Askul, a major Japanese office and household goods retailer, suffered a ransomware attack that severely disrupted its e-commerce and logistics operations. The cyberattack, discovered over a weekend, led Askul to halt all online orders, product shipments, and new user registrations across its three main e-commerce platforms: Askul (office supplies), Lohaco (household goods), and Soloel Arena (corporate clients). The company also suspended customer inquiries due to the system failures caused by the attack. Askul publicly stated that it is investigating the full extent of the incident, including the potential leak of personal and customer data, and has not yet determined when operations will resume. The impact of the attack extended beyond Askul itself, affecting several major Japanese retailers that rely on its logistics network. Muji, a prominent retailer of minimalist household goods and clothing, was forced to take its Japanese online store offline, suspending browsing, purchases, and access to order histories via its app. Muji clarified that only its Japanese online operations were affected, with physical stores and international branches remaining operational. The company is working to identify which customer shipments were impacted and plans to notify affected customers by email. Other retailers, such as Loft and Sogo & Seibu, also reported disruptions, halting online orders and some product shipments due to their reliance on Askul’s logistics systems. Askul’s customer service desk became unreachable, both by phone and online, further complicating the response for affected customers. The attack highlights the interconnectedness of Japan’s retail and logistics sectors, where a single supplier’s outage can cascade across multiple brands and services. The incident follows a series of recent ransomware and cyberattacks targeting Japanese companies, including a notable attack on Asahi, Japan’s largest brewer, earlier in the month. Askul is owned by Yahoo! Japan Corporation and plays a significant role in both business-to-business and business-to-consumer logistics in the country. The company has not disclosed the specific ransomware group responsible, nor the method of initial compromise. Restoration efforts are ongoing, but no timeline for full recovery has been provided. The disruption underscores the vulnerability of supply chain and logistics providers to ransomware attacks and the broad operational impact such incidents can have on dependent businesses. Both Askul and its partners are working to restore services, but the resumption date remains undetermined. The incident has prompted increased scrutiny of cybersecurity practices within Japan’s retail and logistics sectors.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Muji halted online sales after the ransomware attack on its logistics partner Askul disrupted fulfillment and related supply-chain operations. Reports described the impact as stemming from the supplier's compromised systems rather than a direct attack on Muji itself.
Following the ransomware incident, Askul suspended online order intake and shipment operations while responding to the disruption. The outage was significant enough to interrupt normal retail and logistics activity.
Japanese retailer and logistics provider Askul was hit by a ransomware attack that disrupted systems tied to order processing and shipping operations. The incident affected Askul's own e-commerce and fulfillment functions and had downstream impact on customers relying on its logistics services.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.