Japan

Country

Sexual Wellness Manufacturer, Tenga, Suffers BEC

February 13, 2026

Japan-based sexual wellness maker, Tenga Co., Ltd., suffered a business email compromise last week after officials discovered that an unauthorized party gained access to the professional email account of an employee.
“We immediately took steps to secure the account and began an investigation,” the company said in an advisory. “We have determined that on February 13, 2026, between 12 a.m. and 1 a.m. PT the unauthorized party used this account to send unsolicited “spam” emails to contacts found within the account’s history, which may have included you.” Tenga has a U.S. office in Torrance, California.
The attacker had access to the contents of the email inbox. This means the attacker had access to name, email address, and historical email correspondence (which may include order details or customer service inquiries) ended up potentially viewed or acquired.

read more

Ransomware Attack at Semiconductor Maker Advantest

February 15, 2026

Tokyo, Japan- based semiconductor test equipment manufacturer Advantest Corporation suffered a ransomware attack last week impacting certain systems within its network, the company said in an advisory.
“On February 15, the company detected unusual activity within its IT environment,” the company said. “Upon detection, Advantest immediately activated its incident response protocols, isolated affected systems, and engaged leading third-party cybersecurity experts to assist in the investigation and containment of the incident.”
Preliminary findings appear to indicate an unauthorized third party may have gained access to portions of the company’s network and deployed ransomware.
The company said it believes its containment actions and activation of business continuity plans minimized operational disruption and enabled it to continue serving customers.

read more

Japanese High-performance Automotive Suspension Manufacturer Force to Halt Production in Japan and China

October 31, 2025

TEIN, Inc. suffered a ransomware attack on October 31, 2025. The attack hit the main server, affecting all group companies. Japan HQ factory halted production for one day.
The subsidiary factory in China (TEIN Shock Absorber Manufacturing (Jiangsu) Co., Ltd.) was forced to shut down for one week (from November 3). The company is compensating for the lost time by operating on weekends and expects the final impact to be minimal. Their order/shipping system runs on a separate server and was NOT hit by the incident.

The company has not yet confirmed a data leak, internally or externally.

read more

Japanese Chemical Manufacturer Discloses System Failure due to Cyberattack

October 16, 2025

Kurogane Kasei, a chemical manufacturer and subsidiary of KH Neochem, revealed a system failure believed to be caused by a cyberattack. According to the company, it detected a possible breach of some of its servers on October 16, 2025. System failures have also occurred and are believed to be the result of this breach. The company is currently investigating the scope and cause of the impact, including the possibility of an information leak. The company denies that the outage has had any impact on production activities. RansomHouse claimed the cyberattack on October 23, 2025, and threatened to release sensitive data unless the company engaged in negotiations. The company has not confirmed who is behind the cyberattack.

read more

Japanese Aluminum Manufacturer Operations Impacted by Cyberattack

October 1, 2025

Manufacturer Mino Kogyo Co., Ltd. confirmed a cyberattack and its details on their website. The company detected the attack and initiated a network shutdown on October 4, 2025. Production activities were partially affected but largely continued through individual adjustments. Financial settlement systems were restored quickly. The company later confirmed 300 GB of communications data had been stolen.

SafePay claimed responsibility for the attack. The hackers got access through a regular employee’s VPN account using a valid ID and password (not a VPN vulnerability exploit). This led to internal exploration, system administrator privilege escalation (Oct 3), system destruction, and file encryption. Data leak was confirmed on October 28, 2025.

read more

Japanese Brewer Hit in Ransomware Attack

September 29, 2025

A major global brewer based in Japan reverted to some manual operations after a ransomware attack hit the company last week. The attack forced it to suspend some of its operations like beer production. “Asahi Group Holdings, Ltd. is currently experiencing a system failure caused by a cyberattack, affecting operations in Japan,” the company said. It suspended the following operations: order and shipment operations at group companies in Japan and call center operations, including customer service desks. All 30 Asahi plants in Japan were forced to temporarily halt operations and beer production reportedly resumed at the six plants on October 2. Asahi Breweries did not specify how much longer it would take to return to full capacity.

read more

Ransomware Attack Disrupts Hitachi Vantara Operations

April 26, 2025

Hitachi Vantara experienced a ransomware incident on April 26. BleepingComputer reports that, while the company’s cloud services are not impacted, Hitachi Vantara systems and Hitachi Vantara Manufacturing were disrupted as part of the containment effort. Additionally, while Hitachi Vantara’s remote and support operations are down, customers with self-hosted environments can still access their data as usual. The attack has also affected multiple projects owned by government entities.

read more

Cyberattack Leads to Order Delays at Sportbrand Mizuno

February 4, 2025

Sports equipment and sportswear brand Mizuno suffered a ransomware attack over the weekend of February 4th, targeting the USA corporate network. This cyberattack led to significant business disruption, including phone outages, delays in shipping products, and website issues. nnThe ransomware attack came at a bad time for Mizuno. They just launched their Mizuno Pro 221, 223, and 225 golf irons on February 3rd, which were preordered and eagerly anticipated by many customers. Customers who preordered the irons faced delays with no way to contact the company for more information. Also, Mizuno resellers can no longer access Mizuno’s ‘Direct Connect’ B2B website used by resellers to place orders.

Mizuno is not providing a public statement about what is causing their week-long outages. At this time, it is unknown what ransomware gang is behind the attack.

read more

Cyberattack at Japan’s Largest Mobile Carrier, NTT Docomo

January 2, 2025

Japan’s largest mobile carrier, NTT Docomo, reported a cyberattack temporarily disrupted operations. Its system were targeted by a distributed denial-of-service (DDoS) attack.
From early Thursday morning until late afternoon, local users were unable to access NTT Docomo’s news website, video streaming platform, mobile payment and webmail services. The company reported that access to most services had been restored late afternoon, although some content updates might still face delays.

read more

Over 46 Japanese Businesses, incl Banks and Government Agencies,Targeted by Cyberattacks

January 9, 2025

At least 46 Japanese entities, including banks and government agencies, were targeted by cyberattacks utilizing the same malware, causing temporary service suspensions. According to Trend Micro Inc., Japan Airlines Co., NTT Docomo Inc. and major banks were among the victims of distributed denial-of-service, or DDoS, attacks in which networks are overwhelmed by data from multiple sources over a short period, causing temporary service suspensions. The Japan Weather Association said on Thursday it was hit by a cyberattack that rendered its information website inaccessible for over nine hours from around 7 a.m. A similar cyberattack on Sunday that affected both the web and app versions of the weather site took over 7 hours to resolve.

“We can’t rule out the possibility that multiple groups conducted attacks at the same time,” a Trend Micro official said. The hackers were able to simultaneously control devices including cameras and home appliances connected to the internet to carry out the attacks, the security firm said.

read more