Ransomware attack knocks out Japan's IDCF Cloud region used by 495 firms and governments

SoftBank subsidiary IDC Frontier shut down its IDCF Cloud East Japan Region 1 after a ransomware attack that affected 495 companies and local governments.

Ransomware attack knocks out Japan's IDCF Cloud region used by 495 firms and governments

At a glance

  • The attack began at 3:40 a.m. local time on October 7, according to BleepingComputer.
  • IDC Frontier isolated East Japan Region 1 and disabled management console access in all regions.
  • 495 companies and local governments are affected; no ransomware group has been named.
  • Unverified attacker claims cite 16,000 encrypted VM disks and over 554,000 wiped snapshots.

IDC Frontier, a SoftBank Group subsidiary that operates the IDCF Cloud infrastructure-as-a-service platform in Japan, has confirmed that a ransomware attack caused an outage at the data center cluster serving eastern Japan, affecting 495 companies and local governments. According to BleepingComputer, the attack began at 3:40 a.m. local time on October 7, and the company has since shut down systems in the affected region and cut off customer access to management consoles across all regions while it checks their security.

What happened

IDC Frontier said that "a disruption in East Japan Region 1 was caused by a ransomware attack by a third party," BleepingComputer reported. The company isolated and powered down systems in that region and said it is still investigating the exact cause and the scope of the impact. It is also working to identify and block the intrusion route and to verify the security of its other regions.

As a precaution, customers have lost access to the management console in every region, not only the affected one. According to BleepingComputer, IDC Frontier has not given a recovery timeline and said console access will only be restored once it confirms that doing so is safe.

Attacker claims

BleepingComputer reported that screenshots shown to customers contain a message from the attackers claiming the breach took seven minutes. The threat actor claims to have encrypted 225 databases totaling 3.6 PB, reached 239 hypervisors, sealed 16,000 virtual machine disks and wiped 554,153 snapshots. These claims have not been independently verified, and IDC Frontier has not confirmed them.

No ransomware group has been publicly named, and BleepingComputer said it could not confirm whether any data was stolen. The reported claims relate to encryption and deletion of data rather than exfiltration.

Who is affected

The outage affects the 495 companies and local government organizations that rely on IDCF Cloud services in the impacted region. BleepingComputer also noted that Nissui Logistics, a subsidiary of seafood company Nissui Corporation, reported an outage caused by suspected unauthorized access to a third-party data center, but it is unclear whether that incident is linked to the IDCF Cloud attack.

Attacks on hypervisors and snapshot storage are especially damaging for cloud customers because they can remove both the running workloads and the backups organizations would normally use to recover them.

What to do

IDCF Cloud customers should follow IDC Frontier's official notices and prepare to restore critical services from backups stored outside the provider's platform. More broadly, the incident is a reminder for organizations to keep offline or separately administered copies of cloud backups, to restrict and monitor administrative access to hypervisor management planes, and to include a cloud provider outage in business continuity plans.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.