IDC Frontier, a major Japanese cloud infrastructure provider and SoftBank Group subsidiary, has confirmed that its IDCF Cloud platform was hit by a ransomware attack that forced an outage at its East Japan Region 1 data center cluster. The company says the intrusion began on October 7 at 3:40 AM local time, triggering an emergency shutdown of affected network and systems.

According to IDC Frontier, the disruption affects 495 companies and local government bodies that rely on IDCF Cloud for virtual servers, storage, and networking to run websites, applications, and business systems. The company says it is still investigating the precise cause and full scope of the breach.

To contain the incident, IDC Frontier isolated and shut down systems in the affected region and proactively disabled customer access to management consoles across all regions while it verifies their security. Access will reportedly be restored only after the company confirms the rest of its infrastructure is clean.

Attacker claims deep access

Screenshots shared by affected customers before being locked out of the console show a message from the threat actor claiming it took only seven minutes to breach the East Japan Region 1 infrastructure. The attacker claims to have encrypted 225 databases totaling 3.6 PB of data, compromised 239 hypervisors, sealed 16,000 VM disks, and wiped more than 554,000 snapshots. These figures come from the attacker and have not been independently verified by IDC Frontier.

Possible wider pattern

Separately, Japanese seafood group Nissui Corporation disclosed that its logistics subsidiary, Nissui Logistics, suffered an outage due to suspected unauthorized access at a third-party data center, halting shipping and receiving operations while the company investigates potential data exposure. It remains unclear whether this incident is connected to the IDCF Cloud attack.

Security researcher Yutaka Sejiyama of Macnica notes a sharp rise in cyberattacks against Japanese organizations, with 83 incidents involving data theft or exposure recorded between July 1 and October 6 alone, compared to 84 for all of 2025 and 62 for all of 2024. Sejiyama attributes part of this surge to attackers using cheap, capable AI tools to automate the discovery of access-control, configuration, and authentication weaknesses that previously required significant manual effort to find.

Security teams managing cloud infrastructure in Japan and elsewhere should review incident response plans for provider-side ransomware scenarios, including console lockouts and regional isolation procedures, and monitor for signs of n-day exploitation against exposed web and API endpoints.