Japan dominated this week’s breach news. A ransomware attack on a SoftBank cloud subsidiary rippled out to hundreds of customers, police put a number on one gang’s Japanese victims, and three well-known Japanese firms disclosed leaks. Elsewhere, Asos admitted hackers took far more than it first said, Oracle Health’s count may be close to 20 million, and Denmark found its national register had been looked up on a vast scale.
As always, TSN separates what organisations have confirmed from what is reported or claimed. No attack steps appear below.
The week at a glance
| Incident | Confirmed | Still open or claimed |
|---|---|---|
| IDC Frontier (SoftBank) | Ransomware; outage for 495 customers; Nissui logistics halted at 17 sites; Ibaraki websites down [1] | Data theft; attacker |
| Qilin in Japan | Police: 53 Japanese companies hit [2] | Victims not named |
| Asos | Detailed customer profiles taken; no passwords or bank details [3] | Hackers’ claim of entry via Simon AI on Snowflake |
| MrMax | Up to 1,735,154 members’ IDs, names, emails, phones leaked [4] | Financial impact |
| Oracle Health (Cerner) | State filings: 2,992,244 Texans and others [5] | Bloomberg’s “nearly 20 million” (Oracle has not confirmed) |
| Denmark CPR register | Lookups covered about 8.8 million people (not final) [6] | Who did it; whether data was kept |
| GMO infoQ | Up to 948,498 records; ¥2,869,500 in gift codes taken [7] | Investigation ongoing |
| Nikkei | Employee email account taken over; about 9,000 phishing emails [8] | Number of records |
| WordPress plugins | Ninja Forms and WPC Product Bundles flaws exploited [9] | Number of infected sites |
What happened at IDC Frontier?
IDC Frontier, a SoftBank subsidiary that provides cloud and data-centre services, said on 7 October that a ransomware attack caused a system outage affecting 495 corporate and local-government customers (confirmed) [1]. It is still investigating the scale of the damage and whether personal information was taken [1].
The knock-on effects were wide. Nissui Logistics, part of the seafood group Nissui, uses an IDC Frontier data centre; its logistics system went down, halting deliveries in and out of 17 sites across Japan. Nissui said about 1,200 business partners, including retailers, restaurants and food producers, were affected, and that recovery would not be finished on 8 October [1]. Ibaraki Prefecture, which outsources its websites to IDC Frontier, saw the prefectural government and police sites go offline [1]. No group has been named as responsible in the reports cited.
Update, 9 October 2026
IDC Frontier now says some customer data may not be recoverable (confirmed). In a third notice dated 8 October, IDC Frontier said customer data stored in four zones of its IDCF Cloud East Japan Region 1 (the tesla, henry, pascal and joule zones) is expected to be difficult to retrieve or restore [10]. In the company’s current view, data can be restored only from backups that customers hold themselves, and it is helping affected customers rebuild in a separate environment [10]. Virtual servers in those zones have stopped and cannot be restarted [10].
The company’s notices also confirm more of the timeline. The attack began at about 03:40 local time on Wednesday 7 October, and was “a ransomware attack by a third party” (confirmed) [10][11]. IDC Frontier cut East Japan Region 1 off from the network and shut down its systems to prevent further damage or data leakage, and has suspended the customer management consoles for its other regions while it checks their security [10][11]. It says no unauthorised access has been found so far in its other zones and regions, but it is asking customers there to back up their own data [10]. The count of affected customers is unchanged at 495 companies and local governments [10]. IDC Frontier says it has reported the incident to its supervising ministry and the Tokyo Metropolitan Police, and that the route the attackers used is still under investigation with outside security specialists [10].
What the attackers claim (unconfirmed). Customer screenshots taken before the consoles were switched off show a message from the attackers, BleepingComputer reports [12]. The attackers claim it took seven minutes to breach the East Japan Region 1 infrastructure, and that they encrypted 225 databases “corresponding to 3.6 PB of data”, reached 239 hypervisors, sealed 16,000 virtual-machine disks and wiped 554,153 snapshots [12]. These figures, including the 3.6 PB, are the attacker’s unverified claims. IDC Frontier has not confirmed them.
