A ransomware attack against Japanese cloud provider IDC Frontier has disrupted online services used by hundreds of businesses and local government organizations. The incident forced the company to shut down parts of its infrastructure while investigating the extent of the damage.
The attack began on October 7 at approximately 3:40 a.m. local time and affected IDCF Cloud’s East Japan Region 1. IDC Frontier, a subsidiary of SoftBank, confirmed that unauthorized access by a third party was responsible for the disruption.
According to the company, 495 businesses and local government organizations were affected. The incident caused virtual servers to stop operating, while some customers were unable to restart their systems or access essential cloud resources.
IDCF Cloud provides virtual servers, storage and networking services that organizations use to operate websites, applications and business systems. An attack on this infrastructure can therefore interrupt services belonging to multiple customers simultaneously.
After discovering the intrusion, IDC Frontier disconnected affected systems from its network to prevent further damage. The company also temporarily disabled customer access to management consoles across its cloud regions while checking whether other environments had been compromised.
Investigators have not identified unauthorized access in the other regions. However, customers have been advised to create backups of their data while the company continues assessing the security of its infrastructure.
The attackers reportedly displayed a message claiming responsibility for the incident. They alleged that they had encrypted 225 databases containing approximately 3.6 petabytes of data, affected 239 virtualization servers, and locked 16,000 virtual machine disks.
The message also claimed that more than 554,000 backup snapshots had been deleted. These figures come from the attackers and have not been independently verified or confirmed by IDC Frontier.
The disruption has raised concerns about the potential consequences for organizations relying on shared cloud infrastructure. IDC Frontier has been contacting affected customers individually and providing assistance while investigating the attack.
Separately, Japanese seafood company Nissui reported that its logistics subsidiary experienced a system outage following suspected unauthorized access to a third-party data center. The disruption prevented some goods from being received or shipped, although no connection to the IDCF Cloud attack has been established.
IDC Frontier is continuing to investigate how the attackers entered its systems, whether customer information was compromised, and what steps are necessary to restore normal operations.
As of October 8, the company had not announced a complete recovery timeline, and the full extent of the ransomware attack remained unclear.
