Japan’s National Police Agency confirmed 123 ransomware cases in the first six months of 2026, the highest half-year total since the agency began compiling this data in 2020. The figure, released Thursday and first reported by The Japan Times, is up by seven cases from the same period a year earlier. It lands during a stretch that has already seen some of the country’s biggest ransomware-linked breaches on record, and it puts Japan squarely inside a global surge that is reshaping how the country’s manufacturers, hospitals, and small businesses think about cybersecurity risk.
What makes the number notable isn’t just the record itself. It’s the pattern underneath it: a wave of attacks concentrated on companies that often lack the budget or staff to defend against them, a manufacturing sector still absorbing the bulk of the hits, and a separate stream of intelligence showing that attackers are scanning Japanese networks more aggressively than ever before. Taken together, the data points to a country moving up the target list for ransomware crews that once focused their energy on the US and Europe.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What the National Police Agency’s Cyberthreat Report Shows
The National Police Agency has tracked ransomware damage on a half-year basis since 2020, giving Japan one of the more consistent official datasets on the problem anywhere in the world. The 123 cases confirmed for January through June 2026 mark the highest reading in that six-year run, according to the agency’s cyberthreat report cited by Japan Times. The prior full year told a similar story: NPA confirmed 226 ransomware cases across all of 2025, up four from the year before and the second-highest annual total on record, Japan Times reported in March 2026.
Read together, the two reports describe a trend line that keeps climbing rather than plateauing. Japan’s ransomware cases 2026 figures now sit ahead of every comparable half-year period the agency has published, and officials have not signaled any expectation that the second half of the year will bring relief.
| Period | Confirmed Ransomware Cases | Notes |
|---|---|---|
| Full year 2025 | 226 | Up 4 from 2024, second-highest annual total on record |
| H1 2025 (Jan–Jun) | ~116 | Derived from the reported 7-case year-on-year increase |
| H1 2026 (Jan–Jun) | 123 | Highest half-year total since NPA began tracking in 2020 |
Small and Mid-Sized Businesses Bear the Brunt
The NPA’s breakdown of the 123 H1 2026 cases shows small and medium-sized enterprises absorbing the majority of the damage. Roughly 60% of incidents, or 79 cases, hit SMEs, while 31 cases struck large companies, according to the agency’s figures reported by Yomiuri Shimbun via Infoseek on September 10. That imbalance tracks with what security researchers have said for years about Japan’s corporate landscape: smaller firms, particularly in the country’s dense manufacturing supply chains, often run older systems and smaller IT teams, which makes them easier entry points for ransomware crews looking for a fast payout.
The consequences of a successful attack rarely stay contained to the victim company. A single supplier going offline can ripple through a manufacturer’s whole production chain, a dynamic that separate research on the business impact of cyberattacks has linked to significant revenue loss for affected firms well beyond the initial incident.
Manufacturing Remains the Top Target
Sector data from the NPA report shows manufacturing absorbed 37 of the 123 confirmed cases in H1 2026, by far the largest single category. Wholesale and retail followed with 15 cases, while information and communications and medical and welfare organizations each recorded 9 cases, per the Yomiuri/Infoseek breakdown of the agency’s figures. The remaining cases were spread across other industries the report did not itemize individually.
| Sector | Confirmed Cases, H1 2026 |
|---|---|
| Manufacturing | 37 |
| Wholesale & Retail | 15 |
| Information & Communications | 9 |
| Medical & Welfare | 9 |
| Other sectors (combined) | 53 |
Manufacturing’s dominance on that list isn’t new, but it matters more this year given Japan’s position in global electronics, automotive, and precision-parts supply chains. A ransomware hit that halts a mid-tier parts supplier for even a few days can cascade into delivery delays for automakers and electronics brands well outside Japan, which is part of why global buyers have started paying closer attention to the country’s ransomware cases 2026 numbers rather than treating them as a purely domestic issue.
