SHINDO4
Asahi Group
Asahi Group Holdings, Ltd.
Personal data~2.3Mrecords
LEAK CONFIRMEDFull nameRansomware · Recovering
Open in the live monitor ▶- Disclosed
- Sep 29, 2025
- Detected
- Sep 29, 2025 07:00 JST
- Detection to disclosure
- Same day
- Leak
- Leak confirmed
- Type
- Ransomware
- Status
- Recovering
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityFull name
UnspecifiedContact details and other information
Not leaked
- Credit card information is not included
How many
- Records possibly leaked (revised July 2026) ~2.3M records
- People who contacted the customer consultation office ~1.5M records
- Recipients of congratulatory or condolence items ~117,000 records
- Employees (including former employees) ~107,000 records
- Employees' family members ~162,000 records
- Business partners and their employees ~378,000 records
- Leak confirmed 115,513 records
Who is affected
- People who contacted the customer consultation office
- Recipients of congratulatory or condolence items
- Employees
- Former employees
- Employees' family members
- Business partner staff
Cause
An outside attacker entered the data center network via network equipment at a group site, exploited weak passwords to seize administrator privileges, then intruded into and reconnoitred multiple servers mainly outside business hours before executing ransomware
Timeline
- Intrusion about 10 days before the attack
- Order and shipping operations of domestic group companies suspended
- First disclosure
- Detected
- Data center network disconnected
- Reported to authority
- Second report: ransomware attack confirmed
- Qilin claimed the attack on its leak site (claiming 27 GB, over 9,300 files)
- Third report: traces of data leakage
- Fourth report: possible personal data leak
- Investigation results announced: 1.914 million records possibly leaked; the company said no ransom was demanded or paid
- Order systems resumed at group companies (December 2-3)
- Recurrence prevention measures announced; leak of 115,513 records confirmed
- Shipping of all products resumed (190 days after the incident)
- Possibly leaked count revised to 2.289 million
Response
- Blocked the entry point
- Forensic investigation
- Notified individuals
- Hotline
- Governance / committee
- Service stopped
Network disconnection and data center isolation, investigation with outside experts, notifications to affected people, recurrence prevention measures (announced February 2026)
What you should do
- You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
- Expect targeted phishing posing as HR or interview contacts
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Offline backups with restore drills; segment the network
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Asahi Group Holdings (first report) Official notice · Sep 29, 2025
- Asahi Group Holdings (second report) Official notice · Oct 3, 2025
- Asahi Group Holdings (third report) Official notice · Oct 8, 2025
- Asahi Group Holdings (fourth report) Official notice · Oct 14, 2025
- Asahi Group Holdings (recurrence prevention measures) Official notice · Feb 18, 2026
- Asahi Group Holdings (financial results) IR filing · Jul 8, 2026
- piyolog Researcher · Oct 4, 2025