CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
ROUTINENATOA1incident

IDC Frontier: ransomware stops four zones of IDCF Cloud for 495 companies and local governments, and the provider says customer data there can be restored only from customers' own backups

IDCF Cloud ransomware hits 495 customers incl. local governments; provider says only their own backups restore

Analysis

IDC Frontier says a ransomware attack by a third party that began around 3:40 a.m. on 2026-10-07 stopped four zones of IDCF Cloud East Japan Region 1, affecting 495 companies and local governments, and that, in its current view, data in those zones can be restored only from backups customers hold themselves (translated from Japanese) (IDC Frontier, 2026-10-07; IDC Frontier, 2026-10-08). The provider has suspended customer management consoles in every region (BleepingComputer, 2026-10-08), and Jiji Press reports that websites of Ibaraki Prefecture and the city of Kodaira were among those that went down (Jiji Press via nippon.com, 2026-10-07). No source names the actor, the ransomware family or the intrusion route. The lesson is supplier concentration: local governments sat behind one provider whose recovery depended on copies the customers held.

Cited evidence

In our current view, data can be restored only from backup data that customers hold themselves. (translated from Japanese)

IDC Frontier

IDCF Cloud has proactively disabled customer access to management consoles for all regions while it verifies their security, and will restore access after confirming it is safe to do so.

BleepingComputer 2026-10-08

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.