Nidec Corporation (TSE: 6594; OTC US: NJDCY), the Japanese electric motor manufacturer with roughly US$17.2 billion in annual revenue and about 100,000 employees across more than 40 countries, published a second report on 4 August 2026 confirming that it can no longer rule out data leakage from the June ransomware attack on its Taiwanese subsidiary, Nidec Chaun Choung Technology Corporation. The company's forensic investigators found no explicit evidence of exfiltration, but the attacker published part of a folder and file name listing from the compromised server, which Nidec says makes it "difficult to deny" a possible leak. The Blackfield ransomware group claimed the attack in late June and demanded US$2 million. No source in this set gives a count of affected records, individuals, or files, and Nidec has not published one.
What Happened
Nidec's initial report, dated 24 June 2026 and issued from Kyoto, states that on Monday 22 June 2026 "ransomware-originated damage was confirmed in part of Nidec Chaun Choung Technology's server." The subsidiary shut down the affected server and network as an emergency containment measure, notified external specialist agencies and relevant administrative bodies, and opened a joint investigation into cause and scope.
Nidec stressed from the outset that Nidec Chaun Choung Technology "built and operates an independent network unique to its group," and that the incident would not affect Nidec Corporation or other Nidec Group companies. That segmentation claim has held across both disclosures, though no source in this set describes independent verification of it.
On 30 June, BleepingComputer reported that the Blackfield ransomware gang had claimed the intrusion and posted an extortion demand. The group gave Nidec "more than 15 days" to respond and negotiate, under threat of publishing or selling the allegedly stolen data. The headline demand was US$2 million to delete the data, with two side options: US$5,000 to push the deadline back by a single day, and US$400,000 for immediate download of the data by a third party. OSINTSights, summarising the same BleepingComputer reporting, adds that Blackfield leaked sample files showing file structures and assorted documents as proof, and notes that BleepingComputer could not confirm the validity of those samples. Cyber Magazine covered the same demand structure on 2 July, quoting Huntress vCISO Muhammad Yahya Patel on how the tiered pricing is engineered to make paying feel cheaper than fighting.
The 4 August second report, distributed via Business Wire and carried by FinancialContent, StockTitan and TipRanks, is where the posture shifts. The external local investigation firm hired by Nidec Chaun Choung Technology "has so far confirmed no explicit evidence (e.g., logs) showing any data leak." At the same time, while the attacker had not published the actual files stored on the targeted server, "part of the list of folder and file names was confirmed to be published" on the dark web leak site. Nidec's conclusion: the absence of forensic evidence is not enough to deny a possible leak of the data on that list and other information. As of the date of the report, Nidec says no data from the folder and file list has been confirmed as published.
Accounts differ slightly on business impact, and the difference is one of timing rather than substance. BleepingComputer's late-June write-up recorded Nidec as still investigating possible effects on production and shipping. A Japan IR page summarising the June TDnet filing (AI-generated, per its own disclaimer) states more flatly that there was no impact on production or shipping. The 4 August report, which is the most recent and most authoritative of the three, says the Taiwanese unit is operating normally and that the company expects only minimal impact on consolidated performance, with the financial figure still under assessment. Treat the June "no impact" framing as provisional and the August statement as current.
What Was Taken
This is the honest answer: nobody has published a number, and Nidec explicitly says it does not have one.
What is confirmed by Nidec's own statement is that a partial listing of folder and file names from the compromised server was published on Blackfield's dark web site. That is metadata, not content. Directory listings can still be sensitive on their own, since folder trees frequently expose customer names, project codenames, supplier identities, contract references and internal organisational structure without a single document ever being opened.
What is claimed but unverified is that Blackfield holds a substantive volume of stolen data. The group posted sample files showing file structures and various documents as proof of possession, per BleepingComputer's reporting relayed by OSINTSights, and BleepingComputer said it could not confirm those samples were genuine.
What has not been confirmed by anyone is the leak of personal or confidential information. Nidec said so in June and repeated the position in August, with the added caveat that a leak can no longer be ruled out. There is no report in this source set of customer notification, regulatory enforcement, or an identified category of compromised personal data.
Nidec Chaun Choung Technology is a thermal solutions business within the Nidec group, so the plausible sensitive holdings are engineering documentation, manufacturing process data, supplier and customer commercial records, and employee HR files. That is inference from the subsidiary's role, not something any source states.
Why It Matters
The structural lesson here is subsidiary risk. Nidec is a US$17 billion parent with a global footprint, and the compromise landed on an acquired Taiwanese unit running its own independent network. That independence is what Nidec credits for containment, and on the evidence so far it worked: two disclosures six weeks apart, and neither reports lateral movement into the parent or sibling companies. Multinationals that have chased full IT consolidation should note that the segmentation frequently criticised as legacy debt is exactly what limited blast radius in this case.
