Asahi battles cyberattack fallout, investigates possible data exfiltration - Industrial Cyber
Industrial CyberArchived Jul 05, 2026✓ Full text saved
Asahi battles cyberattack fallout, investigates possible data exfiltration Industrial Cyber
Full text archived locally
✦ AI Summary· Claude Sonnet
Attacks And Vulnerabilities
Control Device Security
Critical Infrastructure
Industrial Cyber Attacks
Malware, Phishing & Ransomware
News
System Design & Architecture
Technology & Solutions
Threat Landscape
Asahi battles cyberattack fallout, investigates possible data exfiltration
OCTOBER 06, 2025
Japanese beermaker Asahi Group Holdings provided an update on a system disruption caused by a cyberattack. The company identified traces suggesting a potential unauthorized data transfer. An investigation is underway to determine the nature and scope of the information that may have been affected by the breach.
“Although system-based order and shipment processes remain suspended, ensuring product supply to customers has been set as our top priority, and we have begun partial manual order processing and shipment,” Asahi said in its update last Friday. “Regarding customer inquiries related to products from Asahi Breweries, Asahi Soft Drinks, and Asahi Group Foods, we are currently preparing to partially and gradually resume call center operations, including customer service desks, with the aim of starting this during the week of October 6.”
Asahi mentioned that “While we are unable to provide a clear timeline for recovery at this time, our Emergency Response Headquarters is working in collaboration with external cybersecurity experts to restore the system as quickly as possible.”
“The scope of the system disruption is currently limited to Japan,” it added. “The potential impact of this incident on our financial results for the fiscal year ending December 2025 is currently under review.”
“I would like to sincerely apologize for any difficulties caused to our stakeholders by the recent system disruption,” Atsushi Katsuki, president and group CEO, said. “We are continuing our investigation to determine the nature and scope of the potential unauthorized data transfer.”
Katsuki added that “We are making every effort to restore the system as quickly as possible, while implementing alternative measures to ensure continued product supply to our customers. We appreciate your understanding and support.”
Upon detecting the incident, an ‘Emergency Response’ headquarters was established to investigate the situation, confirming that the company’s servers were targeted by a ransomware attack. To prevent further damage, specific details regarding the cyberattack are being withheld. Immediate action was taken to contain and respond to the incident, with the highest priority placed on safeguarding critical data, including personal information of customers and business partners. Affected systems were promptly isolated to minimize the impact.
As a result of the containment measures, operations across Asahi’s domestic group companies, including order placement and product shipment, have been affected. “Additionally, we are currently unable to receive email communications from external sources,” the statement added.
Offering commentary on the Asahi cybersecurity incident, Takanori Nishiyama, senior vice president for the APAC and Japan Country Manager at Keeper Security, wrote in an emailed statement that the ransomware attack affecting Asahi Group underscores the growing exposure of Japan’s manufacturing and industrial sectors to sophisticated cyber threats. “As production environments and supply chains become increasingly digitized, cybercriminals are exploiting legacy systems, unmonitored endpoints, and privileged accounts to disrupt operations and extort payments.”
Asahi confirmed that ransomware caused system failures affecting order processing, shipments, and customer service at its domestic subsidiaries. While international operations remain unaffected, the company reported data theft from compromised servers and continues to assess the scope of the breach.
“Incidents like this highlight a consistent challenge across Asia-Pacific manufacturing: ransomware can halt production lines, delay shipments, and affect global supply continuity,” according to Nishiyama. “Compromised credentials and the misuse of privileged accounts continue to be among the most common entry points for such attacks, making identity and access management a critical component of any defense strategy.”
To mitigate these risks, Nishiyama identified that “organizations must adopt a zero-trust architecture that assumes no implicit trust and continuously verifies every user, device, and system connection. Privileged access management plays a central role in this model, enabling organizations to secure administrative accounts, enforce least-privilege policies, and monitor access to sensitive systems in real time.”
“Equally important is prioritizing security solutions that employ zero-knowledge encryption, which ensures that even service providers cannot view or access stored credentials, eliminating potential insider risks and minimizing exposure in the event of a breach,” he added. “The Asahi incident is a clear reminder that operational resilience now depends on cybersecurity resilience, and that both must evolve together as Japan’s industrial sector continues its digital transformation.”
Anna Ribeiro
Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.
Related
NIST SP 800-18r2 strengthens system planning with integrated security, privacy, and supply chain risk guidance
DHS and FRA use Project CHARIOT to boost freight rail cyber resilience, secure OT communications, protect rail infrastructure
GAO presses NTIA to address priority recommendations on spectrum management, cybersecurity, broadband oversight
OTCC expands coalition with OSC Global, brings OT integration expertise to boost critical infrastructure cybersecurity
NIST NCCoE drafts OT asset management project to strengthen industrial cyber defenses, close critical visibility gaps
NetRise Provenance strengthens federal software supply chain risk management with deeper software visibility
CISA launches ANCHOR-CI to strengthen critical infrastructure security and resilience, improve cyber coordination
FCC adopts new rules to secure submarine cable infrastructure deployment, support AI-driven global connectivity
DOE’s CESER steps up cyber supply chain defenses to protect critical energy infrastructure from emerging threats
FCC moves to new cybersecurity rules to prevent emergency alert hijacking, modernize public warning systems