INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention
| 2026-10-09 15:38 CRITICAL LOW AI-ENABLED ATTACK RANSOMWARE & EXTORTION MALWARE & BOTNETS DDOS & DISRUPTION LAW ENFORCEMENT
Executive Summary
AI-generated
Germany arrested a Russian national believed to be the leading figure in the Qilin ransomware group on October 9, 2026. The suspect was detained by Japanese authorities in May while traveling as a tourist and extradited to Germany under a provisional detention warrant issued by Japan's Ministry of Justice. This arrest is significant for both countries, with Japan having been directly affected by the group's attacks, including disruptions at Nissan and Asahi breweries that exposed data belonging to 1.5 million people. The Qilin ransomware operation has been active since 2022, claiming over 40 victims monthly in June 2025, using double-extortion tactics and targeting multiple sectors worldwide with phishing and known vulnerabilities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2020-1472, CVE-2025-2479 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
nt•••••.dit
ra•••••.live
de•••••.py
se•••••.py
SA•••••.txt
de•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
CVE-2020-1472CVE-2020-1472
CVE-2025-2479CVE-2025-2479
CVE-2025-24799CVE-2025-24799
Target & Sectors
DACH
DACH
FIVE_EYES
FIVE_EYES
mediamedia
manufacturingmanufacturing
governmentgovernment
hospitalityhospitality
Incident Timeline
January to 87
The number of reported incidents increased sharply from 48 in January to 87 in February.
August 2022
Threat actors using Qilin's ransomware-as-a-service operation launched a double-extortion attack on IDCF, stealing and encrypting data prior to extorting a ransom.
Click on any entity below to view its context and source!
tactic
Ransomware
Qilin is a notorious ransomware-as-a-service (RaaS) operation that emerged in August 2022 under the name Agenda, and deployed typical double-extortion attacks, where data is stolen before being encrypted.
malware
Qilin
Qilin is a notorious ransomware-as-a-service (RaaS) operation that emerged in August 2022 under the name Agenda, and deployed typical double-extortion attacks, where data is stolen before being encrypted.
tactic
Extortion
Qilin is a notorious ransomware-as-a-service (RaaS) operation that emerged in August 2022 under the name Agenda, and deployed typical double-extortion attacks, where data is stolen before being encrypted.
around July 2025
The Gentlemen ransomware group launched a campaign targeting victims around July 2025.
Click on any entity below to view its context and source!
tactic
Ransomware
Overview of The Gentlemen ransomware
The Gentlemen ransomware group has been active since around July 2025.
2025/09/17
Ransomware incidents in Japan increased slightly by approximately 4.7% from the same period last year, with a total of around 86 reported incidents between January and July this year.
Click on any entity below to view its context and source!
tactic
Ransomware
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level.
Looking at the ransomware groups observed this year, very few of the groups that were active during the same period last year have been observed, highlighting the rapid changes in the ransomware threat landscape.
target_region
Japan
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
general_metric
4.7 %
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level.
general_metric
86 incidents
Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level.
malware
Qilin
This was followed by Qilin, which caused the highest number of incidents last year, and SafePay, which had relatively few confirmed incidents during the same period last year, with seven incidents each.
organisation
SafePay
This was followed by Qilin, which caused the highest number of incidents last year, and SafePay, which had relatively few confirmed incidents during the same period last year, with seven incidents each.
2025/10/09
Threat actors took credit for a ransomware attack on Japanese beverage giant Asahi in April 2025, which was linked to another incident targeting German democratic socialist party Die Linke.
Click on any entity below to view its context and source!
tactic
Ransomware
The group took credit for an
April ransomware attack
on German democratic socialist political party Die Linke and another devastating incident last year involving
Japanese beverage giant Asahi
.
target_region
Japan
The group took credit for an
April ransomware attack
on German democratic socialist political party Die Linke and another devastating incident last year involving
Japanese beverage giant Asahi
.
target_region
Germany
The group took credit for an
April ransomware attack
on German democratic socialist political party Die Linke and another devastating incident last year involving
Japanese beverage giant Asahi
.
organisation
Asahi
The group took credit for an
April ransomware attack
on German democratic socialist political party Die Linke and another devastating incident last year involving
Japanese beverage giant Asahi
.