Warning Signs Are Flashing Brighter: Suspicious Activity Up 50%
Beyond confirmed attacks, the NPA also tracks network activity considered a precursor to cyberattacks, and that data points to more trouble ahead. Suspicious communications flagged by NPA sensors as attack precursors rose roughly 50% year-on-year in H1 2026, with the agency logging an average of 13,687 such signals per day, according to the Yomiuri/Infoseek report of the NPA findings. Kyodo News, in a separate account of the same data carried by Indonesian outlet VOI, described the figure as suspicious access attempts averaging 13,687 per monitored IP address per day, up more than 4,000 from the same period a year earlier.
Security teams generally treat this kind of scanning and probing data as a leading indicator rather than a lagging one. When reconnaissance traffic climbs at a faster rate than confirmed breaches, it typically means attackers are still in the process of mapping targets, which suggests the current wave of Japan ransomware attacks has not yet peaked.
Recovery Costs Are Climbing Fast
The financial toll of getting back online after an attack has also grown steeper, according to an NPA survey of victim companies cited in the Yomiuri/Infoseek report. About 60% of surveyed cases required at least 10 million yen in recovery spending, with some victims reporting costs of 100 million yen or more, and many companies needed over a month to fully restore their systems. Those figures cover direct remediation costs and don’t necessarily capture lost production, missed deliveries, or reputational damage that can linger long after systems come back online.
Japan’s Rising Profile on the Global Ransomware Map
Japan’s ransomware problem isn’t developing in isolation. Threat intelligence firm Forescout tracked Japan as the 14th most attacked country by ransomware groups between January and April 2026, up sharply from 28th place during the same window two years earlier, according to the company’s 2026 threat landscape analysis. Publicly claimed ransomware breaches against Japanese organizations rose 39% year-over-year in early 2026, climbing from 23 incidents to 32, Forescout found, a growth rate that outpaced the 25% increase in ransomware incidents worldwide over the same stretch.
| Metric | Japan | Global |
|---|---|---|
| YoY growth in publicly claimed ransomware breaches (early 2026) | +39% (23 → 32 incidents) | +25% |
| Global ransomware target ranking, Jan–Apr 2026 | 14th | — |
| Global ransomware target ranking, two years earlier | 28th | — |
That climb from 28th to 14th in roughly two years is one of the sharpest shifts Forescout has recorded for any single country, and it lines up with the NPA’s own case data. Ransomware groups tend to follow the money and the soft targets, and a jump of that size usually reflects a deliberate reallocation of criminal attention rather than a statistical blip.
The Threat Actors Behind the Surge
Forescout’s analysis names Qilin, The Gentlemen, Everest, Night Spire, and Inc Ransom among the most active ransomware groups targeting Japanese organizations between January and April 2026. These are largely the same double-extortion crews causing damage elsewhere in the world this year. Medusa, a separate group, has been linked to attacks on roughly 500 critical infrastructure organizations in the US, illustrating that the crews hitting Japan operate within a broader, borderless ecosystem rather than running Japan-specific campaigns in isolation.
Qilin stands out in the Japan-specific data with a concrete, attributed incident: the group claimed responsibility for a breach at Anabuki Housing Service that exposed information on roughly 496,000 people and involved the theft of 240 gigabytes of data, according to threat intelligence firm CybelAngel’s review of Q1 2026 activity. Forescout’s report does not detail specific victims tied to The Gentlemen, Everest, Night Spire, or Inc Ransom in Japan, but their presence on the list signals that multiple well-resourced groups are now running campaigns against Japanese targets simultaneously.
Inside 2026’s Biggest Japanese Ransomware Breaches
Several individual incidents help explain why Japan’s numbers climbed so fast this year. CybelAngel’s Q1 2026 review flagged a ransom demand of $100 million against Nippon Medical School Musashi Kosugi Hospital, describing it as the largest single demand of the quarter. The same quarter saw an attack on the Nagoya Port Authority, one of Japan’s busiest cargo hubs, according to the same CybelAngel briefing.
