Threat reportRansomwareTL-2026-3065
Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) East Japan Region 1, Impacting 495 Government and Enterprise Clients
Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) (TL-2026-3065), also tracked as IDCF Cloud ransomware incident, is a high-severity ransomware operation, first published 2026-10-09. It has no confirmed attribution, affects IDC Frontier (SoftBank Group) IDCF Cloud (IaaS), East Japan Region 1, maps to 6 MITRE ATT&CK techniques (T1078, T1485, T1486), and is covered by 9 detection rules and 10 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-3065
- Threat ID
- TL-2026-3065
- Also known as
- IDCF Cloud ransomware incident, IDC Frontier East Japan Region 1 outage
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- cloud-services, government administration, telecoms, ecommerce, health, education, media-entertainment
- Target regions
- japan
- Detection rules
- 9
- Indicators of compromise
- 10
- Updates
- 2026-10-09 · revalidated 1× · latest source
How Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) works
On 2026-10-07 at approximately 3:40 AM JST, a ransomware attack by an unidentified third party took down four zones of IDC Frontier's IDCF Cloud IaaS in East Japan Region 1 (Shirakawa, Fukushima), affecting 495 companies and local governments. IDC Frontier states customer data in the four zones is expected to be difficult or impossible to extract or restore, and suspended management consoles in all regions pending security verification.
IDC Frontier, a SoftBank Group subsidiary, operates the IDCF Cloud IaaS from data centers in Shirakawa, Fukushima Prefecture (East Japan Regions 1-3). At approximately 3:40 AM JST on 2026-10-07 customers began reporting outages in East Japan Region 1. IDC Frontier's first statement (about 1:52 PM JST, 2026-10-07) acknowledged unauthorized access by a third party to some systems. Its second report (about 8:39 PM JST) formally identified the cause as a ransomware attack by a third party, stated that East Japan Region 1 had been disconnected from the network and its systems shut down, that intrusion-route identification and blocking was under way, and that management-console access for customers in all regions was temporarily suspended while the security of other regions was verified.
The third report (2026-10-08, about 9:02 PM JST) stated that in four East Japan Region 1 zones (tesla, henry, pascal, joule) extraction and restoration of customer data is expected to be difficult, that virtual servers in those zones remain stopped and cannot be restarted, and that customers should build a safe separate environment and rebuild from their own backups. IDC Frontier supplied a six-step recovery procedure (identify affected environments, confirm off-zone backup sources, prepare a secure rebuild environment, inspect backups for malware or tampering, validate data consistency, coordinate manual operations and communications) and continues to investigate the intrusion vector with external security specialists.
An English-language message was reportedly displayed in the Region 1 management console and an image circulated on social media on 2026-10-07. Per BleepingComputer, the message claims the breach took seven minutes, 225 databases (3.6 PB) encrypted, 239 hypervisors reached, about 16,000 VM disks sealed and 554,153 snapshots wiped. A Japanese security outlet (Security Measures Lab) transcribing the image reports headline text 'IDCF CLOUD INFRASTRUCTURE SEIZED' / 'YOUR CLOUD IS OURS', 16,600+ VM disks, and 41.5 PB of backup capacity lost, with VMware (vCenter/ESXi) referenced in the image. These figures are actor claims; IDC Frontier said it was aware of the statement and investigating its authenticity, and has not confirmed encryption scope, backup destruction or data exfiltration. If the claims are accurate, the activity is consistent with hypervisor-level ransomware with deliberate destruction of snapshots and backups to prevent recovery, executed from the management plane.
Downstream impact is broad: reported affected services include Six Apart's Movable Type Cloud (31 servers reported unrecoverable), Greenwich e-commerce tools, MediaLink telephony services, UD Talk, Hoover Brain, Mackerel integrations, Do-Regi DNS/domain services (temporary DNS issues), Fibergate, Poppins Group, JRA-VAN, and websites of Ibaraki Prefecture, Kodaira City and, unconfirmed, the Ibaraki Prefectural Police. Separately, Nissui Corporation reported an outage at its logistics subsidiary due to suspected unauthorized third-party access to a data center; no link to IDCF has been established. No ransomware family, threat actor, initial access vector, CVE or network IOCs have been publicly disclosed as of 2026-10-09; the corresponding fields are left Unknown rather than inferred.