October 2025
Threat actors, specifically the Qilin RaaS group, utilized global bulletproof hosting networks to support their ransomware extortion operations.
Click on any entity below to view its context and source!
malware
Qilin
In October 2025, Resecurity’s researchers
detailed
how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
tactic
Extortion
In October 2025, Resecurity’s researchers
detailed
how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
organisation
Resecurity
In October 2025, Resecurity’s researchers
detailed
how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
2026/10/07
Nissui Corporation's logistics subsidiary, Nissui Logistics, experienced a system outage due to suspected unauthorized access to its third-party data center.
Click on any entity below to view its context and source!
target_region
Japan
Message seen by IDFC Cloud clients on the platform console
Source:
j416dy
Nissui also hit
Japanese marine products company Nissui Corporation
announced yesterday
that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.
organisation
Nissui
Message seen by IDFC Cloud clients on the platform console
Source:
j416dy
Nissui also hit
Japanese marine products company Nissui Corporation
announced yesterday
that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.
organisation
Nissui Corporation
Message seen by IDFC Cloud clients on the platform console
Source:
j416dy
Nissui also hit
Japanese marine products company Nissui Corporation
announced yesterday
that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.
organisation
Nissui Logistics
Message seen by IDFC Cloud clients on the platform console
Source:
j416dy
Nissui also hit
Japanese marine products company Nissui Corporation
announced yesterday
that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.
October 7
The IDCF cloud was compromised by a ransomware attack starting at 3:40 AM local time on October 7.
between July 1 and October 6
Threat actors launched a ransomware attack on Macnica's cloud services between July 1 and October 6, resulting in 83 cybersecurity incidents involving personal information theft or exposed data.
Click on any entity below to view its context and source!
general_metric
119 cybersecurity incidents
Since the start of the year, Macnica
logged 119 cybersecurity incidents
involving personal information theft or exposed data, 83 occurring between July 1 and October 6.
data_breach
83 data
Since the start of the year, Macnica
logged 119 cybersecurity incidents
involving personal information theft or exposed data, 83 occurring between July 1 and October 6.
January to July 2026
Ransomware attacks targeted Japanese companies, resulting in a significant increase in listings from January to July 2026.
Click on any entity below to view its context and source!
tactic
Ransomware
Victimized companies
Figure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026.
target_region
Japan
Victimized companies
Figure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026.
general_metric
1 Japan Region
Victimized companies
Figure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026.
January – July 2026
Threat actors used ransomware to target The Gentlemen leak site, resulting in the compromise of IDCF's cloud infrastructure.
2026/10/09
The Qilin ransomware group allegedly stole information about targets of ATF investigations and used a double-extortion strategy, encrypting victims' data while also threatening to publish stolen information unless a ransom is paid.
Click on any entity below to view its context and source!
organisation
the Japanese
“When a Russian national for whom Germany had obtained an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, the Japanese Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition,” [mac…
organisation
Ministry of Justice
“When a Russian national for whom Germany had obtained an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, the Japanese Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition,” [mac…
Japan’s Ministry of Justice worked to detain the suspect before they were extradited to Germany.
organisation
the Tokyo High Public Prosecutors Office
“When a Russian national for whom Germany had obtained an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, the Japanese Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition,” [mac…
When the suspect arrived in Japan, the Japanese authorities worked with the Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities to detain him under a provisional detention warrant, in accordance with Japan’s Act of Extradition.”
reads
a full NPA statement in Japanese.
organisation
the U.S. Bureau of Alcohol, Tobacco
In August, Qilin actors took credit for a
ransomware attack
on the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF).
More recently, the threat group hit the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (
ATF
) and was also linked to the exploitation of
Check Point VPN zero-days
and
Palo Alto VPN n-day flaws
.
victims
40 victims
Qilin ransomware
operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.
organisation
LockBit
In early October,
DragonForce
,
LockBit
, and
Qilin
formed a ransomware alliance
to boost attack effectiveness, marking a major shift in the cyber threat landscape.
organisation
Ransomware
Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape.
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients.
organisation
Dow Inc.
At the end of March,
Qilin Ransomware
group
allegedly breached
the chemical manufacturing giant Dow Inc.
