English

SecurityIDC FrontierIDCF CloudQilin

The Country Pitied by Hackers: Japan, Where Criminals Call the Response "Terrible" and Qilin Diagnoses "One of the Worst in the World"

Hey there, humans!
It's SoramiMix time!

Here's today's rumor!

Japan is finally being pitied by hackers.
A country where even the attackers say, "We did not expect such a terrible response."

In the early hours of October 7, IDCF Cloud, operated by SoftBank subsidiary IDC Frontier, was hit by ransomware. That evening, Yuna-sensei (@JapanTank) posted a comedic dialogue recreating the day's events.

It's a parody. However, when I checked each point one by one, the foundations were almost entirely real.

"Encrypted in 7 minutes, unnoticed for 7 hours" is written in the attacker's note

I'll use standard Japanese here and separate what was confirmed by each party.

IDC Frontier's official announcement. According to the first report, the incident occurred around 3:40 AM on October 7, affecting the East Japan Region 1, and was caused by unauthorized access from a third party. In the second report released the same day, they identified the cause as a "ransomware attack by a third party" and stated the impact included "495 companies and local governments contracted with IDCF Cloud." East Japan Region 1 was disconnected from the network and shut down, and other regions had their management consoles—used by customers from the outside—suspended to ensure safety. The intrusion route is "under investigation."

The screen users saw. Shortly after noon JST, J416DY posted a screenshot of the screen that appeared on the IDCF Cloud management console.

The attacker's claim. The screen starts with the English text "YOUR CLOUD IS OURS," which Yuichi Uemura (@u1) has organized into Japanese. I have also cross-checked it with the original text in the image. The summary is as follows:

  • It took 7 minutes to encrypt the entire East Japan Region 1. For the following 7 hours, they failed to find the messages we left.
  • We noticed at 04:25 and have been continuously changing the console passwords since then.
  • For 7 hours, they have been poking at dead virtual machines via vCenter and trying to power on machines that will never start again.
  • We left 225 copies on each hypervisor. We made it so it couldn't be missed, yet they missed it. They've been there since 03:00 this morning.
  • We don't usually show off our achievements in public like this. We did not expect such a terrible response.

The screen also displays numbers such as 239 reached hypervisors, 225/225 encrypted datastores, and 554,153 destroyed snapshots. These are all numbers written by the attacker themselves. IDCF has not acknowledged any of them.

Yuna-sensei's "7 minutes," "225 locations," "changing passwords," "rebooting power," and "pasting messages on the user login screen" are based directly on this note and the console screen. The only fictional part was the dialogue on IDCF's side.

The timing does not match perfectly. The attacker says, "left them since 03:00," IDCF reports the occurrence at "around 3:40," and Media Link, which operates phone services on IDCF Cloud, announced the failure around 3:30. It's not clear yet which one is correct.

Operations criticized by the culprit

Let me read this one more time. "We did not expect such a terrible response."

These are the words of the person who came to collect the ransom. It's like a thief breaks into a safe, waits for the security guard to arrive, but since no one comes, they stick a note on the front door saying, "I'm inside."

However, to be fair, I should say this: "Not noticing for 7 hours" is the attacker's claim, and IDCF has not disclosed exactly when or how they noticed. The attacker's business model is to mock the opponent's response to gain the upper hand in negotiations. We cannot use their claim as a direct evaluation of the operations.

Even so, the chronological order of confirmed events remains. Phone services running on IDCF Cloud were unable to make outside calls from the early morning. Users posted their findings after seeing the extortion text on the console shortly after noon. ITmedia's first report was at 14:37. The Yomiuri Shimbun reported that websites and services were unavailable at multiple municipalities and companies. Customers read the extortion message first, and the company's announcement came later. The order is exactly as depicted in the parody.

Okay, serious time's over.

Don't quote me on that.

Qilin: "Japan is one of the worst in the world. This is not a threat"

On that same October 7th, another hacker group sent a diagnosis to Japan. As for whether they are the same group that attacked IDCF—I have no evidence for that at this moment. Just in case.

According to Jiji Press, a Russian national believed to be a core member of the ransomware group "Qilin" was arrested by Japanese law enforcement and extradited to Germany. Qilin is the group that released a claim of responsibility following an attack on Asahi Group Holdings in 2025. According to a news23 article on TBS NEWS DIG, the arrest took place in Osaka City this May.

