Japanese Firms Suffer Long Tail of Ransomware Damage - Dark Reading
Dark ReadingArchived Apr 09, 2026✓ Full text saved
Japanese Firms Suffer Long Tail of Ransomware Damage Dark Reading
Full text archived locally
✦ AI Summary· Claude Sonnet
CYBERATTACKS & DATA BREACHES
CYBERSECURITY OPERATIONS
CYBER RISK
THREAT INTELLIGENCE
NEWS
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific
Japanese Firms Suffer Long Tail of Ransomware Damage
Ransomware actors have targeted manufacturers, retailers, and the Japanese government, with many organizations requiring months to recover.
Robert Lemos,Contributing Writer
December 9, 2025
4 Min Read
SOURCE: TBBSTUDIO VIA SHUTTERSTOCK
More than two months after ransomware shutdown its operations, Japanese food and beverage giant Asahi Holdings continues to suffer from back-office disruptions and was recently forced to acknowledge the possibility of a data breach affecting 1.9 million people.
The company is not alone among Japanese firms.
Japanese online retailer Askul announced this week that it would resume taking orders from its corporate clients more than six weeks after the firm acknowledged an attack, but still reportedly suffers from shipment delays and would not fulfill orders from individual customers. The online retailer's outage also affected other companies, such as the online store for Muji, a seller of minimalist household goods, which had to halt sales.
Overall, the incidents underscore that Japanese companies are suffering the long tail of recovering from ransomware, especially if the victims refuse to pay the ransom, says Jon Clay, vice president of threat intelligence for cybersecurity firm Trend Micro.
Related:Fraud Rockets Higher in Mobile-First Latin America
"Rebuilding machines could take time depending on how effective IT can access these systems physically but more importantly remotely," he says. "All of these can cause significant delays in recovering, which is why, in some cases, an organization may pay the ransom in order to get the decryption keys and get access back to their systems and data."
Japanese companies continue to struggle with cybersecurity. Threat actors targeted Japanese enterprises with exploits for critical vulnerabilities in Ivanti's Connect Secure virtual private network product, many of which remained unpatched this summer. Japanese companies and government agencies are seeing more attacks overall, despite recently passed legislation that allows more active measures in the name of network defense.
As the world's fourth largest economy and the start of many supply chains, Japan is a major target for cybercriminals, says Shane Barney, chief information security officer at credential management firm Keeper Security.
"Ransomware groups are focusing on Japan because its industries sit at the heart of global supply chains and run with very little room for disruption," he says. "From an attacker's perspective, that creates pressure to resolve incidents quickly, which increases their leverage."
Japan Under Attack?
Some companies have seen a general acceleration in cyberattacks against targets in Japan. Cybersecurity firm Sophos, for example, has seen more than 200 named Japanese ransomware victims in the past four years, with 72 victims in the past year alone, showing some acceleration in attacks.
Related:Bank Trojan 'Casbaneiro' Worms Through Latin America
Japan as a country, however, is not specifically being targeted, says Chris Yule, director of Sophos' threat research team. Instead, the country is facing the impact of an overall global increase in ransomware attacks. In the past 12 months, the number of Japanese victims of ransomware is a third higher (35%) than the previous 12 months. However, globally the same trend is apparent: The number of ransomware victims has grown by a third (33%), he says.
"Ransomware groups are opportunistic, attacking any organizations that are vulnerable and likely to pay," Yule says. "We're not seeing any indications that they’re targeting specific geographies or market sectors, but sometimes a couple of big-name victims in the news can make it feel like a trend."
Fortune Favors the Prepared
The trend will likely to continue. While cyberattackers and ransomware groups are not done with North America and Europe, the Asia-Pacific region offers less mature security controls and processes, relatively untested incident response and recovery playbooks, and complex legacy environments, says Heath Renfrow, co-founder and chief information security officer at Fenix24, a breach-recovery services provider.
Related:Chinese Police Use ChatGPT to Smear Japan PM Takaichi
"Threat actors gravitate toward regions where recovery costs are high, the likelihood of disruption is significant, and resilience gaps are predictable," he says.
Manufacturers, such as Asahi Holdings, tend to be more vulnerable to operational disruptions.