Despite the suspect’s detention in May, the cybercrime group has listed hundreds of new victims on its Tor leak site since June alone.
organisation
IDCF Cloud
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients.
organisation
Frontier
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country.
victims
90 organizations
According to Cisco Talos research, 90 organizations in Japan were affected by ransomware during this period.
organisation
NightSpire
Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
organisation
LockBit 5.0
Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
organisation
AiLock
Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
infrastructure
Windows
Our investigation found ransomware targeting ESXi and Windows environments linked to The Gentlemen.
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain.
This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status.
organisation
LLM
We also identified traces of code that appears to have been generated by an LLM in “deploy_locker.py”, a script used to distribute and execute ransomware across multiple endpoints.
organisation
Tor
Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals.
organisation
Nissan
Among the victims are Japanese automaker
Nissan
, Japanese brewery
Asahi
, U.S. newspaper publisher
Lee Enterprises
, and Australia’s
Court Services Victoria
.
The group has attacked Japanese organizations, including carmaker Nissan and brewing company
Asahi
.
organisation
Asahi
The attack on Asahi, Japan’s largest beer producer, was particularly damaging,
disrupting operations
for an extended period and exposing sensitive details about
1.5 million people
.
The attack on Asahi disrupted its operations for an extended period and exposed data belonging to 1.5 million people.
organisation
the Ministry of Justice
When the suspect arrived in Japan, the Japanese authorities worked with the Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities to detain him under a provisional detention warrant, in accordance with Japan’s Act of Extradition.”
reads
a full NPA statement in Japanese.
organisation
Japan’s Act of Extradition
When the suspect arrived in Japan, the Japanese authorities worked with the Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities to detain him under a provisional detention warrant, in accordance with Japan’s Act of Extradition.”
reads
a full NPA statement in Japanese.
organisation
Japan’s Ministry of Justice
Per the NPA’s own account, Japan’s Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities worked together to detain him under Japan’s extradition law, using a provisional detention warrant, before handing him over to Germany through the proper legal process.
organisation
Screenshots
Screenshots from customers before they were locked out of the console show a message from the threat actor claiming that it took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure.
organisation
IDCF Cloud’s
Screenshots from customers before they were locked out of the console show a message from the threat actor claiming that it took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure.
infrastructure
1 infrastructure
Screenshots from customers before they were locked out of the console show a message from the threat actor claiming that it took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure.
organisation
Macnica
Analysis
Number of confirmed cyberattacks against Japanese entities
Source: Macnica
Analysis of these incidents shows that attackers are probing websites and APIs for access-control, configuration, and authentication weaknesses, and exploiting known (n-day) vulnerabilities.
organisation
Asahi Group Holdings
In 2025, the group claimed responsibility online for a major system outage at Japanese food and beverage company Asahi Group Holdings.
victims
450 victims
Since June, the group has listed more than 450 victims on its data leak site.
victims
11,500 employees
Nissui is a Japanese seafood and food group with approximately 11,500 employees and an international supply chain spanning fishing, aquaculture, processing, and sales.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
victims
2,350 known organizations
By more recent statistics, the group targeted more than 2,350 known organizations across 62 countries.
organisation
ATF
The group allegedly stole information about targets of ATF investigations.
organisation
NPA
The NPA statement does more than confirm the arrest.
organisation
SoftBank Group
The IDCF Cloud infrastructure-as-a-service platform is operated by IDC Frontier, a subsidiary of SoftBank Group, a multinational investment holding company based in Tokyo.
organisation
BleepingComputer
Sejiyama told BleepingComputer that finding weaknesses specific to individual websites has traditionally required considerable time and effort, making small targets less attractive.
data_breach
225 databases
The threat actor claims they encrypted 225 databases corresponding to 3.6 PB of data, reached 239 hypervisors, sealed 16,000 VM disks, and wiped 554,153 snapshots.
organisation
SSN
lots of employee documents (passports, DLs, SSN, de
ath and birth certs), financials, insurance, credit cards, client information, NDAs and so on.