Separately, utility company Nippon Telenet disclosed a system failure on March 9, 2026 that the firm later confirmed was tied to a ransomware attack, exposing roughly 1,041,044 pieces of personal information, according to a H1 2026 ransomware roundup published by Comparitech. Comparitech’s tally found that all five of the largest publicly reported data breaches worldwide so far in 2026 occurred in Japan, a striking concentration for a country that, per Forescout’s ranking, only recently broke into the top 15 most-targeted nations.
A Separate Industry Tally Paints an Even Starker Picture
The NPA’s 123-case figure isn’t the only measurement of Japan’s ransomware problem this year, and other counts suggest the damage may run deeper than the official police statistics capture. Takashi Ohmoto, chief cybersecurity strategist at Netskope Japan, published an independent survey in July 2026 that counted 117 direct ransomware incidents and 15 indirect ones in Japan during H1 2026, a monthly average of about 22 cases. Business operations were halted entirely in 54% of the incidents Ohmoto tracked, with a particularly large spike in February tied to an attack on a company that provided IT infrastructure for an entire corporate group.
The gap between the NPA’s police-confirmed figure and Netskope Japan’s independent count reflects a familiar problem in ransomware reporting worldwide: official statistics generally only capture cases that victims formally report to authorities, while private researchers who scan leak sites, dark web forums, and public disclosures often surface additional incidents that never reach police records.
Should Companies Pay the Ransom? The Data Says It’s a Gamble
A survey reported by Kyodo News in April 2026 offers a blunt answer to the question every ransomware victim eventually faces. At least 222 Japanese companies have paid ransomware attackers at some point, the survey found, yet about 60% of them still failed to fully recover their data. Of the firms that paid, 83 were able to restore their systems and data while 139 were not, according to the Kyodo report carried by Bernama. Separately, 141 companies recovered successfully without paying anything at all. Roughly half of the affected companies estimated their combined losses, including ransom payments and recovery costs, at between 1 million and just under 50 million yen.
That data undercuts one of the more persistent assumptions about ransomware: that paying guarantees a faster return to normal. It doesn’t, at least not consistently, and the pattern has pushed more security teams globally toward the same conclusion that unpatched, internet-facing software remains the bigger point of leverage to fix before an attack starts. Vulnerabilities in widely deployed remote-access and IT-management tools, similar to the flaw ransomware operators exploited in a separate incident tied to N-able software, continue to be a common entry point for the same class of attacks hitting Japanese firms this year.
How Japan’s Surge Fits the Global Ransomware Picture
Japan’s 2026 numbers arrive as ransomware trends elsewhere show a more mixed picture. Global data on ransomware attacks and payments in 2026 has shown attack volume climbing in some regions even as the share of victims willing to pay has fallen, a dynamic that mirrors what Japan’s own Kyodo-reported survey found: paying is increasingly seen as unreliable, yet attacks keep coming regardless. That combination, rising attack volume paired with falling payment rates, is part of why many ransomware crews have shifted toward pure data-theft extortion, threatening to leak stolen files rather than relying solely on encryption to force a payout.
Industry analysts have pointed to reports that cyber insurance premiums for Japanese companies have grown more expensive and coverage more restrictive as insurers digest a year of record claims, though specific premium figures for the Japanese market were not detailed in the National Police Agency’s report. A separate Japan Cyber Briefing report on the country’s 2026 outlook noted that most ransomware incidents in Japan still go unreported, meaning even the NPA’s record figures may understate the true scale of the problem. What is clear from the agency’s own numbers is that the country’s ransomware cases 2026 total has become a reference point for how insurers, regulators, and corporate boards in Japan are recalibrating risk for the rest of the year.
Historical Context: How Japan Got Here
The NPA’s half-year ransomware tracking, which began in 2020, has shown a mostly upward trajectory since the agency started publishing the data, according to Japan Times’ reporting on the annual figures. 2025 closed with 226 confirmed cases for the full year, the second-highest annual total the agency has recorded, itself an increase of four cases from 2024. Six months into 2026, the country has already logged 123 cases, more than half of last year’s full-year total, which points toward another record annual figure once the second half of the year is counted.