A wider pattern in Japan (researcher’s count). Yutaka Sejiyama, a researcher at the security firm Macnica, told BleepingComputer that Macnica has logged 119 incidents this year involving personal-information theft or exposed data, 83 of them between 1 July and 6 October, compared with 84 in the whole of 2025 and 62 in 2024 under the same criteria [12]. These are Macnica’s own counts.
Kodaira City (reported, separate). Separately, Nippon TV reported on 8 October that Kodaira City in Tokyo cannot display its official website after ransomware hit a cloud service used by the contractor that maintains it [13]. No leak has been confirmed, but personal details sent through forms such as contact forms may have leaked [13]. The report does not say which cloud service was involved, and no source TSN has seen links the Kodaira incident to IDC Frontier.
Later, 9 October 2026: JR East and Viewcard
JR East and its card company Viewcard said on 9 October that about 6.09 million accounts, mostly email addresses, may have been exposed after the IDC Frontier attack (reported, a possible exposure rather than confirmed theft; the figure counts accounts across three services, not people) [14][15]. IDC Frontier has still not confirmed that data left its systems. TSN has covered it in a separate post: JR East and Viewcard Say About 6.09 Million Accounts May Be Exposed After the IDC Frontier Attack.
How widespread is Qilin in Japan?
Japan’s National Police Agency said on 8 October that 53 companies in Japan have been targeted by the Qilin ransomware group (confirmed) [2]. They span manufacturing, services, construction, hospitals and schools; none has been named [2]. The agency says Qilin has operated since about October 2022, has attacked some 4,000 companies worldwide, and has been active in Japan since April 2023 [2]. Kyodo notes Qilin is believed to be behind the 2025 attack on Asahi Group, and reports, citing a source, that Japan recently handed a detained Russian suspect to Germany [2].
Cybersecurity minister Toshiharu Furukawa said the government will urge businesses to fix system vulnerabilities and prevent misuse of leaked information [2].
What did Asos admit?
Asos first said “basic personal information including name and contact details may have been accessed” after hackers sent a pop-up to app users on 6 October. After the hackers contacted BBC News with a sample, Asos told customers that detailed data profiles had been taken (confirmed) [3]. According to the BBC, these include names, addresses, phone numbers, emails, customer numbers and search terms used on the site. Asos says no bank details or passwords were accessed [3].
Asos says the hackers got into an employee account by “impersonating a trusted contact to obtain log in credentials” [3]. The group, calling itself Xuanyewen, claims it got in through Simon AI, a platform built on Snowflake; that is unverified, and Snowflake has previously said its platform was not breached [3]. The main risk now is convincing scam emails and calls that use real details [3].
Which other Japanese companies disclosed breaches?
- MrMax. Tokyo-listed Mr Max Holdings said in a stock-exchange filing that on 3 October an outsider misused a function of the software behind its subsidiary MrMax’s app and online store. Data for up to 1,735,154 registered members leaked: member IDs, names, email addresses and phone numbers. Addresses, dates of birth, card details, passwords and purchase histories were not [4].
- GMO Product Platform disclosed that its subsidiary’s survey site infoQ was breached on 3 October through a flaw in the site’s software. Up to 948,498 records may be affected, including names, addresses and contact details, and members’ points were swapped for ¥2,869,500 in Amazon gift codes without consent. The site is suspended [7].
- Nikkei Inc. said an employee’s Microsoft 365 account was taken over and used on 30 September to send about 9,000 emails with links to malicious sites, including to news sources. Recipients’ names, email addresses and some email content are believed leaked; Nikkei has reported it to Japan’s privacy regulator [8].
What about Oracle Health and Denmark?
Oracle Health. Bloomberg reports, citing a Texas attorney general report, that nearly 20 million people’s personal and medical data was compromised in the early-2025 attack on Cerner’s legacy servers (reported; Oracle declined to comment) [5]. The confirmed state filings are smaller: 2,992,244 Texans, about 283,000 in South Carolina and about 69,000 in Washington [5]. Data may include names, Social Security numbers and medical record details [5].
