IDC Frontier has confirmed that a ransomware attack by a third party disrupted its IDCF Cloud infrastructure-as-a-service platform. The disruption began at about 3:40 AM local time on October 7, 2026, and the company says it affects 495 companies and local governments that use the service. IDC Frontier is a SoftBank company. BleepingComputer describes it as a SoftBank Group subsidiary, while Kyodo (via The Mainichi) and ITmedia name SoftBank Corp. as the parent. The affected infrastructure is East Japan Region 1, which ITmedia places at a data center in Shirakawa, Fukushima Prefecture. In its third update, IDC Frontier said customer data in four zones of that region will likely be hard or impossible to retrieve, and that customers can restore only from backups they hold themselves. The attacker claims the damage is far larger, but those claims have not been verified.
What Happened
Timeline from IDC Frontier's own notices, as compiled by piyolog and confirmed in the company's third report:
- October 7, ~3:40 AM: The disruption begins in East Japan Region 1. The company's third report lists the affected zones as tesla, henry, pascal and joule. The symptoms were virtual servers stopping and then failing to restart.
- October 7, morning: Before IDC Frontier said anything, affected organizations started posting outage notices. piyolog reports that the UDTalk speech-recognition app named IDCF Cloud as the cause at 9:32 AM.
- October 7, 1:52 PM (first report): IDC Frontier blames the disruption on unauthorized access by a third party.
- October 7, 8:18 PM (second report): The company confirms ransomware and says 495 companies and local governments are affected.
- October 8 (third report): IDC Frontier says customer data in the four affected zones is unlikely to be recoverable from its side. It adds that it has reported the incident to its supervisory ministry and the Tokyo Metropolitan Police Department, and is working with an outside security firm.
Containment. IDC Frontier cut East Japan Region 1 off from the network and shut down its systems, stating this was "to prevent secondary damage and data leaks." It also shut down the customer-facing management consoles in every region while it checks their security. Because the consoles are offline, IDC Frontier staff are starting and stopping customers' virtual servers on request.
Scope. The company says it has found no unauthorized access in the region's other zones (radian and newton), in East Japan Regions 2 and 3, or in West Japan Region 1. It is still telling customers there to make their own backups. IDCF Cloud TypeS (formerly White Cloud ASPIRE) and IDCF Private Cloud are not affected.
Downstream impact. Organizations that publicly named IDCF Cloud as the cause include:
- Six Apart: 31 Movable Type cloud servers are down. The company is restoring from backups taken before the incident (as of 1:00 AM on October 7) and stored on Google Cloud, and is moving the servers to Sakura Cloud.
- UDTalk (Shamrock Records): The company says IDCF told it "data restoration is difficult." It is rebuilding on another cloud.
- Hoover Brain: Manager functions for its Eye 247 products are down. The company says those services used IDCF only as a network path and kept their databases with another provider.
- Greenwich: Its e-commerce tools Rakuraku Zaiko and Rakuraku Saiyasu Koshin are down, and Ultra ASP is partly affected.
- SKIMA: At first the company described its data as very difficult to recover. It later found data it could recover from.
Other outages were reported, though these organizations did not publicly name IDCF. The Mainichi reports that the websites of the Ibaraki prefectural government and prefectural police went offline. Nissui Corp. said a system failure at a logistics subsidiary that uses the cloud service disrupted shipments to and from its frozen-food cold storage warehouses. ITmedia lists the Japan Basketball Association, Radio Kansai, Kodaira City, J.League clubs, Tobu Zoo and JRA-VAN World as also reporting outages.
What Was Taken
No exfiltration has been confirmed. IDC Frontier says it is still checking whether personal information was leaked (piyolog, citing the company's comments to the press). Its third report says the scope of impact is still under investigation.
All of the following figures come from the attacker and none have been confirmed. Before the consoles went down, customers took screenshots of a message the attacker posted there. BleepingComputer, citing those screenshots, reports the attacker's claims:
- the breach took seven minutes
- 225 databases totaling 3.6 PB were encrypted
- 239 hypervisors were reached
- 16,000 VM disks were "sealed"
- 554,153 snapshots were wiped
IDC Frontier has not published any figures for encrypted data, hypervisors or snapshots. A company official told Kyodo: "We are aware that such a statement has been issued, but we are investigating its authenticity."
