Cyber & AI intelligence
Wasteland.
Briefs indexed3090
Issues31
Published Mondays07:30 CT
█ Ransomware IDC-FRONTIER-IDCF 2026-10-09

IDC Frontier: Ransomware Attack Takes Down IDCF Cloud East Japan Region 1

"IDC Frontier has confirmed that a ransomware attack by a third party disrupted its IDCF Cloud infrastructure-as-a-service platform. The disruption began at about 3:40 AM local time on October 7, 2026, and the company…"

IDC Frontier has confirmed that a ransomware attack by a third party disrupted its IDCF Cloud infrastructure-as-a-service platform. The disruption began at about 3:40 AM local time on October 7, 2026, and the company says it affects 495 companies and local governments that use the service. IDC Frontier is a SoftBank company. BleepingComputer describes it as a SoftBank Group subsidiary, while Kyodo (via The Mainichi) and ITmedia name SoftBank Corp. as the parent. The affected infrastructure is East Japan Region 1, which ITmedia places at a data center in Shirakawa, Fukushima Prefecture. In its third update, IDC Frontier said customer data in four zones of that region will likely be hard or impossible to retrieve, and that customers can restore only from backups they hold themselves. The attacker claims the damage is far larger, but those claims have not been verified.

What Happened

Timeline from IDC Frontier's own notices, as compiled by piyolog and confirmed in the company's third report:

Containment. IDC Frontier cut East Japan Region 1 off from the network and shut down its systems, stating this was "to prevent secondary damage and data leaks." It also shut down the customer-facing management consoles in every region while it checks their security. Because the consoles are offline, IDC Frontier staff are starting and stopping customers' virtual servers on request.

Scope. The company says it has found no unauthorized access in the region's other zones (radian and newton), in East Japan Regions 2 and 3, or in West Japan Region 1. It is still telling customers there to make their own backups. IDCF Cloud TypeS (formerly White Cloud ASPIRE) and IDCF Private Cloud are not affected.

Downstream impact. Organizations that publicly named IDCF Cloud as the cause include:

Other outages were reported, though these organizations did not publicly name IDCF. The Mainichi reports that the websites of the Ibaraki prefectural government and prefectural police went offline. Nissui Corp. said a system failure at a logistics subsidiary that uses the cloud service disrupted shipments to and from its frozen-food cold storage warehouses. ITmedia lists the Japan Basketball Association, Radio Kansai, Kodaira City, J.League clubs, Tobu Zoo and JRA-VAN World as also reporting outages.

What Was Taken

No exfiltration has been confirmed. IDC Frontier says it is still checking whether personal information was leaked (piyolog, citing the company's comments to the press). Its third report says the scope of impact is still under investigation.

All of the following figures come from the attacker and none have been confirmed. Before the consoles went down, customers took screenshots of a message the attacker posted there. BleepingComputer, citing those screenshots, reports the attacker's claims:

IDC Frontier has not published any figures for encrypted data, hypervisors or snapshots. A company official told Kyodo: "We are aware that such a statement has been issued, but we are investigating its authenticity."

The company's own statement suggests the attack destroyed data rather than stealing it. IDC Frontier says the data in the four affected zones will be difficult to retrieve or restore, so for most tenants there the platform is effectively unrecoverable. Downstream accounts differ somewhat. SKIMA later found data it could recover from. Six Apart and UDTalk were told, or concluded, that recovery on IDCF was not possible. No ransomware group has publicly claimed the attack in these sources, and no ransom demand has been reported.

Why It Matters

The Attack Technique

The initial access vector is unknown. IDC Frontier says it is still identifying and blocking the intrusion route, with help from an outside security firm that is examining network, server and storage components in both East and West Japan regions.

Several details point to an attack on the virtualization control plane rather than on individual tenant workloads:

The claimed seven-minute breach time is unverified, and it may describe only the final stage after earlier access had been gained.

What Organizations Should Do

  1. Keep backups outside your provider's control plane. Store copies on a separate provider or in an offline, immutable location, with credentials that are not linked to your production cloud account. Do not count provider snapshots as backups.
  2. Practice moving to another provider. Six Apart could restore onto Sakura Cloud because it already had backups held elsewhere. Write down and test a rebuild-elsewhere runbook for your critical services, covering DNS, images, configuration and data.
  3. Map your hidden dependencies on hosting providers. Many affected organizations did not know, or did not say, which provider they were using. Find out which of your vendors, SaaS tools and website hosts run on shared IaaS, and ask them for their backup and recovery arrangements.
  4. IDCF customers in unaffected regions should act now. Follow IDC Frontier's advice to take your own backups immediately. Plan for the consoles to stay down. Watch for unusual activity in guest operating systems and rotate any credentials stored on the platform.
  5. Harden your virtualization management layer. If you run hypervisors yourself, put management interfaces on an isolated network, require phishing-resistant MFA for administrators, alert on bulk snapshot deletion, and set snapshot deletion protection or retention locks.
  6. Prepare for data exposure as well as downtime. Exfiltration has not been ruled out. Local governments and businesses handling personal data should prepare to meet their notification obligations under Japan's APPI while IDC Frontier's investigation continues.

Sources: Ransomware in one IDCF Cloud region hits 495 tenants | Ransomware attack disrupts Japan's IDCF Cloud used by govt ... | IDCF Cloud ransomware attack hits 495 Japanese customers | IDCFクラウドへのランサムウェア攻撃についてまとめてみた - piyolog | Ransomware attack hits IDC Frontier's IDCF Cloud, 495 clients affec... | 【第3報】当社サービスの一部システムへの不正アクセスによる障害について ニュース IDCフロンティア | IDCFクラウドへのランサム攻撃、495の企業・自治体に影響 一部には「復元難しい」との通達も - ITmedia NEWS | SoftBank subsidiary's cloud service disrupted in cyberattack - The...