SHINDO4

Asahi Group

Personal data~2.3Mrecords

LEAK CONFIRMEDFull nameRansomware · Recovering

Open in the live monitor ▶
Disclosed
Sep 29, 2025
Detected
Sep 29, 2025 07:00 JST
Detection to disclosure
Same day
Leak
Leak confirmed
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
UnspecifiedContact details and other information

Not leaked

  • Credit card information is not included

How many

  • Records possibly leaked (revised July 2026) ~2.3M records
  • People who contacted the customer consultation office ~1.5M records
  • Recipients of congratulatory or condolence items ~117,000 records
  • Employees (including former employees) ~107,000 records
  • Employees' family members ~162,000 records
  • Business partners and their employees ~378,000 records
  • Leak confirmed 115,513 records

Who is affected

  • People who contacted the customer consultation office
  • Recipients of congratulatory or condolence items
  • Employees
  • Former employees
  • Employees' family members
  • Business partner staff

Cause

An outside attacker entered the data center network via network equipment at a group site, exploited weak passwords to seize administrator privileges, then intruded into and reconnoitred multiple servers mainly outside business hours before executing ransomware

Timeline

  1. Intrusion about 10 days before the attack
  2. Order and shipping operations of domestic group companies suspended
  3. First disclosure
  4. Detected
  5. Data center network disconnected
  6. Reported to authority
  7. Second report: ransomware attack confirmed
  8. Qilin claimed the attack on its leak site (claiming 27 GB, over 9,300 files)
  9. Third report: traces of data leakage
  10. Fourth report: possible personal data leak
  11. Investigation results announced: 1.914 million records possibly leaked; the company said no ransom was demanded or paid
  12. Order systems resumed at group companies (December 2-3)
  13. Recurrence prevention measures announced; leak of 115,513 records confirmed
  14. Shipping of all products resumed (190 days after the incident)
  15. Possibly leaked count revised to 2.289 million

Response

  • Blocked the entry point
  • Forensic investigation
  • Notified individuals
  • Hotline
  • Governance / committee
  • Service stopped

Network disconnection and data center isolation, investigation with outside experts, notifications to affected people, recurrence prevention measures (announced February 2026)

What you should do

  1. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Offline backups with restore drills; segment the network
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources