CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

IDC Frontier IDCF Cloud ransomware attack (October 2026)

incident · incident:idc-frontier-idcf-cloud-ransomware-2026-10

Ransomware attack from about 3:40 a.m. on 2026-10-07 that stopped four zones of the SoftBank Group subsidiary IDC Frontier's IDCF Cloud East Japan Region 1 for 495 companies and local governments, with the provider saying customer data in those zones can be restored only from customers' own backups and suspending customer consoles in every region; the intrusion route and the actor are not public (IDC Frontier, 2026-10-07 and 2026-10-08; BleepingComputer, 2026-10-08; Jiji Press, 2026-10-07).

Aliases: IDCF Cloud ransomware

Coverage
1
first 2026-10-11 → last 2026-10-11
Latest activity
2026-10-11
IDCF Cloud ransomware hits 495 customers incl. local governments; provider says only their own backups restore
Peak priority
routine
1 routine
Targets
technology
sectors: technology, public-sector · regions: apac
Sources cited
4
3 hosts

Defender insights

What each entry about IDC Frontier IDCF Cloud ransomware attack (October 2026) tells a defender to do, newest first.

2026-10-11ROUTINEIDCF Cloud ransomware hits 495 customers incl. local governments; provider says only their own backups restore

Exposure

Story timeline

  1. 2026-10-11IDC Frontier: ransomware stops four zones of IDCF Cloud for 495 companies and local governments, and the provider says customer data there can be restored only from customers' own backups
    active-threatsIDCF Cloud ransomware hits 495 customers incl. local governments; provider says only their own backups restore

Hunting pivots

Affected products
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactData Encrypted for Impact

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-10-11/idc-frontier-idcf-cloud-ransomware-495-customers-backups · ATT&CK page ↗

Entries about IDC Frontier IDCF Cloud ransomware attack (October 2026) (1)

2026-10-11 · view entry permalink →

ROUTINENATOA1

IDC Frontier: ransomware stops four zones of IDCF Cloud for 495 companies and local governments, and the provider says customer data there can be restored only from customers' own backups

IDC Frontier says a ransomware attack by a third party that began around 3:40 a.m. on 2026-10-07 stopped four zones of IDCF Cloud East Japan Region 1, affecting 495 companies and local governments, and that, in its current view, data in those zones can be restored only from backups customers hold themselves (translated from Japanese) (IDC Frontier, 2026-10-07; IDC Frontier, 2026-10-08). The provider has suspended customer management consoles in every region (BleepingComputer, 2026-10-08), and Jiji Press reports that websites of Ibaraki Prefecture and the city of Kodaira were among those that went down (Jiji Press via nippon.com, 2026-10-07). No source names the actor, the ransomware family or the intrusion route. The lesson is supplier concentration: local governments sat behind one provider whose recovery depended on copies the customers held.

In our current view, data can be restored only from backup data that customers hold themselves. (translated from Japanese)

IDC Frontier

IDCF Cloud has proactively disabled customer access to management consoles for all regions while it verifies their security, and will restore access after confirming it is safe to do so.

BleepingComputer 2026-10-08
incident11 Oct 03:38Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • idcf.jp2 (50%)
  • bleepingcomputer.com1 (25%)
  • nippon.com1 (25%)