CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats Apr 09, 2026

Japanese Firms Suffer Long Tail of Ransomware Damage - Dark Reading

Dark Reading Archived Apr 09, 2026 ✓ Full text saved

Japanese Firms Suffer Long Tail of Ransomware Damage Dark Reading

Full text archived locally
✦ AI Summary · Claude Sonnet


    CYBERATTACKS & DATA BREACHES CYBERSECURITY OPERATIONS CYBER RISK THREAT INTELLIGENCE NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific Japanese Firms Suffer Long Tail of Ransomware Damage Ransomware actors have targeted manufacturers, retailers, and the Japanese government, with many organizations requiring months to recover. Robert Lemos,Contributing Writer December 9, 2025 4 Min Read SOURCE: TBBSTUDIO VIA SHUTTERSTOCK More than two months after ransomware shutdown its operations, Japanese food and beverage giant Asahi Holdings continues to suffer from back-office disruptions and was recently forced to acknowledge the possibility of a data breach affecting 1.9 million people. The company is not alone among Japanese firms. Japanese online retailer Askul announced this week that it would resume taking orders from its corporate clients more than six weeks after the firm acknowledged an attack, but still reportedly suffers from shipment delays and would not fulfill orders from individual customers. The online retailer's outage also affected other companies, such as the online store for Muji, a seller of minimalist household goods, which had to halt sales. Overall, the incidents underscore that Japanese companies are suffering the long tail of recovering from ransomware, especially if the victims refuse to pay the ransom, says Jon Clay, vice president of threat intelligence for cybersecurity firm Trend Micro. Related:Fraud Rockets Higher in Mobile-First Latin America "Rebuilding machines could take time depending on how effective IT can access these systems physically but more importantly remotely," he says. "All of these can cause significant delays in recovering, which is why, in some cases, an organization may pay the ransom in order to get the decryption keys and get access back to their systems and data." Japanese companies continue to struggle with cybersecurity. Threat actors targeted Japanese enterprises with exploits for critical vulnerabilities in Ivanti's Connect Secure virtual private network product, many of which remained unpatched this summer. Japanese companies and government agencies are seeing more attacks overall, despite recently passed legislation that allows more active measures in the name of network defense. As the world's fourth largest economy and the start of many supply chains, Japan is a major target for cybercriminals, says Shane Barney, chief information security officer at credential management firm Keeper Security. "Ransomware groups are focusing on Japan because its industries sit at the heart of global supply chains and run with very little room for disruption," he says. "From an attacker's perspective, that creates pressure to resolve incidents quickly, which increases their leverage." Japan Under Attack? Some companies have seen a general acceleration in cyberattacks against targets in Japan. Cybersecurity firm Sophos, for example, has seen more than 200 named Japanese ransomware victims in the past four years, with 72 victims in the past year alone, showing some acceleration in attacks. Related:Bank Trojan 'Casbaneiro' Worms Through Latin America Japan as a country, however, is not specifically being targeted, says Chris Yule, director of Sophos' threat research team. Instead, the country is facing the impact of an overall global increase in ransomware attacks. In the past 12 months, the number of Japanese victims of ransomware is a third higher (35%) than the previous 12 months. However, globally the same trend is apparent: The number of ransomware victims has grown by a third (33%), he says. "Ransomware groups are opportunistic, attacking any organizations that are vulnerable and likely to pay," Yule says. "We're not seeing any indications that they’re targeting specific geographies or market sectors, but sometimes a couple of big-name victims in the news can make it feel like a trend." Fortune Favors the Prepared The trend will likely to continue. While cyberattackers and ransomware groups are not done with North America and Europe, the Asia-Pacific region offers less mature security controls and processes, relatively untested incident response and recovery playbooks, and complex legacy environments, says Heath Renfrow, co-founder and chief information security officer at Fenix24, a breach-recovery services