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
organisation
/mnt/Backup
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
organisation
VHDX
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
organisation
Ervin, Taubman & Kaminsky
Akira has just published a new victim : Krycler, Ervin, Taubman & Kaminsky.
organisation
Krycler
Krycler, Ervin, Taubman & Kaminsky
Description:
Krycler, Ervin, Taubman & Kaminsky is a prominent accounting, litigation support, and consultin
g firm based in Sherman Oaks, California.
data_breach
88 gb
We will upload 88gb of corporate data soon.
organisation
GPO
The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain.
organisation
Active Directory Group Policy
This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain.
organisation
Windows/Active Directory
This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status.
organisation
NetExec
The actor then repeatedly installs and configures reconnaissance tools such as nmap and masscan, along with BloodHound, NetExec, Responder, and Impacket for targeting AD environments, all within the same command history.
organisation
Proofs
Following target selection, during Phase 3, we observed the actor downloading and executing Proofs of concept, reconnaissance scripts, and attack tools associated with known vulnerabilities against publicly exposed web services and administrative interfaces.
organisation
RustHound
They may also have used RustHound/BloodHound-related tools to collect domain users, groups, computers, administrative privileges, and trust relationships, with the aim of identifying paths that could be used for lateral movement and privilege escalation.
organisation
BloodHound
We also identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authe…
organisation
RDP
They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement.
organisation
SQL
…identified
RustHound
, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authenticati…
organisation
Responder
…ack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks f…
organisation
NTLM
…CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the rem…
organisation
AnyDesk
…unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
Rclone
…unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool
Responder
;
impacket-partial-mic
, which can be used for NTLM authentication relay attacks;
Ligolo-ng
, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool
chisel
; the remote desktop tool AnyDesk; and the file transfer tool Rclone.
organisation
CVE-2025-24799
Specifically, the actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database.
organisation
PoC
Specifically, the actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database.
organisation
SAM
The command history records the installation of libguestfs-tools, qemu-utils, and nbd-client, the creation of directories such as /mnt/vhdx, and the copying of ntds.dit, SAM, and SYSTEM.
organisation
Chisel
In Phase 1, the actor uses VPN software and tools such as Chisel and Ligolo to establish network routes and turn its server into an attack platform.
organisation
Nmap
They appear to have used Masscan and Nmap to assess publicly exposed hosts, VPN-related ports, web services, SMB, and other active services in order to understand the external and internal network structure.
organisation
SMB
They appear to have used Masscan and Nmap to assess publicly exposed hosts, VPN-related ports, web services, SMB, and other active services in order to understand the external and internal network structure.
organisation
Active Directory
Upon gaining access to the internal network, they used NetExec to enumerate SMB shares, host information, LDAP, and computer information in Active Directory.
organisation
cPanel/WHM
The actor also used a scanner targeting cPanel/WHM and downloaded and executed a PoC to test for authentication bypass vulnerabilities.
organisation
SSH
The actor used VPN, Chisel, Ligolo-ng, SSH, and Proxychains to establish communication paths from the attacker-controlled server into the target organization’s internal network.
organisation
HTTP/S
In addition, it supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB, making it adaptable to various network environments.
organisation
DNS/DoH
In addition, it supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB, making it adaptable to various network environments.
organisation
IP
The tool itself is relatively simple, periodically sending ping requests to a specified IP address and logging whether the host is reachable.
organisation
the .bash_history File
Contents of the .bash_history File (excerpt).
organisation
MFA
To prevent the abuse of credentials, organizations should implement multi-factor authentication (MFA) for VPNs, cloud services, remote desktop services, and administrative accounts.
organisation
EDR
To limit the spread of an attack, it is also effective to use EDR and other security tools to monitor activities such as suspicious remote access, the acquisition of administrative privileges, the disabling of backup functions, and large-scale file modifications.
organisation
SNORT®
Coverage
The following SNORT® rules (SIDs) detect and block this threat:
data_breach
100 number
In June, however, the number exceeded 100 for the first time, reaching 108, and remained high at 105 in July.
data_breach
16 files
The VHDX file was split into 256MiB chunks, with up to 16 files uploaded concurrently to reduce the overall upload time.
the first half of 2026
The Gentlemen ransomware group was the most active in Japan during the first half of 2026, resulting in 14 reported incidents.
Click on any entity below to view its context and source!
organisation
Ransomware
Ransomware incidents in Japan in the first half of 2026:
In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.
Ransomware incidents in Japan during the first half of 2026 (January through July).
