IDC Frontier ransomware: SoftBank's cloud arm halts 495 customers, data may be unrecoverable
A ransomware attack on IDC Frontier, SoftBank's cloud and data center subsidiary, knocked out East Japan Region 1 of its IDCF Cloud from 3:40 a.m. Japan time on October 7, 2026, affecting 495 corporate and municipal customers. Virtual servers in four availability zones stopped and would not restart, and the company told customers that recovering data from the affected infrastructure would be difficult and that they should 'prepare a separate environment and rebuild.' The attacker claims a seven-minute breach of about 240 hypervisors, 225 encrypted datastores and more than 554,000 deleted snapshots; IDC Frontier has not confirmed those numbers. SoftBank's telecom services were not affected.
The three lines
- Damage — East Japan Region 1 down since Oct. 7; 495 corporate and municipal customers; VMs won't restart
- Recovery — company says data restoration is difficult and advises rebuilding; consoles locked in all regions
- Attacker claims — seven minutes, ~240 hypervisors, 554,000+ snapshots deleted; unconfirmed
Key questions
- IDC Frontier ransomware attack
- **An entire region of a SoftBank subsidiary's cloud went down.** | Item | Detail | |---|---| | Company | IDC Frontier (SoftBank subsidiary) | | Service | IDCF Cloud East Japan Region 1 (Shirakawa, Fukushima) | | Start | 3:40 a.m. JST, October 7, 2026 | | Impact | 495 corporate and municipal customers | | Status | VMs in four zones can't restart; consoles locked in all regions |
- IDCF Cloud data recovery
- **The company says restoring from the affected infrastructure will be difficult.** | Item | Detail | |---|---| | Guidance | 'Prepare a separate environment and rebuild your system' | | Method | Manual VM restoration per customer request (console down) | | Customer backups | Restore from your own backups if you have them | | Timeline | Consoles to reopen region by region; no date |
- IDC Frontier affected companies
- **Only some victims have been named.** | Company | Impact | |---|---| | Fibergate | Wi-Fi authentication outage | | Medialink | Cloud telephony and IP-PBX offline | | Others | Public bodies; logistics, education and finance firms | | Nissui Logistics | Shipping halted after unauthorized data center access — link to IDCF unconfirmed |
One cloud region stopped, and 495 companies and local governments across Japan stopped with it. Then the provider said it might not be able to give the data back. IDC Frontier, SoftBank's cloud and data center subsidiary, says East Japan Region 1 of its IDCF Cloud stopped responding at 3:40 a.m. Japan time on October 7, 2026, and confirmed a third-party ransomware attack. Virtual servers in four availability zones went down and would not restart. The next day the company told customers that recovering data from the affected infrastructure would be difficult and that they should "prepare a separate environment and rebuild your system." That implies the attack hit not individual servers but the virtualization layer beneath them.
1. Timeline
| Time (JST) | Event |
|---|---|
| Oct. 7, 3:40 a.m. | East Japan Region 1 (Shirakawa data center, Fukushima) stops responding |
| Oct. 7 | Ransomware confirmed; region isolated; VMs in four zones won't restart |
| Oct. 7 onward | Customer management consoles disabled in all regions pending checks |
| Oct. 8 | Customer notice: restoration difficult, rebuild advised |
| Now | Emergency HQ set up; SoftBank supporting; VMs restored manually per request |
IDC Frontier says it is "continuing to investigate the precise cause and the scope of the impact." SoftBank's telecom services appear unaffected. Consoles will reopen region by region once cleared; no date has been given.
2. What the company confirmed vs. what the attacker claims
| Confirmed by IDC Frontier | Attacker's claim (unverified) | |
|---|---|---|
| Customers | 495 corporate and municipal | — |
| Scope | East Japan Region 1, four zones | About 240 hypervisors |
| Time | — | Seven minutes to breach the management plane |
| Data | Hard to restore from affected infrastructure | 225 datastores encrypted, 16,000 virtual disks sealed |
| Backups | Restore from your own backups | 554,000+ snapshots deleted, 41.5 PB of backups removed |
The attacker left an English-language message on the console. Named victims include Fibergate, whose Wi-Fi authentication failed, and Medialink, whose cloud telephony and IP-PBX went offline; public bodies and logistics, education and finance firms were also hit. A logistics subsidiary of seafood group Nissui halted shipments the same week after unauthorized access to a third-party data center; whether that is the same incident is unconfirmed.
3. Why the hypervisor was the target
Thousands of cloud virtual machines run on hypervisors. Lock that layer instead of each server and you can stop every VM and its snapshots at once — the point of the attacker's "seven minutes" boast.
| Server-level attack | Virtualization-layer attack | |
|---|---|---|
| Scope per action | One server | Dozens to hundreds per host |
| Backups | May survive elsewhere | Same-layer snapshots can be wiped |
| Recovery | Reinstall the server | Rebuild from the foundation |
| Victims | One company | Every customer on that cloud |
Japanese security firm Macnica counts 119 personal-data theft or exposure incidents in Japan in 2026 through October 6 — already above all of 2025 (84) — with 83 since July. For the mechanics, see "What is hypervisor ransomware."
4. What remains unclear
- Data loss: how much customer data is permanently gone has not been disclosed.
- Entry point: how the attacker reached the management plane — stolen credentials or an unpatched flaw — is not public.
- Attacker and ransom: no group name or demand has been disclosed.
- Lesson: when public and private systems concentrate in one cloud region, one attack stops hundreds of organizations. The assumption that "it's in the cloud, so it's backed up" failed here; only backups kept outside that provider survive.
Sources
- SDxCentral — SoftBank national cloud arm attacked in 'seven minutes,' taking Japan infrastructure offline
- TechEchelon — Ransomware Attack on IDC Frontier's IDCF Cloud Disrupts 495 Companies and Government Clients in Japan
- DataBreaches.Net — Cyberattack at IDC Frontier disrupts services around nation
- The Japan Times — More Japanese firms hit by large-scale data breaches
- MLex — Japan cloud ransomware attack exposes municipal backup vulnerabilities