The second lesson is about how leak sites shape disclosure. Nidec's forensics found nothing. The company still had to publicly concede probable leakage, because the attacker published a directory listing. Extortion crews have learned that they do not need to dump data to force a disclosure obligation; a file tree is cheap to publish, hard for a victim to disprove, and sufficient to move a company from "no evidence" to "cannot deny." Defenders should assume that any incident response timeline is now partly controlled by the adversary's publishing schedule, not just the forensic evidence.
Third, the price structure is worth studying. US$2 million to delete, US$400,000 for a third party to buy the data outright, and US$5,000 a day to stall. The Huntress commentary in Cyber Magazine frames the intent plainly: the demand is calibrated to be easier to pay than to fight. The US$400,000 resale option is the part defenders should register, because it means non-payment does not remove the risk of the data reaching a buyer, and it undercuts the assumption that ransom refusal is a clean decision.
Finally, the manufacturing and automotive supply chain context matters. Nidec supplies motors for EVs, electric power steering and advanced driver assistance systems, alongside micro-precision motors for phones and hard drives. Downstream customers of a tier supplier should treat any confirmed compromise at that supplier as a prompt to review what of their own design and commercial data sits on the supplier's systems.
The Attack Technique
Initial access vector, ransomware variant behaviour, dwell time, and the presence or absence of a confirmed exfiltration channel are all unstated across every source in this set. Nidec describes the event only as "unauthorized access" and a ransomware infection affecting part of one server, with the cause still under investigation by an external local firm as of the 4 August report.
What can be said with confidence:
- The intrusion was attributed by the actor itself. Blackfield claimed the attack on its leak site; Nidec has not named a group in its own disclosures.
- Containment was server and network shutdown, executed after damage was already confirmed on 22 June, which indicates detection at or near the encryption stage rather than earlier in the intrusion chain.
- The attacker's leverage rests on claimed exfiltration, and the only publicly verified artefact of that claim is a partial folder and file name listing plus unverified sample files.
- Nidec's forensic team found no log evidence of data leaving the environment. That is a meaningful negative finding, but it is also consistent with insufficient logging retention or coverage on the affected server, and no source clarifies which.
Anyone building detections off this incident should treat Blackfield's tradecraft as unknown from these sources and rely on generic ransomware precursor telemetry rather than incident-specific indicators. No IOCs have been published in any of the reporting reviewed here.
What Organizations Should Do
-
Audit logging coverage on file servers before you need it. Nidec's investigators could not find evidence either way, and that ambiguity is what forced a probable-leak disclosure. Verify that file access, authentication and egress logs on document repositories are retained long enough (90 days minimum, 180 preferred) and shipped off-host, so a post-incident forensic answer is actually available.
-
Inventory and test subsidiary network segmentation. Nidec's containment argument rests on its Taiwanese unit running an isolated network. Confirm the same is true for your acquired entities: map trust relationships, shared identity providers, VPN tunnels and management planes between parent and subsidiary, and test whether a compromise on one side reaches the other.
-
Build a directory-listing exposure plan. Assume an attacker may publish your file tree without publishing files. Review whether folder and file naming conventions leak customer names, project codenames or contract identifiers, and pre-draft the disclosure and customer-notification position for a metadata-only leak, since that scenario now drives real regulatory and contractual obligations.
-
Model the resale option, not just the deletion demand. Blackfield offered the data for US$400,000 to any buyer alongside the US$2 million deletion price. Ransom decision frameworks that only weigh publication risk are incomplete. Assume compromised data circulates regardless of payment, and prioritise credential rotation, contract review and downstream notification over negotiation outcomes.
-
Harden and monitor remote access into overseas manufacturing sites. With the initial vector unpublished, cover the common ones: enforce phishing-resistant MFA on all external access to subsidiary environments, remove or gate internet-exposed RDP and management interfaces, and patch edge appliances on an accelerated cycle at sites with thin local IT staffing.
-
Rehearse the containment decision. Nidec shut down the affected server and network within the response window and appears to have limited spread. That decision is far easier when the authority to pull a production network offline has been pre-delegated to site leadership. Run a tabletop that specifically tests who can order a manufacturing site disconnect, and how fast.
Sources: Nidec Announces the Second Report on Ransomware-caused Damage to an... | Blackfield ransomware asks Nidec Corporation for $2 million ransom | Initial Report on Ransomware-caused Damage to an ... | 【NIDEC】 Overseas Subsidiary Hit by Ransomware|June 2026 Japan IR | Nidec Taiwan Unit Operating Normally After Ransomware Attack | nidec-reports-limited-impact-from-ransomware-attack-on-taiwanese-su... | Security Lessons from the Nidec Ransomware Attack Cybersecurity Ma... | Blackfield Ransomware Targets Nidec with $2 Million Extortion Deman...