Skip to content
TEN Brief Ten verified stories a day 2026.10.12 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 3 min read · Breaking

IDC Frontier ransomware: SoftBank's cloud arm halts 495 customers, data may be unrecoverable

A ransomware attack on IDC Frontier, SoftBank's cloud and data center subsidiary, knocked out East Japan Region 1 of its IDCF Cloud from 3:40 a.m. Japan time on October 7, 2026, affecting 495 corporate and municipal customers. Virtual servers in four availability zones stopped and would not restart, and the company told customers that recovering data from the affected infrastructure would be difficult and that they should 'prepare a separate environment and rebuild.' The attacker claims a seven-minute breach of about 240 hypervisors, 225 encrypted datastores and more than 554,000 deleted snapshots; IDC Frontier has not confirmed those numbers. SoftBank's telecom services were not affected.

An engineer seen from behind walking down a bright data center aisle

The three lines

  • Damage — East Japan Region 1 down since Oct. 7; 495 corporate and municipal customers; VMs won't restart
  • Recovery — company says data restoration is difficult and advises rebuilding; consoles locked in all regions
  • Attacker claims — seven minutes, ~240 hypervisors, 554,000+ snapshots deleted; unconfirmed

Key questions

IDC Frontier ransomware attack
**An entire region of a SoftBank subsidiary's cloud went down.** | Item | Detail | |---|---| | Company | IDC Frontier (SoftBank subsidiary) | | Service | IDCF Cloud East Japan Region 1 (Shirakawa, Fukushima) | | Start | 3:40 a.m. JST, October 7, 2026 | | Impact | 495 corporate and municipal customers | | Status | VMs in four zones can't restart; consoles locked in all regions |
IDCF Cloud data recovery
**The company says restoring from the affected infrastructure will be difficult.** | Item | Detail | |---|---| | Guidance | 'Prepare a separate environment and rebuild your system' | | Method | Manual VM restoration per customer request (console down) | | Customer backups | Restore from your own backups if you have them | | Timeline | Consoles to reopen region by region; no date |
IDC Frontier affected companies
**Only some victims have been named.** | Company | Impact | |---|---| | Fibergate | Wi-Fi authentication outage | | Medialink | Cloud telephony and IP-PBX offline | | Others | Public bodies; logistics, education and finance firms | | Nissui Logistics | Shipping halted after unauthorized data center access — link to IDCF unconfirmed |

One cloud region stopped, and 495 companies and local governments across Japan stopped with it. Then the provider said it might not be able to give the data back. IDC Frontier, SoftBank's cloud and data center subsidiary, says East Japan Region 1 of its IDCF Cloud stopped responding at 3:40 a.m. Japan time on October 7, 2026, and confirmed a third-party ransomware attack. Virtual servers in four availability zones went down and would not restart. The next day the company told customers that recovering data from the affected infrastructure would be difficult and that they should "prepare a separate environment and rebuild your system." That implies the attack hit not individual servers but the virtualization layer beneath them.

1. Timeline

Time (JST)Event
Oct. 7, 3:40 a.m.East Japan Region 1 (Shirakawa data center, Fukushima) stops responding
Oct. 7Ransomware confirmed; region isolated; VMs in four zones won't restart
Oct. 7 onwardCustomer management consoles disabled in all regions pending checks
Oct. 8Customer notice: restoration difficult, rebuild advised
NowEmergency HQ set up; SoftBank supporting; VMs restored manually per request

IDC Frontier says it is "continuing to investigate the precise cause and the scope of the impact." SoftBank's telecom services appear unaffected. Consoles will reopen region by region once cleared; no date has been given.

2. What the company confirmed vs. what the attacker claims

Confirmed by IDC FrontierAttacker's claim (unverified)
Customers495 corporate and municipal—
ScopeEast Japan Region 1, four zonesAbout 240 hypervisors
Time—Seven minutes to breach the management plane
DataHard to restore from affected infrastructure225 datastores encrypted, 16,000 virtual disks sealed
BackupsRestore from your own backups554,000+ snapshots deleted, 41.5 PB of backups removed

The attacker left an English-language message on the console. Named victims include Fibergate, whose Wi-Fi authentication failed, and Medialink, whose cloud telephony and IP-PBX went offline; public bodies and logistics, education and finance firms were also hit. A logistics subsidiary of seafood group Nissui halted shipments the same week after unauthorized access to a third-party data center; whether that is the same incident is unconfirmed.

3. Why the hypervisor was the target

Thousands of cloud virtual machines run on hypervisors. Lock that layer instead of each server and you can stop every VM and its snapshots at once — the point of the attacker's "seven minutes" boast.

Server-level attackVirtualization-layer attack
Scope per actionOne serverDozens to hundreds per host
BackupsMay survive elsewhereSame-layer snapshots can be wiped
RecoveryReinstall the serverRebuild from the foundation
VictimsOne companyEvery customer on that cloud

Japanese security firm Macnica counts 119 personal-data theft or exposure incidents in Japan in 2026 through October 6 — already above all of 2025 (84) — with 83 since July. For the mechanics, see "What is hypervisor ransomware."

4. What remains unclear

  • Data loss: how much customer data is permanently gone has not been disclosed.
  • Entry point: how the attacker reached the management plane — stolen credentials or an unpatched flaw — is not public.
  • Attacker and ransom: no group name or demand has been disclosed.
  • Lesson: when public and private systems concentrate in one cloud region, one attack stops hundreds of organizations. The assumption that "it's in the cloud, so it's backed up" failed here; only backups kept outside that provider survive.

Sources

  1. SDxCentral — SoftBank national cloud arm attacked in 'seven minutes,' taking Japan infrastructure offline
  2. TechEchelon — Ransomware Attack on IDC Frontier's IDCF Cloud Disrupts 495 Companies and Government Clients in Japan
  3. DataBreaches.Net — Cyberattack at IDC Frontier disrupts services around nation
  4. The Japan Times — More Japanese firms hit by large-scale data breaches
  5. MLex — Japan cloud ransomware attack exposes municipal backup vulnerabilities

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • Attacker figures (seven minutes, ~240 hypervisors, 225 datastores, 554,000+ snapshots, 41.5 PB of backups removed, 3.6 PB encrypted) are the attacker's claims, not confirmed by IDC Frontier.
  • Reports naming JR East and JR Kyushu as affected appeared in a few outlets only and were not confirmed by major media, so they are omitted.
  • Whether the Nissui Logistics outage is the same incident is unconfirmed.
  • The attacking group and any ransom demand have not been disclosed.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related