NEWS

Ransomware Attack Disrupts Japan's IDCF Cloud Used by Government Clients

A ransomware attack on SoftBank-owned IDC Frontier's IDCF Cloud knocked out Japan's East Japan Region 1, disrupting 495 companies and government clients.

Dylan H.

News Desk

October 8, 2026
7 min read
Ransomware Attack Disrupts Japan's IDCF Cloud Used by Government Clients

Ransomware Attack Knocks Out Japan's IDCF Cloud, Disrupting Government and Enterprise Clients

IDC Frontier, a cloud and data-center company owned by SoftBank Group, confirmed that its IDCF Cloud service was hit by a ransomware attack that began in the early hours of October 7, 2026, taking down the East Japan Region 1 data center cluster at the company's facility in Shirakawa, Fukushima Prefecture. The resulting outage disrupted 495 contracted companies and local governments, including the Ibaraki Prefecture government and the Ibaraki Prefectural Police, whose public-facing websites went offline alongside sites belonging to municipalities, J.League soccer clubs, and other organizations. IDC Frontier disabled management console access across all regions as a precaution while it investigates, and as of October 8, the company has not published a timeline for full recovery.


Incident Details

AttributeValue
TargetIDCF Cloud (IDC Frontier, a SoftBank Group subsidiary)
Attack typeRansomware / unauthorized third-party access
DetectedOctober 7, 2026, approximately 3:40 AM JST, via monitoring alerts
Affected clusterEast Japan Region 1, located at the Shirakawa, Fukushima Prefecture data center
Threat actorNot publicly named by IDC Frontier
Clients affected495 contracted companies and local governments
Notable public-sector victimsIbaraki Prefecture government, Ibaraki Prefectural Police
Attacker claims (unverified)225 databases encrypted; 3.6 petabytes of data affected; 239 hypervisors reached; 16,000 VM disks sealed; 554,153 snapshots wiped
Data exfiltrationUnconfirmed — IDC Frontier is investigating possible personal-data exposure
Recovery status (as of Oct 8)No restoration timeline published; management consoles disabled across all regions

How the Attack Unfolded

Early-Morning Detection and a Fast-Moving Shutdown

IDC Frontier's monitoring systems flagged anomalous activity in East Japan Region 1 at approximately 3:40 AM JST on October 7, when unauthorized third-party access was detected. Within roughly 20 minutes, servers at the affected data center lost power. By 8:00 AM, SoftBank had notified Ibaraki Prefecture of the disruption to its hosted services. IDC Frontier issued its first public report at 1:52 PM, describing the incident only as unauthorized access, before a second report at 8:18 PM confirmed it was a ransomware attack and disclosed that 495 contracted companies and local governments were affected. The company says it has since completed network isolation and system shutdown for the affected region and is now focused on identifying the intrusion vector.

A Single Facility With Outsized Reach

According to IDC Frontier's own published service specifications, East Japan Regions 1, 2, and 3 are all hosted out of the same Shirakawa, Fukushima data center, rather than being physically distributed across separate sites. That concentration meant a ransomware intrusion limited to one logical region carried a blast radius large enough to affect nearly 500 tenants at once, and prompted the company to proactively disable management-console access to its other regions nationwide while it verifies they were not also reached.

Attacker Claims of Mass Destruction

Screenshots circulated to IDCF Cloud customers and on social media, purportedly from the attackers, claimed it took only seven minutes to breach the East Japan Region 1 infrastructure, followed by encryption of 225 databases, destruction of more than 554,000 snapshots, and the sealing of 16,000 virtual machine disks across 239 hypervisors, totaling roughly 3.6 petabytes of affected data. IDC Frontier has acknowledged awareness of these claims but says it is still verifying their authenticity rather than confirming the figures independently. No ransomware group has publicly taken credit for the attack.

Collateral Impact Across Public and Private Sectors

Beyond Ibaraki Prefecture's government and police websites, reporting has linked the outage to inaccessible sites for Kodaira City, multiple J.League soccer clubs, Tobu Zoo, the Japan Basketball Association, Radio Kansai, hotel chain Anshin Oyado, and karaoke chain Karaoke Pasela — though not all of these organizations have explicitly confirmed IDCF Cloud as the underlying cause. Illustration-commissioning platform SKIMA initially said data recovery looked "extremely difficult" before later confirming salvageable data remained and that restoration work was underway, illustrating how recovery prospects have varied significantly by tenant.

Impact Assessment

Impact AreaDescription
Government servicesIbaraki Prefecture and its police force lost public-facing websites, disrupting citizen-facing services and public communications
Business continuity495 organizations across multiple sectors lost access to hosted infrastructure with no confirmed recovery date as of October 8
Data integrityUnverified attacker claims of mass database encryption and snapshot destruction, if accurate, could mean unrecoverable data for some tenants
Single-facility concentration riskEast Japan Regions 1-3 reportedly share one Fukushima facility, amplifying the blast radius of a single-region intrusion
Trust in enterprise cloud providersA SoftBank-affiliated, enterprise-grade cloud provider being disabled by ransomware raises scrutiny of resilience across Japan's cloud sector
Potential data exposureIDC Frontier has not ruled out personal-information leakage and is actively investigating

Recommendations

For IDCF Cloud Customers and Tenants

  • Treat all workloads hosted in East Japan Region 1 as potentially compromised until IDC Frontier confirms otherwise, and verify the status of resources in other regions independently
  • Activate offline or out-of-band backups and incident communication plans that do not depend on the affected management console
  • Review hosting contracts and SLAs for data-loss, breach-notification, and service-credit obligations
  • Rely on IDC Frontier's official advisories for confirmed scope and recovery timelines rather than attacker-sourced claims circulating on social media

For Cloud and IT Administrators More Broadly

  • Avoid concentrating production data and backup copies within a single physical data-center facility, even when a provider markets "multiple regions" — verify the underlying physical diversity
  • Maintain immutable, offline backups stored outside the primary cloud provider's control plane
  • Periodically test restoration from backups in a way that does not depend on the primary provider's management console remaining available

For Security Teams and Government IT Leads

  • Confirm independently whether your organization's tenant was among the 495 affected rather than relying solely on a vendor's self-reported scope
  • Update incident response plans to cover scenarios where a hosting or cloud provider itself is incapacitated, not just on-premises systems
  • Watch for secondary phishing or extortion attempts that exploit this incident's public visibility against affected government and enterprise clients

Key Takeaways

  1. A ransomware attack detected around 3:40 AM JST on October 7, 2026 disabled the East Japan Region 1 cluster of IDC Frontier's IDCF Cloud, a SoftBank Group subsidiary.
  2. 495 contracted companies and local governments were affected, including Ibaraki Prefecture's government and police websites.
  3. Attacker-supplied claims circulating among customers allege 225 encrypted databases, 3.6 petabytes of affected data, 239 compromised hypervisors, 16,000 sealed VM disks, and 554,153 wiped snapshots — none independently confirmed by IDC Frontier.
  4. No ransomware group has publicly claimed responsibility, and IDC Frontier has not confirmed whether personal data was exfiltrated.
  5. As of October 8, 2026, management console access remains disabled across all IDCF Cloud regions as a precaution, with no public recovery timeline.
  6. The incident has renewed scrutiny of single-facility region concentration — East Japan Regions 1-3 reportedly share one Fukushima data center — as a business-continuity risk for enterprise cloud customers.

Sources