IDC Frontier announced that the IDCF Cloud service was subjected to a ransomware attack that disrupted a data center serving eastern Japan, in an incident affecting 495 companies and local governments that use the cloud platform. According to the company, the attack began at 3:40 a.m. local time on October 7, 2026.
The incident led to the shutdown of the network and systems in the East Japan Region 1. IDC Frontier said its initial investigation concluded that the outage resulted from a ransomware attack carried out by a third party, but it is still verifying the precise cause and scope of the impact.
Systems Isolated and Management Dashboards Suspended
The company isolated and shut down the affected systems to prevent the breach from spreading to other parts of the infrastructure. It also proactively disabled customer access to the service’s management dashboards in all regions until security checks are completed, confirming that access will be restored after its safety has been verified.
IDCF Cloud provides virtual servers, storage, and networks that organizations rely on to operate websites, applications, and business systems within Japanese data centers. The platform is operated by IDC Frontier, a subsidiary of the SoftBank Group.
Attacker Claims and Extent of Damage Remain Unclear
Screenshots captured by some customers before they lost access to the management dashboards showed a message from the attacker claiming to have breached the infrastructure within seven minutes. The message also claimed to have encrypted 225 databases containing a total of 3.6 petabytes of data, accessed 239 virtual administrators, locked 16,000 disks for virtual machines, and erased 554,153 Snapshot copies.
These figures came from the attacking party and have not been confirmed by IDC Frontier. The company is working to identify and block the entry path, in addition to examining the other regions, so the final extent of the damage and the possibility of data loss remain unclear.
Separate Outage Affects Nissui
In a separate incident, Japanese marine-products company Nissui announced that its logistics arm, Nissui Logistics, experienced a systems outage caused by suspected unauthorized access through a third-party data center. The shipment and receipt of goods came to a halt, while the company investigated the possibility of personal information or customer data leakage.
There is currently no evidence proving a connection between the Nissui incident and the IDCF Cloud attack. This comes amid a notable rise in cyber incidents tracked by Macnica; it recorded 119 incidents involving the theft of personal information or data exposure since the beginning of 2026, including 83 incidents that occurred between July 1 and October 6, compared with 84 incidents during 2025 and 62 in 2024 under the same criteria.
Why Does This Matter?
The incident practically demonstrates the sensitivity of relying on a single cloud provider, as a breach of an operational region can disrupt the services of commercial organizations and government entities at the same time. Observations by researcher Yutaka Sejiyama of Macnica indicate that attackers target weaknesses in access privileges, configuration, and authentication, as well as known flaws in websites and APIs. He also believes that inexpensive and capable artificial intelligence tools could make broad vulnerability reconnaissance faster, but the source does not establish that artificial intelligence was specifically used in this attack.