SoftBank national cloud arm attacked in ‘seven minutes,’ taking Japan infrastructure offline | #ransomware | #cybercrime


SoftBank cloud subsidiary IDC Frontier was targeted in a ransomware attack that blighted various Japanese operators and service providers.

The infrastructure-as-a-service (IaaS) vendor confirmed its IDCF Cloud service in East Japan Region 1 was attacked on October 7, affecting almost 500 corporate and municipal customers in total. A later update revealed that virtual servers in four availability zones had stopped and could not restart. The company warned that it would be difficult to retrieve or restore customer data from the affected infrastructure, with customers potentially having to restore everything from their own backups.

“Given the current damage situation and security considerations, we are advising you to prepare a separate environment and rebuild your system,” it said in translation.

IDC’s own customer management console remains down, leaving the firm to manually restore virtual servers per individually made client requests.

Among the affected customers were Wi-Fi and internet services provider Fibergate, which disclosed impact on its Wi-Fi authentication services, while enterprise communications software firm Medialink saw its cloud-based enterprise telephony and Internet Protocol Private Branch Exchange (IP-PBX) services go offline.

Public sector organizations were also caught up in the attack, as well as firms spanning logistics, education, and financial services.

No telecom services provided by IDC’s parent appear to have been impacted in the breach.

‘Seven minutes to take a national cloud apart’

In a screenshot shared by Bleeping Computer, the bad actor in question left an English-language message on the IDCF platform console taunting that the attack only took seven minutes to carry out.

“October 7, 2026. Seven minutes. Exactly seven minutes is what it took to turn your entire East Japan Region one into ciphertext (and) take a national cloud apart – and in the seven hours since, you could not even manage to find the message we left telling you we had done it,” the message read. “We do not normally parade our work in public like this. We did not expect a response this bad. You noticed at 04:25. You have been rotating console passwords ever since.”

“For seven hours you have been poking dead VMs (virtual machines) from vCenter (VMware vCenter Server), power-pressing machines that will never boot again,” it added.

The actor claimed the breach reached almost 240 hypervisors, destroyed over 554,150 snapshots, and removed 41.5 PB of backup capacity.

It also claimed to have encrypted 225 datastores, referring to storage infrastructure that holds VM files and virtual disks.

In response, IDC Frontier established an emergency response headquarters, with SoftBank supporting the investigation and customer assistance and recovery.

While AI agent-led cybersecurity attacks are currently grabbing headlines, recent Google security research reported that virtualization infrastructure was targeted in approximately 43% of ransomware intrusions it responded to in 2025, up from 29% in 2024.

As with the IDC attack, its investigations identified ransomware groups using automated scripts to access multiple ESXi hosts, shut down VMs, delete snapshots and backups, and deploy ransomware.



Click Here For The Original Source.

——————————————————–

..........

.

.