“We’ve kidnapped your data.” Ransomware attacks are on the rise in Japan | #ransomware | #cybercrime


Nobody in Japan sends a ransom note anymore. There’s no note made out of cut-out letters from a newspaper. It’s not people being kidnapped anyway; it’s your data. The ransom note arrives on the screen, in a font somebody else chose. Probably 明朝体 (Mincho / serif). The notes and threats vary, but the content is usually the same:

“Your files are locked. Pay us, in crypto, and you get them back. Don’t pay, and we put your customers’ names and all your data on the internet where everyone can read it.”

It is a kidnapping with the victim still sitting at the desk.

From a government site explaining ransomware threats against businesses: https://www.gov-online.go.jp/article/202210/entry-10263.html

Japan’s National Police Agency has been counting these cases every six months since the second half of 2020. On September 10 it released the tally for the first half of 2026. There were 123 reported ransomware attacks in 35 of the country’s 47 prefectures. That is the most in any half-year since the count began. It is only seven more than the same period a year ago, which tells you the number was already bad.

The victims were not the people you’d expect. Seventy-nine were small and medium-sized companies. Thirty-one were large corporations. Thirteen were organizations of other kinds. Manufacturers took the worst of it, with 37 cases. The favorite way in was through a VPN — meant to keep the outside out. The lock was the door, which is both ironic and iconic.

The damage does not stop when the screen goes dark. Fewer than half of the respondents were back on their feet within a month. Nine companies stopped operating entirely. Among organizations that answered the cost question, six out of ten spent more than ten million yen on investigation and recovery. Recovery costs are climbing. So is the sophistication of the people doing the work. The police describe the trend with a phrase that translates roughly as “the methods are getting cleverer.” That is Japanese understatement at its best.

Nobody in Japan had to guess what a long outage looks like. In the small hours of June 8, 2024, servers across the KADOKAWA group stopped doing their job — and put Japan’s right-wing crappy version of YouTube, ニコニコ動画 (Niconico Dōga), out of business — for a while.

ためにならない!? 実は『ニコニコ動画』発の有名人を紹介

Dwango is the KADOKAWA subsidiary that runs Niconico. KADOKAWA is a huge traditional publisher. Niconico is the video site where Japanese users layer their comments over the picture like graffiti on a subway car. The system got hacked.

By eight that morning they had confirmed it was a cyberattack involving ransomware. KADOKAWA pulled every Niconico service offline, severed server-to-server communications and shut machines down. When the attackers remotely restarted servers to keep spreading the infection, engineers physically pulled power and communication cables inside the data center. The encrypted systems included large numbers of virtual machines in the private cloud at a group data center; Niconico’s core video system and uploaded videos, which were hosted in a public cloud, were not themselves encrypted.

A Russian-linked group calling itself BlackSuit claimed responsibility for the job. The damage ran past the video site. Book ordering, digital manufacturing and logistics systems went down, and shipments fell. On June 28 KADOKAWA acknowledged that personal information had leaked. By August 5 it had confirmed leakage affecting 254,241 people — including creators and business partners, all Dwango employees down to part-timers, and some students, graduates, parents, applicants and others connected to N Junior High School, N High School and S High School. (Yeah, I know — N High School from the Niconico people?)

NewsPicks reported in June 2024 that KADOKAWA had paid the hackers $2.98 million — about ¥470 million at the time — in Bitcoin. KADOKAWA did not confirm the report. Months later, Kyodo reported evidence consistent with a $2.98 million cryptocurrency payment. The attackers nevertheless leaked data, which is the oldest trick in the kidnapping business. It’s proof of life and a warning. Like sending the pinkie of your victim in the mail.

“They’re still alive…for now. Don’t cross us. Don’t go to the police. We know where the victim lives. We can come back and finish the job.”

Niconico stayed dark for about two months. It came back at 3 p.m. on August 5, 2024, rebuilt, under a new version name that translates as “Niconico Has Returned.” The KADOKAWA group’s portal website took about four and a half months.

BlackSuit itself was hit by an international law-enforcement operation in July 2025 that seized servers and domains. No arrests were announced, and security researchers said some of the same operators may have resurfaced under a new ransomware operation called Chaos. The people who do this have a habit of staying out there, which is the other oldest lesson.

Personally, I didn’t really shed a tear to see this heavily right-wing off-brand Dailymotion get shut down for a while. Karma is a bitch.

The comments on Niconico, in-your-face by design, get ugly fast. They’re also the core identity of the site.

Niconico at its best

In 2015, there was an incident where an anti-hate speech organization had to halt their livestream programming on Niconico because they were getting an unmanageable influx of hate speech on their broadcasts. But Niconico didn’t take any real action to remedy this problem.

Norikae Netto, the anti-hate speech org, decided to move to YouTube instead — as has most of Japan and the world.

Anti-hate speech organization Norikae Netto’s logo

The NPA has a tool of its own. It built software to decrypt data locked by ransomware and says it has recovered some 20.11 million records so far, customer information among them. The tool has been handed to Europol and is now used in other countries. It is a modest consolation. Someone stole the car; the police have learned to unlock the door.

The NPA runs sensors on the internet to catch the probing that comes ahead of an attack — attackers testing terminals for weaknesses. In the first half of this year those sensors logged an average of 13,687 suspicious contacts per IP address per day, more than 4,000 above the same period last year, and the highest figure on record. Roughly one and a half times last year’s rate. The burglars are walking the block and trying every handle.

The ransomware count came bundled with the rest of the agency’s cyber report, and none of it reads like good news.

There’s methods aplenty. There’s the classic social engineering gambit. “Fake president fraud” — someone poses as the boss, emails the accounting department, and orders a transfer for what looks like ordinary business. That method produced 127 confirmed cases and about 3.88 billion yen in losses. Unauthorized transfers through internet banking accounted for 253 cases and roughly 2.07 billion yen. The NPA’s broader figure for internet-based fraud was 175.5 billion yen, up 45 percent from a year earlier and on pace for a record. Victims are increasingly being talked into wiring the money themselves. It saves the criminals the trouble of stealing it.

Phishing emails — the fake bank page, the fake delivery notice, the form that wants your card number — actually went down. There were about 731,000 in the half, some 465,000 fewer than the year before. Analysis of a year’s worth of them put the estimated location of the sending server in China in 45 percent of cases, Japan in 14 percent, Brazil in 10 percent. It’s nice to see Brazil doing their part.

The decline in one kind of cybercrime is the kind of thing the police mention and then hurry past. It doesn’t help when they ask for a huge budget to note that any crime is actually going down.

Police also went looking for recruiters. Posts on social media suspected of soliciting 闇バイト (やみバイト, yami baito) — “dark part-time work,” the online job listings that funnel young people into fraud and robbery as disposable labor — drew 50,213 warning replies from police in the half year, up 14,576 from the same period in 2025. The agency is putting artificial intelligence on the detection and the warnings. The Internet Hotline Center, which the NPA commissions to collect reports of illegal content, took in 68,842 such reports; 12,516 concerned yami baito, and 5,259 concerned online casinos, a category only added last September.

Arrests for cybercrime rose to 7,607, up 982. Money-laundering cases made up 1,945 of them. That is the other side of every ransom: the money has to go somewhere, and someone has to wash it.

The ransomware numbers sit on top of an older, uglier pile. In July the NPA reported that under its expanded 2026 definition of “special fraud” (特殊詐欺, tokushu sagi) — which now includes SNS investment and romance scams — victims lost a preliminary 181.62 billion yen in the first half of 2026, up about 50 percent from a year earlier and the worst on record. There were 22,031 cases, 3,408 more than the previous year. Eighty percent of the money came from people in their fifties or older. Investment scams run through social media, often with a celebrity’s face pasted on, took about 79.79 billion yen. Scams in which the caller pretends to be a police officer took another 50.79 billion. Romance scams took 24.66 billion. Fifty-six percent of the money moved through bank transfers; 22 percent moved as cryptocurrency. Police arrested 1,381 people, and more than nine in ten of them belonged to what the agency calls “anonymous, fluid criminal groups” (匿名・流動型犯罪グループ, tokumei ryūdōgata hanzai gurūpu) — loose networks that assemble for a job and dissolve. We call them “New-Wave Yakuza.” Overall recorded Penal Code offenses rose 4.8 percent to 383,364, the fourth straight year that the first-half count had risen.

A regional newspaper editorial last October summed up the arrest pattern plainly: some ten thousand people were rounded up in cases tied to these groups the year before, and most were the hired hands. Twenty-nine Japanese nationals aged from their teens to their fifties were detained in Cambodia, held in near-confinement under Chinese-linked managers, making the calls. The people who gave the orders were somewhere else. They usually are.

The ransomware numbers seem small. Partly because these are only the cases reported to police. Some victims may pay up and then shut up. The company names that make the papers — the online office-supply giant Askul (アスクル) is the one everyone mentions — are the ones big enough to be noticed. Askul itself was hit by ransomware in October 2025, temporarily halting services and leaking customer and business-partner information.

Seventy-nine of the victims were small businesses. Their names do not appear. They paid, or didn’t, and then spent a month or more finding out what a company is when its computers won’t talk to it.

The NPA says it has begun full-scale countermeasures. That is what it says every six months. The count goes up anyway. If you’re a victim, the ransom note is still there when you turn the screen back on, and it still wants an answer.

Ransom payments are generally demanded in cryptocurrency, most often Bitcoin. The Devil and criminals take Bitcoin, but some ransomware groups push for privacy coins such as Monero, which are substantially harder to trace. Monero isn’t new — it has been around since 2014 — but its privacy features make it attractive to people who would rather the police not follow the money.

I have a cryptocurrency book, by the way! Here’s a very kind staff pick obi.

Reconsider the VPN your company is using, and whether it is patched. I’d never advise giving in to criminals and, as is often the sad case in kidnapping cases, even when you pay the ransom, you may still lose. But on the bright side, better to lose data than a human life. Although, I’m sure most Japanese corporations wouldn’t agree.



Click Here For The Original Source.

——————————————————–

..........

.

.