provider. Related:Chinese Police Use ChatGPT to Smear Japan PM Takaichi "Threat actors gravitate toward regions where recovery costs are high, the likelihood of disruption is significant, and resilience gaps are predictable," he says. Manufacturers, such as Asahi Holdings, tend to be more vulnerable to operational disruptions. In the end, as long as companies are vulnerable to attacks and are willing to pay a ransom to recover quickly, cybercriminals will target those companies, says Sophos' Yule. Companies that prepare by not only having backups, but also regularly holding recovery exercises and assessing the status of critical assets, will be able to recover the fastest and not need to pay ransoms. "Preparation is key, and when an organization puts the work in upfront, we see a world of difference when we're brought in to help victims respond to these attacks," he says. "You need to know what your plan is if your entire IT infrastructure is no longer available: who's in charge, how do you communicate, what decisions need to be made, and when." Read more about: DR Global Asia Pacific About the Author Robert Lemos Contributing Writer Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline Journalism (Online) in 2003 for coverage of the Blaster worm. Crunches numbers on various trends using Python and R. Recent reports include analyses of the shortage in cybersecurity workers and annual vulnerability trends. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports AI SOC for MDR: The Structural Evolution of Managed Detection and Response How Enterprises Are Developing Secure Applications Frost Radar™: Non-human Identity Solutions 2026 CISO AI Risk Report Gartner IGA Voice of the Customer 2026 Access More Research Webinars Security in the AI Age Identity Maturity Under Pressure: 2026 Findings and How to Catch Up Building a Robust SOC in a Post-AI World Retail Security: Protecting Customer Data and Payment Systems Rethinking SSE: When Unified SASE Delivers the Flexibility Enterprises Need More Webinars Editor's Choice CYBERSECURITY OPERATIONS RSAC 2026: AI Dominates, But Community Remains Key to Security byKristina Beek,Rob Wright APR 2, 2026 CYBERATTACKS & DATA BREACHES Not Toying Around: Hasbro Attack May Take 'Weeks' to Remediate byNate Nelson APR 2, 2026 3 MIN READ ENDPOINT SECURITY CrowdStrike Next-Gen SIEM Can Now Ingest Microsoft Defender Telemetry byJeffrey Schwartz APR 3, 2026 3 MIN READ Want more Dark Reading stories in your Google search results? 2026 Security Trends & Outlooks THREAT INTELLIGENCE Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats JAN 2, 2026 CYBER RISK Navigating Privacy and Cybersecurity Laws in 2026 Will Prove Difficult JAN 12, 2026 ENDPOINT SECURITY CISOs Face a Tighter Insurance Market in 2026 JAN 5, 2026 THREAT INTELLIGENCE 2026: The Year Agentic AI Becomes the Attack-Surface Poster Child JAN 30, 2026 Download the Collection Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Webinars Security in the AI Age TUES, APRIL 28, 2026 AT 1PM EST Identity Maturity Under Pressure: 2026 Findings and How to Catch Up WED, MAY 6,2026 AT 1PM EST Building a Robust SOC in a Post-AI World THURS, MARCH 19, 2026 AT 1PM EST Retail Security: Protecting Customer Data and Payment Systems THURS, APRIL 2, 2026 AT 1PM EST Rethinking SSE: When Unified SASE Delivers the Flexibility Enterprises Need WED, APRIL 1, 2026 AT 1PM EST More Webinars White Papers How Sunrun Transformed Security Operations with AiStrike Autonomous Pentesting at Machine Speed, Without False Positives Fixing Organizations' Identity Security Posture Best practices for incident response planning Industry Report: AI, SOC, and Modernizing Cybersecurity Explore More White Papers BLACK HAT ASIA | MARINA BAY SANDS, SINGAPORE Experience cutting-edge cybersecurity insights in this four-day event featuring expert Briefings on the latest research, Arsenal tool demos, a vibrant Business Hall, networking opportunities, and more. Use code DARKREADING for a Free Business Pass or $200 off a Briefings Pass. GET YOUR PASS HEALTHCARE SECURITY WEBINAR Protecting Patient Data and Clinical Operations SECURE YOUR SEAT GISEC GLOBAL 2026 GISEC GLOBAL is the most influential and the largest cybersecurity gathering in the Middle East & Africa, uniting global CISOs, government leaders, technology buyers, and ethical hackers for three power-packed days of innovation, strategy, and live cyber drills. 📌 BOOK YOUR SPACE
    💬 Team Notes
    Article Info
    Source
    Dark Reading
    Category
    🛡 Active Threats
    Published
    Apr 09, 2026
    Archived
    Apr 09, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