Asahi Group Holdings, a major Japanese brewery, suffered a significant cyberattack at the end of September, which has now been attributed to the Qilin ransomware group. The attack initially caused widespread system failures, forcing Asahi to shut down its ordering, shipping, and call center operations across Japan. Early statements from the company assured stakeholders that customer and employee data remained secure, but subsequent investigations revealed traces of unauthorized data transfers. Asahi has since acknowledged the possibility that personal information may have been compromised during the incident. The Qilin ransomware group has claimed responsibility for the attack, boasting of exfiltrating approximately 27 GB of sensitive files. These files reportedly include financial records, contracts, employee details, forecasts, and other confidential documents. Samples of the stolen data, reviewed by journalists, appear to confirm the theft of personal information, such as employee ID cards and personal documents. The breach has had a tangible impact on Asahi's domestic logistics, resulting in delayed shipments and looming stock shortages throughout Japan. Production at all breweries has resumed, but IT systems remain impaired, forcing staff to revert to manual processes like pen, paper, and fax machines for order processing. The company has postponed its quarterly financial results announcement due to the ongoing disruption and uncertainty surrounding the full extent of the breach. Asahi is actively investigating the scope of the data compromise and has committed to notifying affected individuals and complying with relevant data protection laws. The incident has raised concerns about the security of corporate and personal data within large manufacturing organizations. The attack highlights the operational risks posed by ransomware groups targeting critical business infrastructure. Asahi's response includes efforts to restore systems and mitigate further damage, though a timeline for full recovery has not been provided. The company has publicly stated its commitment to transparency and regulatory compliance as the investigation continues. The Qilin group’s public disclosure of stolen data samples has intensified scrutiny and pressure on Asahi to address the breach. The incident underscores the growing threat of ransomware to global supply chains and the importance of robust cybersecurity measures in the manufacturing sector. Asahi’s experience serves as a cautionary tale for other organizations regarding the potential consequences of cyberattacks on both business operations and data privacy.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting attributed the Asahi Group Holdings incident to the Qilin ransomware operation. The coverage also highlighted infrastructure support, including bulletproof hosting, underpinning the group's activity.
Asahi said the breach may have exposed personal data, escalating the incident from a systems disruption to a potential data compromise. Early reporting indicated the company was still assessing which individuals and records were affected.
Asahi Group Holdings disclosed that it had suffered a cyberattack affecting parts of its internal environment. The incident prompted an investigation into the scope of the compromise and potential business impact.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.