In the end, as long as companies are vulnerable to attacks and are willing to pay a ransom to recover quickly, cybercriminals will target those companies, says Sophos' Yule. Companies that prepare by not only having backups, but also regularly holding recovery exercises and assessing the status of critical assets, will be able to recover the fastest and not need to pay ransoms.
"Preparation is key, and when an organization puts the work in upfront, we see a world of difference when we're brought in to help victims respond to these attacks," he says. "You need to know what your plan is if your entire IT infrastructure is no longer available: who's in charge, how do you communicate, what decisions need to be made, and when."
Read more about:
DR Global Asia Pacific
About the Author
Robert Lemos
Contributing Writer
Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline Journalism (Online) in 2003 for coverage of the Blaster worm. Crunches numbers on various trends using Python and R. Recent reports include analyses of the shortage in cybersecurity workers and annual vulnerability trends.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
AI SOC for MDR: The Structural Evolution of Managed Detection and Response
How Enterprises Are Developing Secure Applications
Frost Radar™: Non-human Identity Solutions
2026 CISO AI Risk Report
Gartner IGA Voice of the Customer 2026
Access More Research
Webinars
Security in the AI Age
Identity Maturity Under Pressure: 2026 Findings and How to Catch Up
Building a Robust SOC in a Post-AI World
Retail Security: Protecting Customer Data and Payment Systems
Rethinking SSE: When Unified SASE Delivers the Flexibility Enterprises Need
More Webinars
Editor's Choice
CYBERSECURITY OPERATIONS
RSAC 2026: AI Dominates, But Community Remains Key to Security
byKristina Beek,Rob Wright
APR 2, 2026
CYBERATTACKS & DATA BREACHES
Not Toying Around: Hasbro Attack May Take 'Weeks' to Remediate
byNate Nelson
APR 2, 2026
3 MIN READ
ENDPOINT SECURITY
CrowdStrike Next-Gen SIEM Can Now Ingest Microsoft Defender Telemetry
byJeffrey Schwartz
APR 3, 2026
3 MIN READ
Want more Dark Reading stories in your Google search results?
2026 Security Trends & Outlooks
THREAT INTELLIGENCE
Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats
JAN 2, 2026
CYBER RISK
Navigating Privacy and Cybersecurity Laws in 2026 Will Prove Difficult
JAN 12, 2026
ENDPOINT SECURITY
CISOs Face a Tighter Insurance Market in 2026
JAN 5, 2026
THREAT INTELLIGENCE
2026: The Year Agentic AI Becomes the Attack-Surface Poster Child
JAN 30, 2026
Download the Collection
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE
Webinars
Security in the AI Age
TUES, APRIL 28, 2026 AT 1PM EST
Identity Maturity Under Pressure: 2026 Findings and How to Catch Up
WED, MAY 6,2026 AT 1PM EST
Building a Robust SOC in a Post-AI World
THURS, MARCH 19, 2026 AT 1PM EST
Retail Security: Protecting Customer Data and Payment Systems
THURS, APRIL 2, 2026 AT 1PM EST
Rethinking SSE: When Unified SASE Delivers the Flexibility Enterprises Need
WED, APRIL 1, 2026 AT 1PM EST
More Webinars
White Papers
How Sunrun Transformed Security Operations with AiStrike
Autonomous Pentesting at Machine Speed, Without False Positives
Fixing Organizations' Identity Security Posture
Best practices for incident response planning
Industry Report: AI, SOC, and Modernizing Cybersecurity
Explore More White Papers
BLACK HAT ASIA | MARINA BAY SANDS, SINGAPORE
Experience cutting-edge cybersecurity insights in this four-day event featuring expert Briefings on the latest research, Arsenal tool demos, a vibrant Business Hall, networking opportunities, and more. Use code DARKREADING for a Free Business Pass or $200 off a Briefings Pass.
GET YOUR PASS
HEALTHCARE SECURITY WEBINAR
Protecting Patient Data and Clinical Operations
SECURE YOUR SEAT
GISEC GLOBAL 2026
GISEC GLOBAL is the most influential and the largest cybersecurity gathering in the Middle East & Africa, uniting global CISOs, government leaders, technology buyers, and ethical hackers for three power-packed days of innovation, strategy, and live cyber drills.
📌 BOOK YOUR SPACE