Most frequently observed ransomware types in Japan
In Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents.
target_region
Japan
Ransomware incidents in Japan in the first half of 2026:
In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.
Ransomware incidents in Japan during the first half of 2026 (January through July).
Most frequently observed ransomware types in Japan
In Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents.
general_metric
14 incidents
Most frequently observed ransomware types in Japan
In Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents.
Tactical Metrics
Metrics
victims
450
Victims
Click for context!
Since June, the group has listed more than 450 victims on its data leak site.
Metrics
victims
2,350
Known Organizations
By more recent statistics, the group targeted more than 2,350 known organizations across 62 countries.
Metrics
victims
40
Victims
Qilin ransomware
operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.
Metrics
infrastructure
1
Infrastructure
Screenshots from customers before they were locked out of the console show a message from the threat actor claiming that it took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure.
Metrics
victims
11,500
Employees
Nissui is a Japanese seafood and food group with approximately 11,500 employees and an international supply chain spanning fishing, aquaculture, processing, and sales.
Metrics
data_breach
83
Data
Since the start of the year, Macnica
logged 119 cybersecurity incidents
involving personal information theft or exposed data, 83 occurring between July 1 and October 6.
Metrics
data_breach
225
Databases
The threat actor claims they encrypted 225 databases corresponding to 3.6 PB of data, reached 239 hypervisors, sealed 16,000 VM disks, and wiped 554,153 snapshots.
Metrics
data_breach
88
Gb
We will upload 88gb of corporate data soon.
Metrics
victims
90
Organizations
According to Cisco Talos research, 90 organizations in Japan were affected by ransomware during this period.
Metrics
infrastructure
Windows
Affected Product
Our investigation found ransomware targeting ESXi and Windows environments linked to The Gentlemen.
In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups.
The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain.
This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status.
Metrics
data_breach
100
Number
In June, however, the number exceeded 100 for the first time, reaching 108, and remained high at 105 in July.
Metrics
data_breach
16
Files
The VHDX file was split into 256MiB chunks, with up to 16 files uploaded concurrently to reduce the overall upload time.
Intelligence Sources
Talos Intelligence
2026-09-17
BleepingComputer
2026-10-09
Security Affairs
2026-10-09
TheRecord
2026-10-09
Ransomware Live
2026-10-01
Data Breaches
2026-10-06
Japan hands over ‘Qilin’ hacker group member to Germany
Data Breaches
BleepingComputer
2026-10-08
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:12
Comprehensive Tactical Telemetry
Highly Correlated Entities
69x
organisation
Identified Entity
the Japanese
entity
21x
timeline
Temporal Reference
August 2022
date
15x
general metric
%
5
%
9x
tactic
Cyber Operation Type
Ransomware
tactic
9x
industry
Targeted Sector
Government
sector
8x
target region
Target Country
Japan
country
5x
source region
Origin Country
Germany
country
4x
attribution
Attributing Entity
the National Police Agency
authority
4x
general metric
Incidents
84
incidents
3x
vulnerability
Exploited CVE
CVE-2025-2479
cve
3x
general metric
Listings
70
listings
2x
victims
Victims
450
victims
2x
general metric
Phase
2
phase
2x
general metric
Jpy
1,000,000,000
jpy
Contextual Telemetry
Context Block
25 METRICS
malware
Malware Payload
Qilin
tool
general metric
People
1,500,000
people
victims
Known Organizations
2,350
known organizations
general metric
Countries
62
countries
general metric
Reported Attacks
127
reported attacks
general metric
Japan Region
1
japan region
infrastructure
Infrastructure
1
infrastructure
victims
Employees
11,500
employees
general metric
Cybersecurity Incidents
119
cybersecurity incidents
data breach
Data
83
data
general metric
Companies
495
companies
data breach
Databases
225
databases
general metric
Pb
4
pb
general metric
Hypervisors
239
hypervisors
general metric
Vm Disks
16,000
vm disks
general metric
Snapshots
554,153
snapshots
data breach
Gb
88
gb
victims
Organizations
90
organizations
infrastructure
Affected Product
Windows
software
malware
Offensive Tool
Bloodhound
tool
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
general metric
- Fold Increase
2
- fold increase
data breach
Number
100
number
general metric
Time
108
time
data breach
Files
16
files
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.