Threat reportRansomwareTL-2026-3065

Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) East Japan Region 1, Impacting 495 Government and Enterprise Clients

highACTIVE

Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) (TL-2026-3065), also tracked as IDCF Cloud ransomware incident, is a high-severity ransomware operation, first published 2026-10-09. It has no confirmed attribution, affects IDC Frontier (SoftBank Group) IDCF Cloud (IaaS), East Japan Region 1, maps to 6 MITRE ATT&CK techniques (T1078, T1485, T1486), and is covered by 9 detection rules and 10 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-3065

Threat ID
TL-2026-3065
Also known as
IDCF Cloud ransomware incident, IDC Frontier East Japan Region 1 outage
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
cloud-services, government administration, telecoms, ecommerce, health, education, media-entertainment
Target regions
japan
Detection rules
9
Indicators of compromise
10
Updates
2026-10-09 · revalidated 1× · latest source

How Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) works

On 2026-10-07 at approximately 3:40 AM JST, a ransomware attack by an unidentified third party took down four zones of IDC Frontier's IDCF Cloud IaaS in East Japan Region 1 (Shirakawa, Fukushima), affecting 495 companies and local governments. IDC Frontier states customer data in the four zones is expected to be difficult or impossible to extract or restore, and suspended management consoles in all regions pending security verification.

IDC Frontier, a SoftBank Group subsidiary, operates the IDCF Cloud IaaS from data centers in Shirakawa, Fukushima Prefecture (East Japan Regions 1-3). At approximately 3:40 AM JST on 2026-10-07 customers began reporting outages in East Japan Region 1. IDC Frontier's first statement (about 1:52 PM JST, 2026-10-07) acknowledged unauthorized access by a third party to some systems. Its second report (about 8:39 PM JST) formally identified the cause as a ransomware attack by a third party, stated that East Japan Region 1 had been disconnected from the network and its systems shut down, that intrusion-route identification and blocking was under way, and that management-console access for customers in all regions was temporarily suspended while the security of other regions was verified.

The third report (2026-10-08, about 9:02 PM JST) stated that in four East Japan Region 1 zones (tesla, henry, pascal, joule) extraction and restoration of customer data is expected to be difficult, that virtual servers in those zones remain stopped and cannot be restarted, and that customers should build a safe separate environment and rebuild from their own backups. IDC Frontier supplied a six-step recovery procedure (identify affected environments, confirm off-zone backup sources, prepare a secure rebuild environment, inspect backups for malware or tampering, validate data consistency, coordinate manual operations and communications) and continues to investigate the intrusion vector with external security specialists.

An English-language message was reportedly displayed in the Region 1 management console and an image circulated on social media on 2026-10-07. Per BleepingComputer, the message claims the breach took seven minutes, 225 databases (3.6 PB) encrypted, 239 hypervisors reached, about 16,000 VM disks sealed and 554,153 snapshots wiped. A Japanese security outlet (Security Measures Lab) transcribing the image reports headline text 'IDCF CLOUD INFRASTRUCTURE SEIZED' / 'YOUR CLOUD IS OURS', 16,600+ VM disks, and 41.5 PB of backup capacity lost, with VMware (vCenter/ESXi) referenced in the image. These figures are actor claims; IDC Frontier said it was aware of the statement and investigating its authenticity, and has not confirmed encryption scope, backup destruction or data exfiltration. If the claims are accurate, the activity is consistent with hypervisor-level ransomware with deliberate destruction of snapshots and backups to prevent recovery, executed from the management plane.

