Cyberattacks on Japanese Companies Expose Structural Weaknesses | #ransomware | #cybercrime



TOKYO –
Japan is entering a more difficult phase in its cybersecurity challenge, as a succession of major data breaches and ransomware attacks exposes weaknesses not only in corporate IT systems but also in supplier networks, governance structures and operational resilience.

The scale of the problem has become increasingly difficult to dismiss. Japan’s National Police Agency confirmed 123 ransomware attacks during the first six months of 2026, the highest half-year total since comparable statistics began in 2020 and seven more than a year earlier. Thirty-one involved major companies. In more than half of the cases, recovery took longer than a month, while nine resulted in the complete suspension of business operations. Losses exceeded 10 million yen in about 60% of cases.

The figures point to a shift in the nature of cyber risk. What was once treated largely as a technical issue for corporate IT departments is increasingly becoming a question of business continuity, supply-chain stability, financial exposure and management accountability.

Japan’s broader data-management problem is also substantial. The Personal Information Protection Commission handled 17,139 reports of personal-data leaks and related incidents involving private organizations in fiscal 2025. While many involved administrative mistakes rather than cyberattacks, more than one-fifth were linked to unauthorized access or other malicious activity.

The distinction is important. Japan is facing two overlapping problems: a persistent weakness in the handling of sensitive information and a rapid increase in the sophistication and commercial scale of cybercrime.

A major breach at KDDI in 2026 illustrated the growing exposure created by interconnected corporate systems.

KDDI discovered unauthorized access to an email platform it operated for six internet service providers after attackers exploited a vulnerability in third-party software. The company initially said as many as 14.22 million email addresses and associated passwords could have been exposed. Subsequent investigations confirmed that more than 12.23 million email addresses had leaked, including passwords belonging to about 7.62 million people.

The significance of the incident extended beyond KDDI itself.

Because the affected infrastructure was shared across multiple service providers, a weakness in one system created exposure across a broader commercial network. BIGLOBE alone confirmed that more than 5 million email addresses had leaked, including passwords associated with more than 4.6 million accounts.

The breach underlined a central vulnerability in modern corporate infrastructure: companies increasingly depend on external software, cloud services, telecommunications providers and specialist vendors over which they do not have direct operational control.

In such an environment, cybersecurity is only as strong as the weakest point in an interconnected network.

The Asahi Group Holdings ransomware attack provided a different but equally significant example.

Attackers entered Asahi’s Japanese network in September 2025 through network equipment at a group location and remained inside the system for roughly 10 days before deploying ransomware.

During that period, they obtained administrative privileges and moved through the company’s internal network, examining servers and systems largely outside regular business hours.

When the ransomware was activated on September 29, the impact moved rapidly beyond information security.

Orders and shipments were disrupted, factory operations were affected, and Asahi was temporarily forced to process some transactions manually. Production at its six domestic beer factories resumed only gradually.

The incident demonstrated how cyberattacks can convert directly into operational disruption.

For a large manufacturer or consumer-products group, the financial consequences of a breach are no longer limited to data recovery, legal expenses or reputational damage. They can include halted production, delayed shipments, lost sales, emergency procurement costs and disruption throughout the supply chain.

The 2024 ransomware attack against KADOKAWA had already provided an earlier warning.

That incident disrupted services including the Niconico video platform and compromised internal file servers operated by Dwango. KADOKAWA later confirmed the leakage of personal information belonging to 254,241 people, including employees, former employees, business partners, creators, job applicants and individuals connected with its education operations.

The three cases differed in technical detail, but collectively they reveal a recurring pattern.

The first is supply-chain exposure.

Large Japanese companies may invest heavily in cybersecurity, but they rely on extensive networks of subsidiaries, contractors, software vendors and small and midsize suppliers. Those organizations frequently operate with smaller IT budgets, older infrastructure and limited access to specialized cybersecurity personnel.

Attackers therefore do not necessarily need to penetrate the strongest systems directly. A poorly protected supplier, an unpatched remote-access device or a vulnerable third-party application may provide a less costly route into a larger corporate network.

This is particularly important in Japan, where industrial supply chains are often deep and highly fragmented.

Manufacturers can have hundreds or thousands of suppliers, some of which are small companies with limited capacity to invest in security infrastructure. A weakness several layers down the supply chain can therefore become a material risk for a large listed company.

Independent research has shown that smaller companies account for a disproportionate share of ransomware victims in Japan. Manufacturing is especially exposed because digital systems are increasingly integrated into production, inventory control, logistics and procurement.

The second structural weakness is legacy infrastructure.

Japanese companies have traditionally placed a premium on extending the operational life of physical assets and enterprise systems. That approach can generate efficiency in capital-intensive industries, but it creates a growing cybersecurity problem when software, network equipment and applications remain in use beyond the period in which they can be securely maintained.

Older systems may depend on unsupported operating systems, outdated software or network architectures designed before current cyber threats emerged.

Modernizing those systems is expensive and operationally difficult.

Factories, hospitals, financial institutions and logistics companies cannot easily take critical systems offline while infrastructure is rebuilt. As a result, businesses may continue operating with known technical debt because the immediate cost and disruption of replacement appear greater than the perceived risk of a future attack.

Cybercrime is exploiting that calculation.

A third issue is human capital.

Japan faces a persistent shortage of experienced cybersecurity professionals. The Information-technology Promotion Agency has cited estimates of a nationwide shortfall of roughly 110,000 people.

The shortage is especially acute among small and midsize companies, many of which do not have dedicated security teams.

Cybersecurity responsibilities are instead absorbed into general IT departments already responsible for employee systems, networks, enterprise applications and technical support.

The imbalance between attacker and defender is significant.

