# Ransomware Attack Disrupts Japan's IDCF Cloud (IDC Frontier) East Japan Region 1, Impacting 495 Government and Enterprise Clients

> On 2026-10-07 at approximately 3:40 AM JST, a ransomware attack by an unidentified third party took down four zones of IDC Frontier's IDCF Cloud IaaS in East Japan Region 1 (Shirakawa, Fukushima), affecting 495 companies and local governments. IDC Frontier states customer data in the four zones is expected to be difficult or impossible to extract or restore, and suspended management consoles in all regions pending security verification.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T11:57:29.416Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3065
- **ID:** TL-2026-3065
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)

## Description

IDC Frontier, a SoftBank Group subsidiary, operates the IDCF Cloud IaaS from data centers in Shirakawa, Fukushima Prefecture (East Japan Regions 1-3). At approximately 3:40 AM JST on 2026-10-07 customers began reporting outages in East Japan Region 1. IDC Frontier's first statement (about 1:52 PM JST, 2026-10-07) acknowledged unauthorized access by a third party to some systems. Its second report (about 8:39 PM JST) formally identified the cause as a ransomware attack by a third party, stated that East Japan Region 1 had been disconnected from the network and its systems shut down, that intrusion-route identification and blocking was under way, and that management-console access for customers in all regions was temporarily suspended while the security of other regions was verified.

The third report (2026-10-08, about 9:02 PM JST) stated that in four East Japan Region 1 zones (tesla, henry, pascal, joule) extraction and restoration of customer data is expected to be difficult, that virtual servers in those zones remain stopped and cannot be restarted, and that customers should build a safe separate environment and rebuild from their own backups. IDC Frontier supplied a six-step recovery procedure (identify affected environments, confirm off-zone backup sources, prepare a secure rebuild environment, inspect backups for malware or tampering, validate data consistency, coordinate manual operations and communications) and continues to investigate the intrusion vector with external security specialists.

An English-language message was reportedly displayed in the Region 1 management console and an image circulated on social media on 2026-10-07. Per BleepingComputer, the message claims the breach took seven minutes, 225 databases (3.6 PB) encrypted, 239 hypervisors reached, about 16,000 VM disks sealed and 554,153 snapshots wiped. A Japanese security outlet (Security Measures Lab) transcribing the image reports headline text 'IDCF CLOUD INFRASTRUCTURE SEIZED' / 'YOUR CLOUD IS OURS', 16,600+ VM disks, and 41.5 PB of backup capacity lost, with VMware (vCenter/ESXi) referenced in the image. These figures are actor claims; IDC Frontier said it was aware of the statement and investigating its authenticity, and has not confirmed encryption scope, backup destruction or data exfiltration. If the claims are accurate, the activity is consistent with hypervisor-level ransomware with deliberate destruction of snapshots and backups to prevent recovery, executed from the management plane.

Downstream impact is broad: reported affected services include Six Apart's Movable Type Cloud (31 servers reported unrecoverable), Greenwich e-commerce tools, MediaLink telephony services, UD Talk, Hoover Brain, Mackerel integrations, Do-Regi DNS/domain services (temporary DNS issues), Fibergate, Poppins Group, JRA-VAN, and websites of Ibaraki Prefecture, Kodaira City and, unconfirmed, the Ibaraki Prefectural Police. Separately, Nissui Corporation reported an outage at its logistics subsidiary due to suspected unauthorized third-party access to a data center; no link to IDCF has been established. No ransomware family, threat actor, initial access vector, CVE or network IOCs have been publicly disclosed as of 2026-10-09; the corresponding fields are left Unknown rather than inferred.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1578 Modify Cloud Compute Infrastructure
- T1485 Data Destruction
- T1490 Inhibit System Recovery
- T1489 Service Stop
- T1486 Data Encrypted for Impact

## Sources

- [Ransomware attack disrupts Japan's IDCF Cloud used by govt clients](https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/)
- [IDC Frontier - 2nd Report Unauthorized access to some of our systems](https://www.idcf.jp/news/topics/20261007002)
- [IDCFクラウドへの不正アクセス、ランサムウェア攻撃と明らかに 運営会社が回答 - ITmedia NEWS](https://www.itmedia.co.jp/news/article/2610/07/2000002106/)
- [IDCFクラウドに不正アクセス、東日本第1リージョンで障害 - Security Measures Lab](https://rocket-boys.co.jp/security-measures-lab/idcf-cloud-unauthorized-access-east-japan-region1/)
- [IDCFクラウド、4ゾーンの顧客情報「取り出し・復元困難」 (third report) - Security Measures Lab](https://rocket-boys.co.jp/security-measures-lab/idcf_cloud_data_recovery_policy_official_third_report/)
- [IDCFクラウドへのランサムウェア攻撃についてまとめてみた - piyolog](https://piyolog.hatenadiary.jp/entry/2026/10/08/070606)
- [IDCフロンティアにランサムウェア攻撃、IDCFクラウドで障害 - Mynavi TECH+](https://news.mynavi.jp/techplus/article/20261008-5095937/)
- [IDCF Cloud Outage: What Exactly Went Down? Affected Companies and Services - Offtrack Notes](https://note.com/offtrack_notes/n/na9f1b1880b45)
- [IDCF Cloud Ransomware Attack Hits 495 Clients, ITmedia Reports - News Directory 3](https://www.newsdirectory3.com/idcf-cloud-ransomware-attack-hits-495-clients-itmedia-reports/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3065
