Ransomware attack on SoftBank's IDCF Cloud disrupts 495 Japanese organisations

· CyberSecurity

TLDR

  • IDC Frontier, a SoftBank Group cloud subsidiary, says a ransomware attack on 7 October knocked out its IDCF Cloud service in East Japan Region 1, affecting 495 corporate and local-government customers.1
  • Virtual servers in four availability zones stopped and could not restart; IDC Frontier warns some customer data in the region may be impossible to retrieve, and told affected customers to prepare to rebuild systems and restore from their own backups.12
  • An unattributed attacker left a message on the platform console claiming the breach took seven minutes, encrypted 225 data stores holding 3.6 petabytes, reached roughly 239 to 240 hypervisors, sealed over 16,000 VM disks, and deleted more than 554,000 backup snapshots; no ransomware group has claimed responsibility.123
  • Affected customers span railways, police services, food logistics, ISPs and enterprise telephony providers; JR East and View Card say up to 6.09 million records may have been accessed through email-delivery services run on the affected cloud.23

IDC Frontier said the attack began on 7 October at 3:40am local time, forcing a shutdown of the network and systems in East Japan Region 1 "caused by a ransomware attack by a third party."1 The company isolated affected systems to stop the compromise spreading, disabled customer access to management consoles across all regions while it verified their security, and said it is still investigating the precise cause and scope.1 In an update, IDC Frontier said four cloud zones were damaged badly enough that customers would need to rebuild their systems elsewhere: "At this time, our view is that data restoration will only be possible from backup data held by the customer themselves."2

Screenshots circulating on social media and seen by BleepingComputer and Cybernews show an English-language message left on the console by the attacker, who claims the breach took exactly seven minutes.123 Figures given in the message vary slightly between outlets: BleepingComputer reports the attacker's claim of 225 encrypted databases covering 3.6 petabytes, 239 hypervisors reached, 16,000 sealed VM disks and 554,153 wiped snapshots, while SDxCentral's version of the same message cites almost 240 hypervisors, more than 554,150 snapshots destroyed, and 41.5 petabytes of backup capacity removed.13 The message reads in part: "October 7, 2026. Seven minutes. Exactly seven minutes is what it took to turn your entire East Japan Region one into ciphertext (and) take a national cloud apart."3 Cybernews says the ransom note carries no self-attribution to any known ransomware group, and that IDC Frontier has not disclosed how the attackers got in, whether a ransom was demanded, or how much data was stolen rather than just encrypted.2

IDCF Cloud is one of Japan's main domestic alternatives to AWS, Azure and Google Cloud, marketed at companies and public bodies wanting systems run on sovereign infrastructure, and the disruption to a single region has cascaded across sectors.2 Affected customers include Wi-Fi provider Fibergate, whose authentication services were hit, and enterprise communications firm Medialink, whose cloud-based IP-PBX telephony went offline; public-sector bodies and firms in logistics, education and financial services were also affected.3 Japan's largest railway operator, JR East, and its credit-card arm View Card said up to 6.09 million records may have been accessed through email-delivery services that ran on IDCF Cloud, though both say credit card numbers, home addresses and phone numbers were not exposed; JR Kyushu separately reported 1.3 million emails affected.2 Frozen-food logistics firm Nissui Logistics also reported a systems outage tied to suspected unauthorised access to a third-party data centre, though it remains unclear if that incident is connected.1

The attack lands amid a broader surge in Japanese breach disclosures: Macnica researcher Yutaka Sejiyama told BleepingComputer the firm logged 119 cybersecurity incidents involving data theft or exposure so far in 2026, 83 of them between July and early October, against 84 for all of 2025 and 62 in 2024, and suggested cheap, capable AI tools may be making broad vulnerability scanning easier for attackers.1

Why it matters: a single ransomware attack on one cloud region knocking railways, police systems, food logistics and millions of rail-customer records offline in one blow shows how concentrated the blast radius becomes once critical services consolidate onto a shared sovereign-cloud provider, and IDC Frontier's own admission that some data may be unrecoverable without customers' own backups is a stark reminder that cloud redundancy is not automatic.

Sources

  1. Ransomware attack disrupts Japan's IDCF Cloud used by govt clients (BleepingComputer)
  2. Cyberattack on Japanese cloud firm hits railways, police and food suppliers, 495 organizations exposed (Cybernews)
  3. SoftBank national cloud arm attacked in 'seven minutes,' taking Japan infrastructure offline (SDxCentral)