Denmark. The digitalisation ministry said on 5 October that unauthorised parties used a small Danish company’s lawful lookup access to the national CPR register for about ten days in September. Names, addresses and personal identification numbers for about 8.8 million people, living and dead, were involved; the ministry says that figure is not final [6]. The company’s access has been cut, police are investigating, and who was behind it is unknown [6].
Which WordPress plugins are under attack?
Patchstack found attackers exploiting high-severity flaws in Ninja Forms (on more than 500,000 sites) and WPC Product Bundles for WooCommerce (more than 30,000) to install a fake plugin and create administrator accounts, one of them hidden from the user list [9]. Patchstack says exploitation is limited so far. Fixed versions are Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7; updating stops new attacks but does not remove an existing infection, so site owners should check for signs of compromise [9].
What this does not prove
- That data was stolen from IDC Frontier’s systems. IDC Frontier is still investigating the scale of the damage and whether personal information was taken [1]. It says some stored data may be unrecoverable, which is different from confirming theft, and it has not said data left its systems [10]. JR East and Viewcard say only that they cannot rule out that customer data was viewed or taken [15].
- Which companies Qilin hit. Police have not named them [2].
- How Asos’s data was taken. The Simon AI and Snowflake route is the hackers’ claim [3].
- The 20 million Oracle Health figure. It is reported, not confirmed by Oracle [5].
- Who looked up Denmark’s register, or why. Officials have not said [6].
- How many WordPress sites are infected. No count has been published [9].
- That 3.6 PB of data was encrypted. That figure, and the other numbers on the ransom screen, are the attacker’s unverified claims [12].
- That Kodaira City’s outage is connected to IDC Frontier. No source makes that link [13].
- That 6.09 million different people are affected. The figure counts accounts across three services, and one person can hold several. JR East’s own notice was not available to TSN; the figures come from news reports of the companies’ statements [14][15][16].
The Bottom Line
The week’s biggest lesson came from Japan: when a shared cloud provider is hit, the damage spreads to its customers’ customers, from seafood deliveries to prefectural websites [1]. Elsewhere, first statements kept proving too small. Asos’s “basic contact details” became detailed profiles [3]; Oracle Health’s count may be several times its state filings [5]. For anyone whose details are in these leaks, the practical risk is the same: scam messages that sound genuine. Treat unexpected calls and emails with suspicion, however much they know about you.
IDC Frontier’s own update makes the stakes clearer: for customers in four zones of its East Japan Region 1, the company expects data to be recoverable only from their own backups [10]. That is the practical lesson from this incident for any organisation that rents cloud servers: keep independent backups you control.
The IDC Frontier attack now has a named knock-on leak: JR East and Viewcard say about 6.09 million accounts’ details, mostly email addresses, may have been exposed (reported) [14][15]. If you use Ekinet, Otona no Kyujitsu Club or Viewcard, treat any unexpected email about your account with suspicion.
