IDC Frontier Inc., a cloud services subsidiary of SoftBank Corp., was hit by a ransomware attack in the early hours of October 7, 2026, and the damage quickly spread far beyond its own data centres. The company said 495 companies and local government services had been affected after part of its IDCF Cloud platform went offline, turning an outage at a single provider into a sprawling cloud supply-chain crisis for Japan. Ransomware had become an infrastructure problem rather than an application problem.
IDCF Cloud is one of the main domestic alternatives to AWS, Microsoft Azure and Google Cloud for Japanese companies and public bodies. That position, built on local support and data residency, meant failures at IDC Frontier were never going to stay local. Within 48 hours, railway operators, a second-hand retail chain, a karaoke group, a travel booking site and a frozen food logistics company were all disclosing that customer data held in IDCF Cloud email and application systems may have been exposed.
By October 9, East Japan Railway Co. (JR East) disclosed that about 6.09 million customer accounts may have been compromised, spread across its Viewcard credit card unit, its Ekinet Shinkansen reservation service and its Otona no kyujitsu kurabu membership programme. Bookoff Group Holdings said the same day that up to 6.43 million accounts may have been exposed after unauthorized access to a member data management system run by one of its subsidiaries.
Japan Cyber Watch reported on October 10 that disclosures in the week of October 4 to 10 covered more than 50 million records in total, with the IDCF Cloud ransomware attack the biggest single incident of that period. Eight government agencies issued warnings or requests, most of them between October 7 and 9, and Japan's National Cybersecurity Office sent a letter to ministries warning that this was no longer just a problem for the IT department.
Key Facts
IDC Frontier said in a statement issued on Wednesday, October 7, that 495 companies and local government services had been affected by the attack, which began in the early hours of that day and knocked some servers offline. In an update published on Thursday, October 8, the provider confirmed that four cloud zones had been so badly damaged that customers would need to rebuild systems elsewhere and restore data from their own backups, saying: "it is expected that it will be difficult to retrieve or restore customer data stored in a part of East Japan Region 1."
Screenshots attributed to the attackers claimed they accessed 239 systems running virtual machines, locked 225 large storage systems holding 3.6 petabytes of data, sealed more than 16,600 virtual machine hard drives and deleted 554,153 backup snapshots, all in about 7 minutes. Japan Cyber Watch reported on October 10 that the attack on IDCF Cloud, a public cloud run by SoftBank's IDC Frontier, began at about 03:40 on October 7 and hit the websites of Ibaraki Prefecture and its police, business phone services and Nissui's cold-chain logistics subsidiary.
JR East and View Card said up to 6.09 million records may have been accessed through email delivery services that used IDCF Cloud, while JR Kyushu reported about 1.3 million emails. Both operators said credit card numbers, home addresses and telephone numbers were not exposed. Mainichi reported on October 9 that roughly 4.03 million of the JR East accounts sat with Viewcard, that about 1.67 million involved Ekinet email logs and that some 390,000 involved the Otona no kyujitsu kurabu programme.
Bookoff said the stolen data included members' names, birthdays, addresses, email addresses, membership numbers and reward programme identification numbers, and that payment details such as credit card numbers were not stored in the affected system. The retailer confirmed the unauthorized access on Tuesday, October 6, and said it had not confirmed any fraudulent use of the data.
The Japan Times reported on October 10 that Daiichikosho, the operator of the Big Echo karaoke chain, said personal information on about 8.72 million customers may have been compromised through unauthorized access to a system managed by an external contractor, and that Adventure Inc., which runs the Skyticket travel booking site, reported a potential breach involving about 14.64 million sets of personal information. Adventure said credit card and passport numbers had not leaked.
Analysis
The bigger picture here is that Japan's push toward domestic cloud providers has created concentrated points of failure that no individual customer can manage or insure against. IDC Frontier is not a minor hosting shop: it is the local answer to the hyperscale clouds, and 495 organisations, from prefectural police websites to cold-chain logistics operators, depended on the same handful of damaged zones inside East Japan Region 1.
The attackers' claimed timeline makes the recovery problem worse than the outage itself. Locking 225 large storage systems holding 3.6 petabytes of data and deleting 554,153 backup snapshots in about 7 minutes is an attack on the ability to restore as much as on the ability to run. IDC Frontier's guidance, that customers rebuild elsewhere and restore from their own backups, effectively returns the burden of resilience to tenants that had already outsourced it.
India Today reported on October 11 that Japan issued a nationwide cybersecurity warning as a growing wave of attacks targets businesses and exposes millions of customers' personal data. Toshihiro Furukawa, the country's Digital Transformation Minister, said attacks are increasing in both quality and quantity, that methods are becoming more sophisticated, and that they are having a tremendous impact on people's lives and causing significant disruption to business activities.
What this really means is that the economics of Japanese cloud consolidation and the economics of ransomware now point in the same direction: fewer, larger targets, each with a bigger blast radius. A study by the newspaper Yomiuri and the cybersecurity firm Trend Micro found Japan has already recorded more than 500 cyberattacks this year, against 473 last year and 503 in 2024, putting the country on course for a record. India Today reported on October 11 that Reuters data showed incidents reached 86 in September, up about 18 percent from August and 37 percent from July.
Why It Matters
The exposed data is mostly email addresses at JR East, plus names, dates of birth and telephone numbers at several other companies. On its own that is less severe than card numbers or passport data, and Adventure said credit card and passport numbers had not leaked. But email addresses combined with names and dates of birth are exactly the raw material that phishing campaigns need, and the government warned that leaks can lead to identity theft and fraudulent money transfers.
Companies said they had found no evidence of unauthorized use of the affected information and urged customers to watch out for suspicious emails and phone calls. India Today reported on October 11 that Japan's National Cybersecurity Office issued instructions to government ministries for distribution to local authorities and private companies, according to Reuters, and that the government urged people to stop reusing passwords and to enable multi-factor authentication. The office also noted that AI is making vulnerabilities increasingly complex.
Japan is not alone in this trend. India Today reported on October 11 that South Korea is facing similar threats, with nine banks and two mega-churches investigating AI-assisted attacks and 1,236 cyber incidents recorded in the first half of 2026, up 20 percent year on year. Inside Japan, the same week brought disclosures from Times Car, where information linked to around 6.6 million customer accounts, including 1.6 million driver's licence images, was exposed, along with Lawson, Seicomart and Daiwa Securities.
Next Up
IDC Frontier customers in the four damaged zones of East Japan Region 1 now face a rebuild and restore cycle with limited help from the provider, and IDC Frontier itself has not said whether any data was actually taken. Japan Cyber Watch reported on October 10 that e-commerce platform FutureShop, whose email servers on IDCF Cloud held recipient addresses and parts of email bodies, is among the tenants still waiting for clarity.
Government pressure is likely to follow the National Cybersecurity Office letter. India Today reported on October 11 that the office issued instructions for distribution to local authorities and private companies, and Cybernews reported on October 9 that the office warned that this is no longer just a problem for the IT department. Whether Tokyo moves from warnings to binding resilience and backup requirements for cloud providers is now the open question for every Japanese organisation that moved its systems to a domestic provider.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.