An attacker needs to identify one effective point of entry. A company must maintain adequate protection across every privileged account, employee device, external connection, software application and third-party interface continuously.

The economics of cybercrime have also become more favorable to attackers.

Ransomware has evolved into a commercial ecosystem in which specialist groups develop malware, maintain payment infrastructure and provide technical support to affiliates that carry out intrusions.

This “ransomware as a service” model has reduced the technical barrier to entry and allowed cybercrime groups to operate with a degree of specialization increasingly comparable to legitimate businesses.

Extortion tactics have also become more sophisticated.

Attackers frequently steal sensitive information before encrypting company systems, creating what is known as double extortion. Even where a company can restore its servers from backups, it may still face demands for payment in exchange for preventing stolen information from being released publicly.

National Police Agency figures for 2024 showed that 111 of 134 ransomware cases in which payment methods were identified involved double extortion.

That development has altered the economics of corporate cybersecurity.

Traditional disaster recovery was built around the assumption that data could be restored. Modern ransomware creates a second problem: once confidential information has been removed from a corporate network, the company can no longer regain control over it.

Japan has begun to respond more aggressively.

The most significant policy change came with legislation passed in May 2025 establishing what is generally described as “active cyber defense.”

The Cyber Response Capability Enhancement Act gives the government broader authority to identify and respond to serious cyber threats, particularly attacks affecting critical infrastructure and national security.

The framework expands public-private information sharing and allows the government, under prescribed conditions, to analyze certain communications data and take measures intended to disrupt systems being used in serious cyberattacks.

Japan has also reorganized its central cybersecurity apparatus.

The National Center of Incident Readiness and Strategy for Cybersecurity was replaced in July 2025 by the National Cybersecurity Office, reflecting an effort to give cyber policy greater institutional weight and improve coordination across government.

The policy shift is substantial.

Japan’s previous approach was largely defensive and decentralized. The new framework represents a move toward earlier detection, greater intelligence sharing and more active intervention.

However, active cyber defense addresses only part of the problem.

It may improve Japan’s ability to identify and disrupt sophisticated attacks, but it does not resolve weaknesses inside individual companies.

It cannot ensure that a regional supplier installs a security patch. It cannot guarantee that a manufacturer separates production networks from administrative systems. Nor can it prevent employees from using weak credentials or companies from continuing to operate unsupported software.

The government is therefore pursuing a second strategy focused on supply chains.

The Ministry of Economy, Trade and Industry and the National Cybersecurity Office are developing the Supply Chain Security assessment system, known as SCS.

The system is intended to establish common cybersecurity standards that companies can use when assessing suppliers.

A basic three-star level will cover essential defensive and organizational measures, while four stars will require broader governance, monitoring, incident response and third-party assessment. A higher five-star category is planned for companies seeking more advanced risk-based protection.

The three- and four-star programs are expected to begin around the end of fiscal 2026.

From a corporate perspective, the concept is significant.

Large companies will eventually be able to require suppliers to demonstrate compliance with recognized cybersecurity standards rather than relying on fragmented internal questionnaires and contractual assurances.

But the framework remains voluntary.

That creates an obvious limitation. Unless major companies incorporate such standards into procurement decisions, supplier assessments may become another compliance exercise rather than a meaningful change in operational risk management.

Japan has also tightened privacy regulation.

Under the Act on the Protection of Personal Information, companies are already required to notify regulators when serious data breaches occur. Initial reports are generally required within several days, followed by more detailed disclosures.

A further amendment passed in July 2026 introduces additional protections and allows financial penalties in certain cases where companies obtain economic benefits through unlawful handling of personal information.

The Personal Information Protection Commission has also increased public warnings following large-scale leakage incidents.

These measures strengthen accountability after a breach occurs.

The more difficult question is whether they are sufficient to reduce the likelihood of the breach occurring in the first place.

On that measure, Japan’s progress remains uneven.

The policy framework is becoming stronger. The government has broader cyber-defense powers, regulators have greater oversight, companies face clearer reporting obligations and supply-chain standards are being developed.

Yet the volume of attacks continues to rise.

That suggests the principal weakness is no longer the absence of policy, but inconsistent execution across the corporate sector.

For large companies, cybersecurity is increasingly becoming a governance issue.

Boards are being forced to consider whether management understands which systems are critical, how quickly operations could be restored, what dependencies exist across suppliers and whether cyber risk is being treated with the same discipline as liquidity, compliance, safety or geopolitical exposure.

The financial implications are becoming harder to ignore.

A serious cyberattack can interrupt revenue, increase operating costs, disrupt production, weaken customer confidence and expose companies to regulatory and legal liabilities.

For listed companies, the consequences can also extend to disclosure obligations, investor confidence and valuation.

The largest vulnerability may therefore be cultural rather than technical.

Cybersecurity has traditionally been treated as a specialist function delegated to IT departments. That model is becoming obsolete.

A company’s exposure increasingly depends on procurement policy, capital expenditure, employee training, supply-chain management, crisis planning and executive oversight.

The KDDI breach demonstrated the risk created by shared infrastructure and third-party software. Asahi showed how a network intrusion can escalate into a production and logistics problem. KADOKAWA illustrated the financial and reputational leverage created when attackers obtain sensitive information.

Together, they point to a broader transition.

Japan’s cybersecurity challenge is no longer simply about protecting data.

It is about protecting the ability of companies to operate.

Whether the country’s current reforms are sufficient will depend less on the breadth of new legislation than on whether cybersecurity becomes embedded in routine corporate decision-making.

Japan has begun building the regulatory and institutional architecture required for that transition.

The more difficult task now is ensuring that the standards applied by major corporations extend throughout the thousands of smaller businesses, contractors and technology providers on which those corporations depend.



Source link

...........