Related on TSN: Cyber breaches, 8 October · Cyber breaches this week: credential reuse, retail alerts, campus ransomware and edge-gear risk · JR East and Viewcard Say About 6.09 Million Accounts May Be Exposed After the IDC Frontier Attack
Sources
- The Asahi Shimbun, “Cyberattack at IDC Frontier disrupts services around nation,” Asia & Japan Watch, 8 October 2026, 10:12 BST (18:12 JST). https://www.asahi.com/ajw/articles/16950581
- Kyodo News, “53 companies in Japan hit by Qilin ransomware group,” 8 October 2026, 11:27 BST (19:27 JST). https://english.kyodonews.net/articles/-/87587
- Joe Tidy, “Asos hackers took more personal details than first revealed, BBC finds,” BBC News, 8 October 2026. https://www.bbc.co.uk/news/articles/c3zxjdw5ywgpo
- Mr Max Holdings Ltd., “Notice and Apology Regarding Information Leakage Due to Unauthorized Access” (English translation of TSE filing), 6 October 2026. https://fs2.magicalir.net/tdnet/2026/8203/20261006546325.pdf
- Eduard Kovacs, “Oracle Health Data Breach Tally Climbs to Nearly 20 Million,” SecurityWeek, 8 October 2026 (citing Bloomberg). https://www.securityweek.com/oracle-health-data-breach-tally-climbs-to-nearly-20-million/
- Swati Khandelwal, “Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account,” The Hacker News, 6 October 2026. https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html
- Japan IR, “GMO Product Platform, Inc. Notice: Unauthorized Access and Personal Information Leakage on infoQ” (summary of the company’s 6 October 2026 disclosure), updated 7 October 2026. https://japanir.jp/en/company/company-3695/ir/3695-20261006-01_wp_disclosure_update/
- Nikkei Inc., “Regarding Information Leaks and the Sending of Suspicious Emails due to a Cyberattack,” announcement, 5 October 2026. https://www.nikkei.co.jp/nikkeiinfo/en/news/announcements/1555.html
- Bill Toulas, “Ninja Forms plugin flaw exploited to hack WordPress sites,” BleepingComputer, 6 October 2026. https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/
- IDC Frontier, “[Third report] Failure caused by unauthorised access to some of our service systems” (【第3報】当社サービスの一部システムへの不正アクセスによる障害について), 8 October 2026 (company notice, in Japanese; TSN’s translation). https://www.idcf.jp/news/topics/20261008001
- IDC Frontier, “[Second report] Unauthorised access to some of our service systems” (【第2報】当社サービスの一部システムに対する不正アクセスについて), 7 October 2026 (company notice, in Japanese; TSN’s translation). https://www.idcf.jp/news/topics/20261007002
- Bill Toulas, “Ransomware attack disrupts Japan’s IDCF Cloud used by govt clients”, BleepingComputer, 8 October 2026, 21:09 BST (source of the attacker’s on-screen claims, which are unverified, and of Macnica’s counts). https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/
- Nippon TV (NTV News NNN), “Tokyo’s Kodaira City official website cannot be viewed after ransomware attack; residents’ personal information may have leaked”, via Yahoo! News Japan, 8 October 2026, 05:25 BST (13:25 JST) (in Japanese; TSN’s translation; reported). https://news.yahoo.co.jp/articles/29a5475e9889fdbc8580dc101f5b6db885d28cb8
- Kyodo News, “Bookoff, JR East each report 6 mil. customer records leak in newest breach”, 9 October 2026, 09:51 BST (17:51 JST) (reported). https://english.kyodonews.net/articles/-/87669
- 梅林日奈子 (ITmedia reporter), “JR東日本、「えきねっと」「ビューカード」などで漏えいか メルアドなど最大609万件 IDCFへの不正アクセスで【追記あり】” (JR East: possible leak at Ekinet, Viewcard and others; up to 6.09 million email addresses and other data, from unauthorised access to IDCF), ITmedia NEWS, 9 October 2026, 07:23 BST (15:23 JST), updated 09:58 BST (17:58 JST) (in Japanese; TSN’s translation; reports both companies’ notices). https://www.itmedia.co.jp/news/article/2610/09/2000002171/
- Nippon TV (NTV News NNN), “【速報】えきねっと会員と大人の休日倶楽部会員に電子メールを送るシステムにも不正アクセス 個人情報漏えいの可能性 JR東日本” (Breaking: unauthorised access also hit the system that emails Ekinet and Otona no Kyujitsu Club members; possible personal-data leak, JR East), 9 October 2026, 06:18 BST (14:18 JST), updated 07:31 BST (in Japanese; TSN’s translation; reported). https://news.ntv.co.jp/category/society/d0a74accb39041b69e1df75b968f00d1
Source note: The brief’s MrMax figure (“1.73M+ per Japanese media”) is replaced by the filing’s own “up to 1,735,154”. The infoQ details come from Japan IR’s English summary of GMO’s disclosure, not the original filing. The Bloomberg report and the Texas attorney general report it cites were not read directly; the “nearly 20 million” figure is as carried by SecurityWeek. The Qilin suspect handover is Kyodo’s report citing an unnamed source. Asos was placed in this roundup rather than as an update to post 20046, which does not cover Asos; the earlier Asos coverage, including an 8 October update, is in post 19971.

