years (78%)

Traditional encryption-only ransomware is now the exception.

Recovery time and cost#

How long recovery took, first half of 2026

Time to recover Organizations
Less than one week 17
One week to one month 6
One to two months 4
Two months or more 8
Still recovering 13
Valid responses 48

Only 23 of 48 (48%) recovered within a month. More than a quarter were still recovering when surveyed.

Total investigation and recovery costs, first half of 2026

Cost Organizations
¥100 million or more 4
¥50 million to ¥100 million 6
¥10 million to ¥50 million 11
¥5 million to ¥10 million 3
¥1 million to ¥5 million 5
Less than ¥1 million 6
Valid responses 35

21 of 35 (60%) spent ¥10 million or more.

Why backups did not help#

In the first half of 2026:

  • 44 of 50 responding victims had backups.
  • But of 40 that answered, only 11 could restore from them. 29 could not.
  • The most common reason (14 of 29) was that the backups themselves had been encrypted or deleted by the attackers. Another 8 cited problems in how backups were run or managed.

Having backups is not the same as being able to recover from them. Attackers now look for backups first, precisely because victims who can restore do not pay.

What the numbers say#

Three patterns stand out in Japan's data, and they match the incidents we cover:

  1. The edge is the entry point. VPN and remote access equipment, often with known but unpatched vulnerabilities, is how most attackers get in. The Digital Agency breach through a VPN flaw was not ransomware, but it followed the same path.
  2. Group companies and business systems take the hit. Attacks such as the one on Keio disrupt payments, reservations, ordering and logistics, often at subsidiaries, while core operations may keep running.
  3. Recovery depends on backups the attacker cannot reach. Most Japanese victims had backups, and most could not use them.

We will update this page when the NPA publishes its full-year 2026 figures, expected in spring 2027.

Japanese terms at a glance#

Japanese Reading Meaning
サイバー空間をめぐる脅威の情勢等について saibā kūkan o meguru kyōi no jōsei-tō ni tsuite The NPA's semi-annual report on threats in cyberspace
被害報告件数 higai hōkoku kensū Number of reported cases
ノーウェアランサム nōwea ransamu "No-ware ransom": data theft and extortion without encryption
二重恐喝 nijū kyōkatsu Double extortion
中小企業 chūshō kigyō Small and medium-sized businesses
復元不可 fukugen fuka Could not restore