Key takeaways
- Japan's National Police Agency (NPA) recorded 123 ransomware cases in the first half of 2026, the most for any six-month period since it started counting in the second half of 2020. There were 226 in all of 2025.
- About six in ten victims are small and medium-sized businesses. Manufacturing is the most affected industry, by a wide margin.
- Attackers mostly get in through internet-facing equipment: VPN devices account for about half of known entry points, and remote desktop for another quarter. Malicious email is now rare.
- Almost every attack with a known method is double extortion: data is stolen as well as encrypted.
- Recovery is slow and expensive. Only just under half of victims recovered within a month, and six in ten spent ¥10 million (roughly US$65,000) or more.
- Backups mostly did not save victims. Of those who tried, nearly three in four could not restore, most often because the attackers had encrypted or deleted the backups too.
Where these numbers come from#
Twice a year, the NPA publishes a report on threats in cyberspace, known in Japanese as サイバー空間をめぐる脅威の情勢等について. It covers the full year each spring and the first half each September. The ransomware figures are cases reported to the police by companies and organizations. The details on entry points, recovery and backups come from a survey of those victims, so they are based on a smaller number of responses.
The NPA publishes an English edition of the annual report. The half-year figures below are from the Japanese edition published in September 2026.
How many attacks#
Reported ransomware cases, by half-year
| Period | Ransomware | No-ware ransom* |
|---|---|---|
| H2 2020 | 21 | – |
| H1 2021 | 61 | – |
| H2 2021 | 85 | – |
| H1 2022 | 114 | – |
| H2 2022 | 116 | – |
| H1 2023 | 103 | 9 |
| H2 2023 | 94 | 21 |
| H1 2024 | 114 | 14 |
| H2 2024 | 108 | 8 |
| H1 2025 | 116 | 8 |
| H2 2025 | 110 | 9 |
| H1 2026 | 123 | 9 |
* "No-ware ransom" (ノーウェアランサム) is the NPA's term for extortion where attackers steal data and demand payment without encrypting anything. The NPA started counting it in 2023.
After a jump in 2021 and 2022, reported cases have stayed at roughly 100 to 120 every six months. The first half of 2026 is the highest yet. Annual totals were 146 in 2021, 230 in 2022, 197 in 2023, 222 in 2024 and 226 in 2025.
Who gets hit#
By organization size
| Period | Small & medium businesses | Large companies | Other organizations | Total |
|---|---|---|---|---|
| 2021 | 79 | 49 | 18 | 146 |
| 2022 | 119 | 65 | 46 | 230 |
| 2023 | 102 | 71 | 24 | 197 |
| 2024 | 140 | 61 | 21 | 222 |
| 2025 | 143 | 64 | 19 | 226 |
| H1 2026 | 79 | 31 | 13 | 123 |
Small and medium-sized businesses have made up around 60% of victims for the past two and a half years. The attacks that make headlines, such as those on large manufacturers, railways and retailers, are the minority.
By industry, first half of 2026
| Industry | Cases |
|---|---|
| Manufacturing | 37 |
| Wholesale and retail | 15 |
| Information and communications | 9 |
| Real estate and leasing | 9 |
| Medical care and welfare | 9 |
| Construction | 8 |
| Other | 36 |
Manufacturing accounted for about 30% of cases, down from about 40% in 2025 (91 of 226), but still far ahead of any other industry.
How attackers get in#
| Entry point | H1 2026 | Past five years |
|---|---|---|
| VPN devices | 18 | 293 |
| Remote desktop | 9 | 105 |
| Malicious email or attachments | – | 24 |
| Other | 9 | 63 |
| Valid responses | 36 | 485 |
Over five years, VPN devices were the entry point in about 60% of cases where the victim could say, and remote desktop in about 22%. Phishing email accounted for only 5%. The NPA describes the typical attack as a remote intrusion through exposed equipment, using unpatched vulnerabilities or leaked credentials. The attackers then take administrator rights, disable security tools, hunt for important data and backups, steal data, and only then encrypt.
How they extort#
Among cases where the method was known, double extortion, where data is stolen before encryption and the victim is threatened with its publication, accounted for:
- 61 of 66 cases in the first half of 2026 (92%)
- 136 of 153 in 2025 (89%)
- 578 of 741 over five years (78%)
Traditional encryption-only ransomware is now the exception.
Recovery time and cost#
How long recovery took, first half of 2026
| Time to recover | Organizations |
|---|---|
| Less than one week | 17 |
| One week to one month | 6 |
| One to two months | 4 |
| Two months or more | 8 |
| Still recovering | 13 |
| Valid responses | 48 |
Only 23 of 48 (48%) recovered within a month. More than a quarter were still recovering when surveyed.
Total investigation and recovery costs, first half of 2026
| Cost | Organizations |
|---|---|
| ¥100 million or more | 4 |
| ¥50 million to ¥100 million | 6 |
| ¥10 million to ¥50 million | 11 |
| ¥5 million to ¥10 million | 3 |
| ¥1 million to ¥5 million | 5 |
| Less than ¥1 million | 6 |
| Valid responses | 35 |
21 of 35 (60%) spent ¥10 million or more.
Why backups did not help#
In the first half of 2026:
- 44 of 50 responding victims had backups.
- But of 40 that answered, only 11 could restore from them. 29 could not.
- The most common reason (14 of 29) was that the backups themselves had been encrypted or deleted by the attackers. Another 8 cited problems in how backups were run or managed.
Having backups is not the same as being able to recover from them. Attackers now look for backups first, precisely because victims who can restore do not pay.
What the numbers say#
Three patterns stand out in Japan's data, and they match the incidents we cover:
- The edge is the entry point. VPN and remote access equipment, often with known but unpatched vulnerabilities, is how most attackers get in. The Digital Agency breach through a VPN flaw was not ransomware, but it followed the same path.
- Group companies and business systems take the hit. Attacks such as the one on Keio disrupt payments, reservations, ordering and logistics, often at subsidiaries, while core operations may keep running.
- Recovery depends on backups the attacker cannot reach. Most Japanese victims had backups, and most could not use them.
We will update this page when the NPA publishes its full-year 2026 figures, expected in spring 2027.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| サイバー空間をめぐる脅威の情勢等について | saibā kūkan o meguru kyōi no jōsei-tō ni tsuite | The NPA's semi-annual report on threats in cyberspace |
| 被害報告件数 | higai hōkoku kensū | Number of reported cases |
| ノーウェアランサム | nōwea ransamu | "No-ware ransom": data theft and extortion without encryption |
| 二重恐喝 | nijū kyōkatsu | Double extortion |
| 中小企業 | chūshō kigyō | Small and medium-sized businesses |
| 復元不可 | fukugen fuka | Could not restore |