IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.
The company, a subsidiary of SoftBank Group, stated that the attack necessitated a shutdown of the affected network and systems. An internal investigation determined that a third-party ransomware attack caused the disruption in "East Japan Region 1." The full scope and precise cause of the impact are still under investigation.
IDCF Cloud provides infrastructure-as-a-service, offering virtual servers, storage, and networking to customers for running websites, applications, and business systems within Japanese data centers. The company confirmed that 495 companies and local government entities utilizing its cloud service have been impacted by the attack.
Upon detecting the compromise, IDC Frontier immediately isolated and shut down affected systems in "East Japan Region 1" to prevent further spread. The company is actively working to identify and block the intrusion route and is conducting security checks across its other regions. As a precautionary measure, IDCF Cloud has proactively disabled customer access to management consoles across all regions, with access to be restored once security is confirmed.
Screenshots reportedly seen by IDCF Cloud clients before their console access was revoked displayed a message from the threat actor. The message claimed that the breach of IDCF Cloud's "East Japan Region 1" infrastructure took only seven minutes. The attackers further asserted that they encrypted 225 databases, corresponding to 3.6 petabytes of data, reached 239 hypervisors, sealed 16,000 virtual machine disks, and wiped 554,153 snapshots. These claims by the attacker remain unverified by IDC Frontier.
In a separate but potentially related incident, Nissui Corporation, a Japanese marine products company, announced a system outage at its logistics subsidiary, Nissui Logistics. This outage was attributed to suspected unauthorized access to a third-party data center it utilizes, leading to disruptions in goods shipment and reception. Nissui is investigating whether personal information or customer data was compromised. It is currently unclear if the Nissui outage is connected to the attack on IDCF Cloud.
This incident follows a recent increase in cybersecurity attacks targeting major Japanese companies. Analysis by security researchers indicates that attackers are increasingly probing websites and APIs for weaknesses in access control, configuration, and authentication, as well as exploiting known (n-day) vulnerabilities. The rise of capable and affordable AI tools is believed to be contributing to a shift in the landscape, making broad and detailed exploration of security weaknesses more feasible for attackers.






