TOKYO –
A series of cyberattacks has disrupted business operations and exposed millions of customer records across Japan, with a ransomware attack on a cloud service provider affecting 495 companies and local governments nationwide, while convenience store operator Lawson has disclosed a separate breach involving more than 2.15 million personal information records.
The disruption has extended into Japan’s food distribution network, raising concerns about shortages of popular frozen foods at supermarkets and restaurants.
At a supermarket in Saitama Prefecture, staff reported difficulties securing supplies of frozen food products manufactured by Nichirei Foods. The company announced on October 8 that a system failure at a logistics service provider had prevented shipments and deliveries of frozen foods.
According to Nichirei, logistics operations at distribution centers nationwide have been suspended, affecting approximately 1,200 businesses, including retailers, restaurant operators and food wholesalers.
A supermarket employee said the store had received repeated notices explaining that shipments remained suspended because of the system failure. Products affected included frozen yakisoba noodles, takoyaki, chicken rice, katsudon and katsu curry.
The disruption was linked to a cyberattack against IDC Frontier, a subsidiary of SoftBank Group that provides cloud computing and data center services.
IDC Frontier announced on October 8 that its systems had been compromised by ransomware, a form of malicious software that encrypts data or otherwise disrupts computer operations while demanding payment to restore access.
The attack has affected 495 companies and local governments using the provider’s cloud services. Among the disruptions, official websites operated by Ibaraki Prefecture and Kodaira City in Tokyo became inaccessible.
The incident illustrates how an attack on a single technology provider can spread across unrelated industries and public services, particularly when organizations depend on shared cloud infrastructure for essential operations.
Separately, Lawson announced on October 9 that unauthorized access by a third party had resulted in the exposure of personal information belonging to customers registered with its Lawson ID membership service.
The breach involved 2,155,345 records, representing approximately 10% of Lawson ID members, as well as 26 additional records associated with an application. The information included names, addresses and telephone numbers.
The convenience store operator’s disclosure adds to growing concerns about the vulnerability of customer databases maintained by major Japanese retailers and service companies.
Another major breach was disclosed on October 9 by Daiichikosho, the operator of the Big Echo karaoke chain, which said approximately 8.724 million personal information records may have been compromised.
The potentially exposed information included customer telephone numbers and other personal details.
According to the company, the incident originated from a cyberattack targeting a device used by an employee of an outside contractor entrusted with handling personal information.
The breach highlights the security risks associated with outsourcing customer data management, as vulnerabilities at contractors and other third-party service providers can expose information held by major corporations.
A man registered as a Big Echo member expressed concern that information he had routinely provided to businesses could now be accessible to unknown parties.
He said he had previously supplied personal details without much consideration but would need to be more careful in the future. Cyberattacks he had regarded as distant problems now felt personally relevant, he added, particularly because he regularly registered information through smartphone applications.
The succession of incidents comes as international ransomware operations face increasing scrutiny from law enforcement authorities.
One group attracting attention is Qilin, an international ransomware organization suspected of targeting companies and institutions around the world.
A Russian national identified as a member of the group was detained in Osaka in May 2026 and subsequently transferred to German authorities, who had been investigating the organization’s activities.
German investigators described the arrest as a significant development in their efforts to dismantle the ransomware operation.
“We arrested one of the key figures,” a German official said, adding that the suspect had expected to enjoy a vacation in Japan but was instead eating bread and cheese in a German prison rather than sushi.
According to German authorities, the group had demanded approximately 450 billion yen in ransom payments over the past four years, of which more than 6.3 billion yen had actually been paid.
Authorities estimated that approximately 4,000 companies and organizations worldwide had been targeted.
In a statement obtained on October 8, German authorities also raised concerns about Japan’s cybersecurity preparedness, describing the country as one of the most vulnerable in the world in terms of computer security.
The warning comes as Japanese companies increasingly depend on interconnected digital systems, creating the possibility that attacks against technology providers, logistics contractors and data management companies can have consequences far beyond the original targets.
In response to the growing number of incidents, the Japanese government announced at an interministerial meeting on October 9 that it would request stronger cybersecurity measures from business operators.
The latest breaches have nevertheless raised questions about whether conventional defensive measures are sufficient, particularly as attackers increasingly exploit weaknesses in systems operated by outside service providers.
Cybersecurity discussions are also shifting toward the amount of personal information companies collect and retain.
A digital policy adviser to the government suggested that personal data, traditionally regarded as a valuable corporate asset, is increasingly becoming a potential liability as the frequency and scale of breaches grow.
Rather than relying exclusively on preventing unauthorized access, companies should assume that their security systems may eventually be penetrated and reconsider how much personal information they need to retain.
One approach is to reduce the amount of customer data stored by individual businesses while maintaining reliable methods of identity verification.
Japan’s Digital Agency has introduced a digital authentication service that enables identity verification through smartphones and My Number cards.
The system allows businesses to confirm information such as a customer’s identity or age without necessarily collecting and retaining large volumes of personal data for extended periods.
For example, financial institutions must verify a customer’s identity when opening a bank account, but digital authentication can provide a means of completing that process without requiring every business to maintain extensive customer databases.
The Digital Agency provides the authentication infrastructure rather than centrally accumulating vast quantities of customer information, with the service functioning more like a shared public utility or payment network.
By allowing businesses to verify specific information when required, the technology could reduce the need to hold personal records for long periods and limit the potential damage caused by future breaches.
The latest incidents underscore the growing economic consequences of cybercrime in Japan, where attacks are no longer confined to information technology departments but can interrupt food supplies, disable government websites and expose the personal records of millions of consumers.
As companies and municipalities strengthen their defenses, the challenge is increasingly not only how to prevent cyberattacks, but also how to maintain essential services and minimize the information exposed when security systems fail.
Source: TBS
Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: newsonjapan.com