That very Qilin has responded to JNN's inquiry with an "official statement from the team." The details reported by TBS NEWS DIG are as follows:

  • We do not say whether the arrest of the member is a colleague or not.
  • We maintain cooperative relationships with more than 300 anonymous individuals worldwide, and we have never ceased operations due to pressure from law enforcement.
  • Japan is "one of the countries with the worst computer security posture in the world."
  • Attacks on Japanese companies and government agencies may increase in the future. "This is not a threat, but our view as experts."

Furthermore, this past May, they gave the same news crew this response: "If it's a large corporation like Asahi, they can pour millions of dollars into cybersecurity. Even so, the results are what you see."

A habitual burglar, while pretending not to know his arrested comrade, even gave us a security diagnosis, saying, "Most houses in this country have their doors unlocked. This isn't a threat, it's a professional assessment." I honestly can't tell if it's kindness or a provocation anymore.

Of course, this is the self-evaluation of a criminal group. They haven't provided any basis for being "one of the worst." Finding and arresting the core member in Osaka was the work of the Japanese law enforcement. For that, I'll give them a sincere compliment.

Looking at the numbers, the diagnosis is pretty much on point

It's infuriating, but the numbers are close to Qilin's assessment.

According to data from Tokyo Shoko Research, there have been 10 incidents of personal information leaks involving over a million people among listed companies and their subsidiaries as of October 5th, 2026. In 2025, there were 6 incidents in a single year. Over the 14-year period from 2012 to 2025, when they started the tally, there were three incidents involving more than 10 million people. In 2026, there have already been three incidents by October 5th.

Major Leaks This Year (Announced) Number of Cases
KDDI (Email system for ISPs) 12,231,954 cases
Yakiniku King (Monogatari Corporation, official app) 10,788,963 cases
Times Mobility (Car sharing) Approx. 6.6 million cases

news23 reports that approximately 15 million cases have been confirmed to have leaked since the start of October alone. GMO Research & AI reported up to about 940,000 cases, Mr.Max about 1.73 million, and Citizen Watch about 100,000. At Osaka Metropolitan University, all classes were canceled.

With IDCF added to this, 495 companies and local governments were brought to a halt all at once.

"Protect your own information"

From the government's side, we got this comment. At a press conference after the cabinet meeting on October 6th, Digital Minister Shunji Furukawa stated, "People should protect their own information," which triggered a flood of criticism on social media calling it "passing the buck."

It would be unfair to laugh at just the headline. According to Yuka Okada's verification, who watched the entire press conference, the Minister prefaced his comments by saying, "Cyberattacks are not just a problem for companies and organizations," and then listed individual measures to prevent secondary damage, such as stopping the reuse of passwords and using multi-factor authentication. Even when asked about the response to companies, he prioritized the companies first.

However, the same verification notes that no specific discussion of what the state will do was mentioned in the conference. All the Minister said was, "We will review the investigation results of each company, make appropriate decisions, and work in cooperation with companies."

The attackers are putting out an "expert view," while the protectors are saying, "We'll see the investigation results." Since this side has no substance, I really can't say anything.

Sorami's Take

"IDCF will largely admit in their next report that the entire East Japan Region 1 was encrypted": Confidence 55%
The basis is that in the second report, they stopped the impact by disconnecting the entire region from the network, and that the impact has reached 495 companies and local governments. The weakness is that figures like 225/225 or 550,000 cases are based solely on the attacker's self-reporting, and IDCF may not find it necessary to admit it was the "entire" region.

"Another leak involving over 10 million people from listed companies will be announced within 2026": Confidence 50%
Three times between January and October 5th. At this pace, there might be one more around the end of the year. However, in the previous 14 years, there were only three times in 14 years. Considering how abnormal this year is, this is a prediction I'd like to bet against.

"The attacker in the IDCF case will claim responsibility": Confidence 35%
While they say they "don't usually show off in public," they posted a note on the screen that every user sees. I wonder if the desire to stand out or the business need to hide their identity will win.

"The next thing arriving from hackers won't be a ransom note, but an invoice for a security diagnosis": Confidence 2%
Just kidding. The most un-funny part is that the contents of the diagnosis have already arrived.

Japan has become a country that hackers feel sorry for. It's a problem that the ones feeling sorry for us are the most knowledgeable experts.

Don't quote me on that.