That trajectory sits against a backdrop of separate, high-profile Japanese breaches this year that, while not all confirmed as ransomware, have kept cybersecurity near the top of the national conversation. Court records, healthcare data, and corporate email systems in Japan have all faced attacks in 2026, a pattern that mirrors what US courts and corporate systems have experienced, including a multi-state court records breach reported in the US this year that similarly took months to fully disclose.
What Comes Next: Five Predictions for the Rest of 2026
Based on the trajectory in the NPA’s own data and the broader threat intelligence picture, here’s how the rest of 2026 is likely to play out for Japan’s ransomware problem.
- A new annual record is likely. With 123 cases already confirmed in H1 2026, Japan is on pace to surpass 2025’s full-year total of 226 once the NPA publishes its next report.
- SMEs will keep absorbing the majority of attacks. Without a major shift in how small and mid-sized manufacturers budget for security, the roughly 60% share of cases hitting SMEs is unlikely to shrink quickly.
- Manufacturing stays the top target. Japan’s export-heavy industrial base gives ransomware crews an outsized incentive to keep hitting parts suppliers and factories, where downtime carries immediate financial pressure to pay.
- Fewer victims will pay, even as attacks rise. The Kyodo-reported finding that roughly 60% of paying victims still failed to fully recover data is likely to push more Japanese boards toward a no-payment default, echoing the trend Group-IB and other researchers have tracked globally.
- Foreign threat intelligence coverage of Japan will expand. Forescout’s tracking of Japan’s climb from 28th to 14th on its global target ranking suggests more international security vendors will build out Japan-specific monitoring and incident response offerings before the year is out.
Frequently Asked Questions
How many ransomware cases did Japan report in the first half of 2026?
Japan’s National Police Agency confirmed 123 ransomware cases between January and June 2026, the highest half-year total since the agency began publishing this data in 2020, according to The Japan Times.
Which industries were hit hardest by ransomware in Japan in H1 2026?
Manufacturing led with 37 confirmed cases, followed by wholesale and retail with 15, and information/communications and medical/welfare with 9 cases each, based on NPA data reported by Yomiuri Shimbun via Infoseek.
Are small businesses or large companies more affected?
Small and medium-sized enterprises accounted for roughly 60% of confirmed cases (79 incidents), compared with 31 cases at large companies, according to the NPA’s breakdown cited by Yomiuri/Infoseek.
Does paying a ransomware demand guarantee data recovery in Japan?
No. A survey reported by Kyodo News in April 2026 found that about 60% of the 222 Japanese companies that paid ransomware attackers still failed to fully recover their data, while 141 companies recovered successfully without paying at all.
Which ransomware groups are most active against Japanese organizations?
Forescout’s 2026 threat landscape report names Qilin, The Gentlemen, Everest, Night Spire, and Inc Ransom as among the most active groups targeting Japan between January and April 2026. Qilin has been publicly linked to the Anabuki Housing Service breach affecting roughly 496,000 people.
How does Japan’s ransomware exposure compare globally?
Forescout ranked Japan as the 14th most attacked country by ransomware groups between January and April 2026, up from 28th during the same period two years earlier, with publicly claimed breaches against Japanese organizations rising 39% year-over-year, ahead of the 25% global growth rate.
How much does ransomware recovery typically cost Japanese companies?
An NPA survey of victim companies found that about 60% of cases required at least 10 million yen in recovery spending, with some victims reporting costs of 100 million yen or more and recovery times exceeding a month, according to the Yomiuri/Infoseek report of the agency’s findings.
Is the National Police Agency’s case count the only measure of Japan’s ransomware problem?
No. An independent July 2026 survey by Netskope Japan’s Takashi Ohmoto counted 117 direct and 15 indirect ransomware incidents in H1 2026, with business operations halted in 54% of cases, a broader tally than the NPA’s police-confirmed figures typically capture.
Related Coverage
Click Here For The Original Source.
