Key takeaways

  • The Japan Times, Japan's oldest English-language daily, said on October 2, 2026 that servers managed by a group company had been accessed without authorization. Whether data leaked is still under investigation.
  • Two days earlier, a ransomware group called Eclipse listed The Japan Times on its leak site, threatening to publish data unless the company makes contact.
  • The company says The Japan Times Online, its subscriber databases and payment systems run on separate infrastructure and are not affected. The paper and website are operating normally.
  • This is not related to Times Car, the car-sharing service whose breach was disclosed the week before. The two companies only share a word in their names.

What happened#

According to The Japan Times' notice, published in English and Japanese:

  • Some servers managed by a group company were accessed without authorization.
  • The company is investigating, with an outside cybersecurity specialist, whether information was leaked, the scope of the impact and the cause. It expects the investigation to take some time.
  • The Japan Times Online, subscriber databases and payment systems run on separate and independent infrastructure, and no impact has been found on them.
  • Newspaper publication and websites continue as usual.
  • The company is working with relevant authorities, and warns of emails and phone calls impersonating the company or its group.

The notice does not name the group company, the servers or the kind of data on them. Its text does not use the word "ransomware", although the web addresses of both the English and Japanese versions contain "ransomware-incident".

The leak site listing#

Date and time Event
Sep 30, 2026 Date of the attack, according to Eclipse's post
Oct 1, 06:53 JST ransomware.live records The Japan Times on Eclipse's leak site
Oct 2 The Japan Times publishes its notice

According to DeXpose, which monitors leak sites, Eclipse's post says the "full leak will be published soon" unless a company representative gets in touch.

A leak site listing is a claim by criminals, not a confirmed fact. Groups list victims to pressure them into paying, and sometimes exaggerate what they hold. The Japan Times has not commented on the claim or confirmed that Eclipse is responsible.

Who is Eclipse?#

Eclipse is a new ransomware and extortion group. Little has been published about how it operates.

First seen August 2026. ransomware.live began tracking its leak site on August 11, and its first victim was posted on August 16–17
Victims listed 11 on ransomware.live as of October 3
Countries United States 3, Singapore 3, India 2, France 1, Italy 1, Japan 1
Sectors Mixed, including hospitality, logistics, manufacturing, financial services, legal, education and media
Japanese victims The Japan Times is the first

Another media company is already on its list: TTG Asia Media, a Singapore-based travel trade publisher, was posted in September. No security firm has yet published a detailed analysis of Eclipse's tools or methods, so it is not known how it gets into its victims' networks.

Not Times Car#

Some people on social media have connected this incident to Times Car, the car-sharing service whose breach of 6.6 million accounts was disclosed in late September. Even an AI-generated search summary we saw while researching this article mixed the two up.

They are unrelated:

The Japan Times Times Car
Company The Japan Times, Ltd. Times Mobility, part of the Park24 group
Business English-language newspaper Car-sharing
What happened Unauthorized access to group company servers. Leak under investigation Attackers took data on about 6.6 million accounts, including 1.6 million ID document images
Ransomware claim Listed by Eclipse No leak site listing found

The only link is the word "Times". Neither company has suggested any connection.

What we don't know yet#

The Japan Times has not said:

  • Which group company and which servers were affected, or what data they held
  • When the access began and when it was detected
  • Whether data was encrypted or taken, and whether a ransom has been demanded
  • Whether Eclipse's claim is accurate

Our analysis#

Listed before it was disclosed#

Here, the first public sign came from the attackers, not the company. Eclipse posted The Japan Times on its leak site about a day before the company's notice. The notice itself is careful: it confirms unauthorized access, says data leakage is still being investigated, and does not mention ransomware or the claim. That is common in Japanese disclosures, but it leaves readers to piece the story together from leak site trackers.

Separation that held, if the company is right#

The notice says the digital edition, subscriber databases and payment systems run on separate infrastructure from the affected servers. If that holds, readers' and subscribers' data is outside the incident. That is the kind of separation that limited the damage in the Keio ransomware attack, where the railway kept running. The question is what the group company's servers held instead: business records, partner contacts or employee data would all be useful to extortionists.

A new group, a known playbook#

Eclipse is new, but the pattern is familiar: steal data, list the victim, threaten to publish. Ransomware cases in Japan are at a record high, and new groups appear regularly. For organizations, the practical lesson does not depend on the group's name: most attackers get in through internet-facing equipment and stolen credentials.

What this means for readers#

  • If you subscribe to The Japan Times, the company says subscriber and payment systems are not affected. Be wary of emails or calls about this incident that ask for personal or payment details.
  • If your organization works with The Japan Times or its group companies, watch for impersonation, especially requests to change payment details.
  • If you were affected by the Times Car breach, this incident does not change anything for you. It is a different company.

Japanese terms at a glance#

Japanese Reading Meaning
ジャパンタイムズ Japan Taimuzu The Japan Times, Ltd.
グループ会社が管理するサーバー gurūpu gaisha ga kanri suru sābā Servers managed by a group company
リークサイト rīku saito Leak site run by a ransomware group
情報漏えいの有無 jōhō rōei no umu Whether information has leaked
外部専門業者 gaibu senmon gyōsha Outside specialist firm

We will update this article when The Japan Times publishes the results of its investigation, or if Eclipse publishes data.