Downstream impact is broad: reported affected services include Six Apart's Movable Type Cloud (31 servers reported unrecoverable), Greenwich e-commerce tools, MediaLink telephony services, UD Talk, Hoover Brain, Mackerel integrations, Do-Regi DNS/domain services (temporary DNS issues), Fibergate, Poppins Group, JRA-VAN, and websites of Ibaraki Prefecture, Kodaira City and, unconfirmed, the Ibaraki Prefectural Police. Separately, Nissui Corporation reported an outage at its logistics subsidiary due to suspected unauthorized third-party access to a data center; no link to IDCF has been established. No ransomware family, threat actor, initial access vector, CVE or network IOCs have been publicly disclosed as of 2026-10-09; the corresponding fields are left Unknown rather than inferred.

MITRE ATT&CK techniques used in TL-2026-3065

Initial Access

T1078 Valid Accounts

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

defense-impairment

T1578 Modify Cloud Compute Infrastructure

Affected products and versions in Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)

  • IDC Frontier (SoftBank Group) — IDCF Cloud (IaaS), East Japan Region 1
    Vulnerable versions: East Japan Region 1 zones: tesla, henry, pascal, joule
  • VMware — vCenter / ESXi (referenced in the actor's message image; not confirmed by IDC Frontier)

Remediation for Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)

Immediate actions

  • IDCF Cloud customers: do not attempt to reuse the stopped tesla, henry, pascal and joule zones; prepare a safe separate environment and rebuild from backups held outside the affected zones
  • Inspect backups for malware or tampering and validate data consistency before and after restoration
  • Rotate credentials, API keys, TLS private keys and secrets that were stored on or accessible from IDCF-hosted VMs
  • Review DNS, mail and authentication dependencies on IDCF-hosted services (e.g. Do-Regi, Fibergate) and fail over where possible
  • Contact IDC Frontier through its customer contact form; affected customers are being contacted individually

Workarounds

  • IDC Frontier provides manual server operation support on request while management consoles are suspended in unaffected regions

Longer-term hardening

  • Keep immutable, offline or cross-provider backups that are not reachable from the same cloud management plane
  • Avoid single-region dependency; design multi-region or multi-provider recovery for critical and public-sector services
  • Enforce MFA, privileged access management and network isolation for hypervisor and cloud management interfaces
  • Monitor management-plane activity for mass snapshot deletion, bulk VM power-off and datastore changes
  • Include cloud-provider outage and ransomware scenarios in BCP and incident-response exercises

Timeline of Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)

  • Do-Regi DNS resolution issues are reported in the evening and resolved by about 8:15 PM.
  • IDC Frontier's second report (about 8:39 PM JST) identifies a third-party ransomware attack affecting 495 companies and local governments; Region 1 is network-isolated and shut down, and management consoles are disabled in all regions pending safety verification.
  • IDC Frontier issues its first statement (about 1:52 PM JST) confirming unauthorized access by a third party to some systems in East Japan Region 1.
  • Customers (e.g. Kyoto Sanga F.C. at 7:54 AM, UD Talk at 9:32 AM) publish service-disruption notices; an image of an English-language attacker message in the management console circulates on social media.
  • At approximately 3:40 AM JST an attack begins on IDCF Cloud East Japan Region 1 (Shirakawa, Fukushima); customer services such as JRA-VAN and MediaLink report outages. The actor's message claims the breach took seven minutes.
  • BleepingComputer publishes its report relaying the actor's claims (225 databases, 239 hypervisors, ~16,000 VM disks, 554,153 snapshots) and the concurrent, unlinked Nissui Logistics outage.
  • IDC Frontier's third report (about 9:02 PM JST) states extraction and restoration of customer data in the tesla, henry, pascal and joule zones is expected to be difficult, and advises customers to rebuild in a separate environment from their own backups.
  • Six Apart reports at about 9:00 AM that data on 31 Movable Type Cloud servers in the East Japan region cannot be recovered.
  • Follow-up reporting notes no unauthorized access confirmed in other IDCF regions and no leak-site posting identified; attribution, ransomware family, initial access vector and exfiltration remain unconfirmed.

Update history for TL-2026-3065

Sources cited for Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier)

Detection coverage for TL-2026-3065

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3065 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats