IDC Frontier, operator of the Japanese cloud service “IDCF Cloud,” released its third update on October 8 regarding the ransomware attack against the service, revealing that customer data stored in the affected zones is unlikely to be retrievable or recoverable. This large-scale security incident affects 495 contracted companies and municipalities, forcing customers to rebuild their environments from their own backups.
The series of disruptions began at approximately 3:40 a.m. on October 7. The affected areas are four zones within East Japan Region 1 — tesla, henry, pascal, and joule — where virtual servers on the cloud have stopped and remain unable to restart. In its first update on October 7, the company disclosed unauthorized third-party access, and in its second update the same day, it confirmed the incident was a ransomware attack.
In the third update, the company stated that the detailed scope of impact and intrusion route remain under investigation, while addressing the data recovery outlook for the first time. Customers in the four affected zones are being advised to rebuild in a separate environment and restore data from their own backups, citing the extent of the damage and security considerations.
The key timeline to date is as follows:
Containment Measures and Investigation Status
To prevent secondary damage and data leakage, IDC Frontier isolated East Japan Region 1 from the network and suspended its management console on October 7. The company is working with external security specialists to identify and block the intrusion route, and continues to investigate the networks, servers, and storage systems that comprise the East Japan and West Japan regions.
Management consoles accessible externally have also been suspended for regions other than East Japan Region 1, with plans to resume operations once safety is confirmed. No unauthorized access has been confirmed to date in the remaining two zones of East Japan Region 1 — radian and newton — or in East Japan Region 2, East Japan Region 3, and West Japan Region 1.
However, the company is urging customers in these areas to back up their own data and is providing instructions on how to do so. Since the management console is suspended, the company is performing tasks such as starting and stopping virtual servers on behalf of customers upon request.
Scope of Impact and Future Response
The incident affects 495 companies and municipalities contracted to IDCF Cloud, and the company is contacting affected customers individually. The status of affected and unaffected zones is summarized below.
| Region/Zone | Status |
|---|---|
| East Japan Region 1 (tesla, henry, pascal, joule) | Ransomware damage, data recovery difficult |
| East Japan Region 1 (radian, newton) | No unauthorized access confirmed |
| East Japan Region 2, 3 / West Japan Region 1 | No unauthorized access confirmed |
Note: Based on company announcements as of October 8, 2026.
The company has reported the incident to supervisory authorities and the Tokyo Metropolitan Police Department, and is considering measures to prevent recurrence. It stated that any new facts requiring disclosure will be announced promptly. “IDCF Cloud TypeS” (formerly White Cloud ASPIRE) and “IDCF Private Cloud” are not affected by this incident.
The impact extends beyond IDCF Cloud contract holders to downstream service users. Key confirmed examples are as follows:
| Affected Party | Incident Details |
|---|---|
| Six Apart “Movable Type Cloud Edition” (IDCF Cloud plan) | 31 servers in East Japan Region 1 are down, making admin panels and public sites inaccessible. Migration to “Sakura Cloud” is underway using backups on Google Cloud |
| Nissui Logistics, a subsidiary of Nissui | Product receiving and shipping halted. Unauthorized access to a contracted data center is believed to be the cause |
| Municipal and J.League club websites (Ibaraki Prefecture, Ibaraki Prefectural Police Headquarters, etc.) | Sites have been intermittently inaccessible since the morning of October 7 |
Note: Based on announcements from each company and organization. Some municipal outages on the same day were caused by separate issues, and causes vary by organization.
Challenges Highlighted by Attacks on Cloud Providers
This incident has resulted in a serious situation where a Japanese cloud provider suffered a ransomware attack that rendered customer data unrecoverable. Unlike attacks on individual companies, attacks on cloud providers carry a structural risk of cascading damage to numerous contracted companies and municipalities. According to Japan’s National Police Agency, reported ransomware incidents in Japan reached 123 in the first half of 2026, a record high for a half-year period.
IDC Frontier is a subsidiary of SoftBank, and IDCF Cloud is used primarily by Japanese mid-sized and small businesses as well as municipalities. Details regarding the intrusion route and the attackers behind the ransomware attack have not been disclosed, and the results of the ongoing investigation will be closely watched.
For customers, the incident has once again underscored the importance of maintaining their own backups even for data stored in the cloud. The fact that the company has no choice but to advise customers in the affected zones to restore from their own backups forces a reconsideration across Japan’s cloud market of both cloud provider security measures and customer-side data protection strategies. Six Apart’s ability to restore its service from backups on a separate infrastructure from IDCF Cloud serves as a case study confirming that importance.
