Key takeaways
- On September 23, 2026, J:COM, Japan's largest cable operator, lost internet service across most of its footprint for about nine hours. Up to 4.08 million subscriber households were affected.
- J:COM says "a large volume of access from outside" overloaded its DNS servers. It has not said whether this was an attack. A DDoS is a possibility, but it is not confirmed.
- J:COM's first notice came about 90 minutes after the outage began, on a support account on X, with no cause or recovery estimate. Its website notice appeared only after service was restored, and support lines were hard to reach all day. Customers have complained loudly.
What happened#
J:COM (JCOM Co., Ltd.) is Japan's largest cable TV and broadband operator, jointly owned by KDDI and Sumitomo Corporation. It also provides internet service wholesale to smaller regional cable companies.
On the morning of September 23, a national holiday and the last day of a five-day weekend, customers across Japan found they could not get online. According to J:COM's official release:
| Item | J:COM's statement |
|---|---|
| Duration | About 8:55 to 18:00 JST, September 23. All services confirmed normal at 20:00 |
| Area | All J:COM NET areas except Hokkaido and Kyushu, plus some partner cable operators' areas. Kansai TV reported 29 prefectures affected |
| Maximum affected | About 4.08 million subscriber households |
| Services | J:COM NET internet access, interactive TV and streaming on J:COM TV, J:COM MOBILE data, the My Page portal and app, and other services that need a J:COM login |
| Cause | "A large volume of access from outside" caused high load on DNS servers, so the processing needed to connect to the internet could not be performed normally |
Broadcast TV viewing was not affected. During the outage, users reported on social media that switching their devices to a public DNS resolver restored access.
Timeline#
| Time (JST) | Event | Source |
|---|---|---|
| Sep 23, ~8:55 | Outage begins | J:COM |
| Sep 23, 10:24 | First notice, on J:COM's support account on X: work toward recovery is under way. No cause or recovery estimate | J-CAST News, ITmedia |
| Sep 23 (daytime) | A regional cable operator in the Kinki area posts that the outage is "due to an external attack" (外部からの攻撃のため), then removes the wording | Kansai TV |
| Sep 23, ~18:00 | Restoration work complete | J:COM |
| Sep 23, 20:00 | J:COM confirms all services normal | J:COM |
| Sep 23, 20:30 | Notice posted on J:COM's website | J-CAST News |
| Sep 24, 16:00 | J:COM publishes the cause: external mass access overloading DNS servers | J:COM |
Was it a DDoS?#
J:COM has not said so, and we cannot confirm it. J:COM attributes the outage to external traffic overloading its DNS servers, not to an equipment failure or a configuration change. That is the kind of impact a DDoS attack can cause. A partner operator's first explanation also used the word "attack" before it was withdrawn.
But a traffic surge can have other causes, and J:COM says its investigation is based on what it has confirmed "at this point". We will update this article if J:COM or the authorities say more.
Our analysis#
Nine hours, and 90 minutes of silence#
For customers, the most frustrating part of the day was not knowing what was going on.
- The first word came late. J:COM's first notice was posted at 10:24, about an hour and a half after the outage began. It appeared on a support account on X, said only that recovery work was under way, and gave no cause or recovery estimate.
- The website notice came after the fix. According to J-CAST News, J:COM's own website carried a notice only at 20:30, after service had been restored.
- Support was unreachable. J:COM acknowledged that its customer center and support channels were hard to reach because of the outage.
- The notices were online, and the customers were not. J:COM MOBILE data was also affected, so some customers had no easy way to see a notice posted on X or the web.
Reaction was blunt. J-CAST News reported a stream of complaints, including customers demanding J:COM "give us back our time" (時間を返して). J:COM has since apologized for the disruption and promised to improve how it provides information during outages. That promise is the right one. A nine-hour outage on a holiday, with 90 minutes of silence at the start, is exactly when customers need early, repeated and plain updates, even if the only honest message is "we don't know yet".
"Large volume of access" is a very Japanese sentence#
J:COM's wording, 外部から大量のアクセス ("a large volume of access from outside"), is the standard phrase in Japanese outage notices. It describes the symptom and avoids the word "attack". Last month, Yamanashi and Gifu prefectures used almost the same wording ("a surge in access from overseas") when their websites went down. A pro-Russian hacktivist group claimed that activity, but no Japanese authority has confirmed the claim.
There can be good reasons for caution. An investigation may be under way, attribution takes time, and the traffic might not have been malicious. But the result is that customers, partner operators and other ISPs are left to guess. A partner writes "attack", then deletes it. Other operators cannot tell whether they should be preparing for the same thing tomorrow.
It is the same disclosure stance we saw in the Digital Agency breach. Organizations confirm the impact carefully, and say little that would help anyone else understand or defend against what happened.
DDoS has been a recurring problem for Japan#
If this does turn out to be a DDoS, it fits a pattern of attacks on Japanese targets:
- Year-end 2024 to early 2025. Japan Airlines, major banks and NTT Docomo were hit by DDoS attacks that disrupted services.
- August 2026. Two prefectural governments had their websites taken down by traffic surges, which a hacktivist group claimed.
DDoS botnets are largely built from compromised routers, cameras and other devices, many of them in Japan. As we argued in our Active Cyber Defense explainer, Japan's new police power to remove malicious code from such devices, which takes effect on October 1, will prove its value only if it is used against this kind of infrastructure.
What this means for readers outside Japan#
- If your operations in Japan run over consumer or small-business broadband, have a backup connection from a different provider, such as mobile tethering on another carrier. Whichever DNS resolvers your organization uses, decide in advance what staff should do if they stop responding, rather than leaving people to improvise during an outage.
- If you track threats to Japan, read J:COM's wording carefully. "External access" in a Japanese notice may or may not mean an attack. Look for follow-up from J:COM or the authorities before drawing conclusions.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| 外部から大量のアクセス | gaibu kara tairyō no akusesu | "A large volume of access from outside". Standard outage wording that avoids saying "attack" |
| 外部からの攻撃 | gaibu kara no kōgeki | "An attack from outside" |
| DNSサーバに高負荷 | DNS sāba ni kōfuka | High load on DNS servers |
| 時間を返して | jikan o kaeshite | "Give us back our time". A common customer complaint after long outages |
We will update this article if J:COM or the authorities publish more on the cause.