The company's own statement suggests the attack destroyed data rather than stealing it. IDC Frontier says the data in the four affected zones will be difficult to retrieve or restore, so for most tenants there the platform is effectively unrecoverable. Downstream accounts differ somewhat. SKIMA later found data it could recover from. Six Apart and UDTalk were told, or concluded, that recovery on IDCF was not possible. No ransomware group has publicly claimed the attack in these sources, and no ransom demand has been reported.
Why It Matters
- One provider, hundreds of victims. This was an attack on the hypervisor and management layer of an IaaS provider, and it took out websites, SaaS products, local government services and cold-chain logistics in one go. The tenants included municipalities and prefectural bodies.
- Provider snapshots are not backups. If the snapshot-wipe claim is true, tenants who relied on IDCF Cloud snapshots lost those recovery points along with their live data. Six Apart could start restoring quickly because it kept backups on a different IaaS provider. Others were left trying to recover data from inside the platform.
- Containment caused much of the outage. IDC Frontier's own isolation of the region and its console lockout in every region took services offline whether or not the attacker had reached them. Tenants have also lost self-service control of their infrastructure for an open-ended period.
- Other regions are still exposed. The intrusion route has not been found. Until it is, IDC Frontier cannot rule out the same path into its other regions, which explains its blanket instruction for all customers to back up.
The Attack Technique
The initial access vector is unknown. IDC Frontier says it is still identifying and blocking the intrusion route, with help from an outside security firm that is examining network, server and storage components in both East and West Japan regions.
Several details point to an attack on the virtualization control plane rather than on individual tenant workloads:
- The attacker says it reached 239 hypervisors and posted its message in tenant-facing consoles. That would mean it had privileged access to the cloud management layer.
- The claim of encrypting VM disks and wiping snapshots in bulk matches the pattern of earlier hypervisor-focused ransomware: take over management, destroy recovery points, then encrypt virtual disks at the storage layer.
- The attack hit four specific zones while the region's other two zones were reported unaffected. This could mean the attacker's reach was bounded by infrastructure segmentation, though IDC Frontier has not said so.
The claimed seven-minute breach time is unverified, and it may describe only the final stage after earlier access had been gained.
What Organizations Should Do
- Keep backups outside your provider's control plane. Store copies on a separate provider or in an offline, immutable location, with credentials that are not linked to your production cloud account. Do not count provider snapshots as backups.
- Practice moving to another provider. Six Apart could restore onto Sakura Cloud because it already had backups held elsewhere. Write down and test a rebuild-elsewhere runbook for your critical services, covering DNS, images, configuration and data.
- Map your hidden dependencies on hosting providers. Many affected organizations did not know, or did not say, which provider they were using. Find out which of your vendors, SaaS tools and website hosts run on shared IaaS, and ask them for their backup and recovery arrangements.
- IDCF customers in unaffected regions should act now. Follow IDC Frontier's advice to take your own backups immediately. Plan for the consoles to stay down. Watch for unusual activity in guest operating systems and rotate any credentials stored on the platform.
- Harden your virtualization management layer. If you run hypervisors yourself, put management interfaces on an isolated network, require phishing-resistant MFA for administrators, alert on bulk snapshot deletion, and set snapshot deletion protection or retention locks.
- Prepare for data exposure as well as downtime. Exfiltration has not been ruled out. Local governments and businesses handling personal data should prepare to meet their notification obligations under Japan's APPI while IDC Frontier's investigation continues.
Sources: Ransomware in one IDCF Cloud region hits 495 tenants | Ransomware attack disrupts Japan's IDCF Cloud used by govt ... | IDCF Cloud ransomware attack hits 495 Japanese customers | IDCFクラウドへのランサムウェア攻撃についてまとめてみた - piyolog | Ransomware attack hits IDC Frontier's IDCF Cloud, 495 clients affec... | 【第3報】当社サービスの一部システムへの不正アクセスによる障害について ニュース IDCフロンティア | IDCFクラウドへのランサム攻撃、495の企業・自治体に影響 一部には「復元難しい」との通達も - ITmedia NEWS | SoftBank subsidiary's cloud service disrupted in cyberattack - The...