The attack “impacts 495 companies and local governments” that used the service, and the threat actor posted screenshots claiming it encrypted 225 databases totaling 3.6 PB of data, reached 239 hypervisors, sealed 16,000 VM disks and wiped 554,153 snapshots.
What happened — timeline and immediate actions by IDC Frontier
IDC Frontier disclosed that its IDCF Cloud infrastructure-as-a-service platform was hit by a ransomware attack that began on October 7 at 3:40 AM local time and forced an immediate shutdown of the network and systems serving its East Japan Region 1 cluster. The company said it isolated and shut down impacted systems in that region to prevent further compromise, and that it is “continuing to investigate the precise cause and the scope of the impact.”
IDC Frontier also proactively disabled customer access to management consoles for all regions while it verifies their security, and said it will restore access only after confirming it is safe to do so. The firm said it is working to identify and block the intrusion route and to check security in other regions.
Scale of the claimant’s damage and the evidence shown to customers
Screenshots captured by customers before they were locked out showed a message from the threat actor claiming the intruder took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure. The posted claims specify substantial technical effects: 225 encrypted databases corresponding to 3.6 petabytes of data, access to 239 hypervisors, 16,000 virtual-machine disks sealed, and 554,153 snapshots wiped.
IDC Frontier has not published a detailed, independently verified inventory of customer data losses in its announcement; its public statements so far describe containment steps and an ongoing investigation into the scope of the impact.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleIDCF Cloud, IDC Frontier, and the customer footprint
IDCF Cloud is operated by IDC Frontier, a subsidiary of SoftBank Group, and provides virtual servers, storage, and networking that customers use to run websites, applications, and business systems in Japanese data centers. IDC Frontier said the outage in “East Japan Region 1” affects 495 companies and local governments that used the cloud service.
The company has emphasized region-level containment and cross-region verification; customers remain locked out of management consoles across all regions until IDC Frontier confirms those consoles are secure.
Nissui Logistics outage and the question of a link
Separately, Nissui Corporation — a Japanese seafood and food group with about 11,500 employees — said its logistics subsidiary, Nissui Logistics, suffered a system outage yesterday caused by suspected unauthorized access to a third‑party data center the subsidiary uses. Nissui reported that goods are not being shipped or received and that it is investigating whether personal information or customer data was leaked.
It is unclear whether the Nissui Logistics outage is connected to the attack on IDCF Cloud; the published accounts state only the coincidence of timing and the ongoing investigations by both companies.
Analysis from Macnica and shifting attacker behavior
Macnica researcher Yutaka Sejiyama told BleepingComputer that several major Japanese companies have been targeted recently. Macnica recorded 119 cybersecurity incidents involving personal information theft or exposed data since the start of the year, with 83 occurring between July 1 and October 6; by comparison, the firm logged 84 incidents in 2025 and 62 in 2024 using the same criteria.
Macnica’s analysis, as recounted by Sejiyama, indicates attackers are probing websites and APIs for access-control, configuration, and authentication weaknesses and are exploiting known (n‑day) vulnerabilities. Sejiyama said that finding weaknesses specific to individual websites traditionally required considerable time and effort, and suggested the rise of capable, inexpensive AI tools may be changing the economics and speed of such broad, detailed exploration.
What this means for technologists, local governments, and affected enterprises
- Technologists and security teams: IDC Frontier’s containment step — isolating East Japan Region 1 and disabling management consoles across regions — shows a focus on limiting lateral spread; teams will watch for the company’s findings on the intrusion route and any indicators of compromise released as part of the investigation.
- Local governments and enterprises that used IDCF Cloud: Nearly 500 organizations are directly implicated by IDC Frontier’s statement; those customers are likely to prioritize restoration of critical services, assessment of data integrity, and confirmation of console access safety before resuming normal operations.
- Supply-chain dependent companies (example: Nissui Logistics): Businesses relying on third‑party data centers or cloud hosts will be monitoring for cascading operational impacts and for any confirmation of shared infrastructure compromise connecting separate outages.
IDC Frontier’s public account centers on containment and an unfolding inquiry: the firm says it is continuing to investigate the precise cause and scope of the impact, and it has promised to restore management-console access only after it confirms security. The immediate technical claims by the attacker — seven minutes to breach and large counts of encrypted or wiped objects — raise hard questions for customers and investigators that the company’s coming forensic findings will need to answer.
Source: BleepingComputer — Ransomware attack disrupts Japan's IDCF Cloud used by govt clients




