Full Report
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.
Analysis Summary
# Incident Report: H1 2026 Ransomware Surge in Japan
## Executive Summary
During the first half of 2026, ransomware incidents in Japan rose by 4.7%, with 90 organizations affected. The threat landscape was dominated by "The Gentlemen" and "Qilin" ransomware groups, who increasingly targeted small- and medium-sized enterprises (SMEs) and utilized AI to increase operational efficiency. The manufacturing sector remained the primary target, while attackers leveraged double-extortion tactics to maximize impact.
## Incident Details
- **Discovery Date:** January – July 2026 (Ongoing monitoring period)
- **Incident Date:** H1 2026
- **Affected Organization:** 90 organizations (names not disclosed)
- **Sector:** Primarily Manufacturing (34%), Information & Communications (11%), and Services (9%)
- **Geography:** Japan (with secondary impacts in Taiwan, USA, and Philippines)
## Timeline of Events
### Initial Access
- **Date/Time:** Peak activity recorded in April 2026 (19 incidents).
- **Vector:** Exploitation of internet-facing vulnerabilities and credential misuse.
- **Details:** Attackers targeted publicly accessible attack surfaces and exploited weak credential management, including third-party vendor access points.
### Lateral Movement
- **Details:** Attackers utilized administrative tools and compromised credentials to move through internal networks, specifically targeting SMEs where security controls were often less mature.
### Data Exfiltration/Impact
- **Details:** Use of double-extortion tactics. Data was exfiltrated to leak sites before encryption. The Gentlemen's leak site listings grew from 48 in January to 105 in July.
### Detection & Response
- **How it was discovered:** EDR alerts, detection of large-scale file modifications, and the emergence of victim names on leak sites.
- **Response actions taken:** Implementation of SNORT rules for blocking, vulnerability patching, and MFA enforcement.
## Attack Methodology
- **Initial Access:** Exploitation of vulnerabilities in internet-facing assets and VPNs.
- **Persistence:** Not explicitly detailed, but implied through the use of RaaS (Ransomware-as-a-Service) frameworks.
- **Privilege Escalation:** Abuse of administrative privileges and service accounts.
- **Defense Evasion:** Disabling of backup functions and security monitoring tools.
- **Credential Access:** Misuse of shared accounts and long-inactive accounts.
- **Discovery:** Scanning for internet-facing assets and mapping subsidiary/third-party connections.
- **Lateral Movement:** Misuse of remote desktop services and VPNs.
- **Collection:** Large-scale file modifications and data aggregation.
- **Exfiltration:** Data uploaded to dedicated leak sites (DLS).
- **Impact:** Encryption of critical data and public exposure of sensitive information (Double Extortion). Qilin specifically used AI to improve the efficiency of these operations.
## Impact Assessment
- **Financial:** High (Ransom demands and operational downtime).
- **Data Breach:** Significant; 80% of victims were SMEs with capital under JPY 1 billion, often lacking recovery resources.
- **Operational:** Disruption to manufacturing lines and communication services.
- **Reputational:** High; increase in public listings on The Gentlemen and Qilin leak sites.
## Indicators of Compromise
- **Network indicators:** SNORT SIDs: 1:67111 (Snort 2) and 7:29 (Snort 3).
- **Behavioral indicators:** Unusual login times/locations, suspicious account creation, and mass file encryption.
## Response Actions
- **Containment measures:** Isolation of affected systems and disabling of compromised administrative accounts.
- **Eradication steps:** Vulnerability management for all internet-facing assets.
- **Recovery actions:** Restoring from backups (where not disabled by attackers) and enforcing MFA across all remote access points.
## Lessons Learned
- **SME Vulnerability:** Attackers are shifting focus to SMEs (78-80% of victims) as they are perceived as "softer" targets with sufficient capital to pay.
- **Supply Chain Risk:** 13.3% of cases involved overseas offices or subsidiaries, highlighting the risk of "island hopping."
- **AI Integration:** Threat actors (Qilin) are now actively using AI to scale their attacks, requiring defenders to adopt automated response tools.
## Recommendations
- **MFA Deployment:** Mandate Multi-Factor Authentication for all VPNs, cloud services, and administrative accounts.
- **Vulnerability Management:** Prioritize patching for all internet-facing assets and conduct regular attack surface audits.
- **Zero Trust Principles:** Limit administrative privileges to the minimum necessary and restrict third-party access to defined time windows.
- **Logging and Retention:** Establish robust processes for retaining connection logs to facilitate post-incident forensics.