LIVE · cybersecurity feed
Live wire
ransomware

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.

ZeroDay News ·

Source: BleepingComputer

IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.

The company, a subsidiary of SoftBank Group, stated that the attack necessitated a shutdown of the affected network and systems. An internal investigation determined that a third-party ransomware attack caused the disruption in "East Japan Region 1." The full scope and precise cause of the impact are still under investigation.

IDCF Cloud provides infrastructure-as-a-service, offering virtual servers, storage, and networking to customers for running websites, applications, and business systems within Japanese data centers. The company confirmed that 495 companies and local government entities utilizing its cloud service have been impacted by the attack.

Upon detecting the compromise, IDC Frontier immediately isolated and shut down affected systems in "East Japan Region 1" to prevent further spread. The company is actively working to identify and block the intrusion route and is conducting security checks across its other regions. As a precautionary measure, IDCF Cloud has proactively disabled customer access to management consoles across all regions, with access to be restored once security is confirmed.

Screenshots reportedly seen by IDCF Cloud clients before their console access was revoked displayed a message from the threat actor. The message claimed that the breach of IDCF Cloud's "East Japan Region 1" infrastructure took only seven minutes. The attackers further asserted that they encrypted 225 databases, corresponding to 3.6 petabytes of data, reached 239 hypervisors, sealed 16,000 virtual machine disks, and wiped 554,153 snapshots. These claims by the attacker remain unverified by IDC Frontier.

In a separate but potentially related incident, Nissui Corporation, a Japanese marine products company, announced a system outage at its logistics subsidiary, Nissui Logistics. This outage was attributed to suspected unauthorized access to a third-party data center it utilizes, leading to disruptions in goods shipment and reception. Nissui is investigating whether personal information or customer data was compromised. It is currently unclear if the Nissui outage is connected to the attack on IDCF Cloud.

This incident follows a recent increase in cybersecurity attacks targeting major Japanese companies. Analysis by security researchers indicates that attackers are increasingly probing websites and APIs for weaknesses in access control, configuration, and authentication, as well as exploiting known (n-day) vulnerabilities. The rise of capable and affordable AI tools is believed to be contributing to a shift in the landscape, making broad and detailed exploration of security weaknesses more feasible for attackers.

ransomwarecloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…

ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

saashigh

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A recent security incident involving the British online fashion retailer ASOS has brought to light the inherent risks associated with customer-facing Software-as-a-Service (SaaS) platforms. The breach reportedly showcased how the compromise of a single user identity could serve as an initial access vector, subsequently allowing attackers to achieve broad penetration into a company's internal…

patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.