MITRE ATT&CK techniques used in TL-2026-3065
Initial Access
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
defense-impairment
Affected products and versions in Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)
- IDC Frontier (SoftBank Group) — IDCF Cloud (IaaS), East Japan Region 1
Vulnerable versions: East Japan Region 1 zones: tesla, henry, pascal, joule - VMware — vCenter / ESXi (referenced in the actor's message image; not confirmed by IDC Frontier)
Remediation for Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)
Immediate actions
- IDCF Cloud customers: do not attempt to reuse the stopped tesla, henry, pascal and joule zones; prepare a safe separate environment and rebuild from backups held outside the affected zones
- Inspect backups for malware or tampering and validate data consistency before and after restoration
- Rotate credentials, API keys, TLS private keys and secrets that were stored on or accessible from IDCF-hosted VMs
- Review DNS, mail and authentication dependencies on IDCF-hosted services (e.g. Do-Regi, Fibergate) and fail over where possible
- Contact IDC Frontier through its customer contact form; affected customers are being contacted individually
Workarounds
- IDC Frontier provides manual server operation support on request while management consoles are suspended in unaffected regions
Longer-term hardening
- Keep immutable, offline or cross-provider backups that are not reachable from the same cloud management plane
- Avoid single-region dependency; design multi-region or multi-provider recovery for critical and public-sector services
- Enforce MFA, privileged access management and network isolation for hypervisor and cloud management interfaces
- Monitor management-plane activity for mass snapshot deletion, bulk VM power-off and datastore changes
- Include cloud-provider outage and ransomware scenarios in BCP and incident-response exercises
Timeline of Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)
- Do-Regi DNS resolution issues are reported in the evening and resolved by about 8:15 PM.
- IDC Frontier's second report (about 8:39 PM JST) identifies a third-party ransomware attack affecting 495 companies and local governments; Region 1 is network-isolated and shut down, and management consoles are disabled in all regions pending safety verification.
- IDC Frontier issues its first statement (about 1:52 PM JST) confirming unauthorized access by a third party to some systems in East Japan Region 1.
- Customers (e.g. Kyoto Sanga F.C. at 7:54 AM, UD Talk at 9:32 AM) publish service-disruption notices; an image of an English-language attacker message in the management console circulates on social media.
- At approximately 3:40 AM JST an attack begins on IDCF Cloud East Japan Region 1 (Shirakawa, Fukushima); customer services such as JRA-VAN and MediaLink report outages. The actor's message claims the breach took seven minutes.
- BleepingComputer publishes its report relaying the actor's claims (225 databases, 239 hypervisors, ~16,000 VM disks, 554,153 snapshots) and the concurrent, unlinked Nissui Logistics outage.
- IDC Frontier's third report (about 9:02 PM JST) states extraction and restoration of customer data in the tesla, henry, pascal and joule zones is expected to be difficult, and advises customers to rebuild in a separate environment from their own backups.
- Six Apart reports at about 9:00 AM that data on 31 Movable Type Cloud servers in the East Japan region cannot be recovered.
- Follow-up reporting notes no unauthorized access confirmed in other IDCF regions and no leak-site posting identified; attribution, ransomware family, initial access vector and exfiltration remain unconfirmed.
Update history for TL-2026-3065
- 2026-10-09 — Ransomware Attack on SoftBank Subsidiary IDC Frontier Disrupts IDCF Cloud East Japan Region 1, Affecting 495 Japanese Local Governments and Companies: What changed No field escalations. Existing severity HIGH, exploitability ACTIVE and status ACTIVE are unchanged. The newer report's impact value (HIGH) is lower than the existing CRITICAL and is ignored. New indicators (3) 3 new entity ind
Sources cited for Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)
- Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
- IDC Frontier - [2nd Report] Unauthorized access to some of our systems
- IDCFクラウドへの不正アクセス、ランサムウェア攻撃と明らかに 運営会社が回答 - ITmedia NEWS
- IDCFクラウドに不正アクセス、東日本第1リージョンで障害 - Security Measures Lab
- IDCFクラウド、4ゾーンの顧客情報「取り出し・復元困難」 (third report) - Security Measures Lab
- IDCFクラウドへのランサムウェア攻撃についてまとめてみた - piyolog
- IDCフロンティアにランサムウェア攻撃、IDCFクラウドで障害 - Mynavi TECH+
- IDCF Cloud Outage: What Exactly Went Down? Affected Companies and Services - Offtrack Notes
- IDCF Cloud Ransomware Attack Hits 495 Clients, ITmedia Reports - News Directory 3
Detection coverage for TL-2026-3065
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3065 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.