Asahi Group Holdings, Japan's largest brewing company, suffered a significant ransomware attack in September that disrupted its Japanese operations and led to the exposure of personal data belonging to nearly 2 million individuals. The Qilin ransomware group claimed responsibility, stating it had stolen 27 GB of internal files, including employee records, contracts, and financial documents. The breach affected 1.525 million customer service contacts, 114,000 external contacts, 107,000 current or former employees, and 168,000 family members, with exposed data including names, addresses, phone numbers, email addresses, and in some cases, dates of birth and gender. Credit card information was reportedly not compromised. The attack forced Asahi to suspend order processing, shipments, and customer service operations in Japan, though international branches were not impacted.
The attackers gained access via compromised network equipment at a Japanese datacenter, deploying ransomware that encrypted data on multiple servers and connected PCs. Asahi responded by isolating the datacenter within hours and has since pledged to notify all affected individuals. While some stolen data was found online, the company continues to investigate the full scope of the breach. The incident highlights the operational and reputational risks posed by ransomware attacks, especially when large volumes of sensitive personal data are involved.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
By late November, Asahi said it had isolated the affected datacenter within hours of the attack and was restoring systems cautiously in phases while implementing stronger security measures and external reviews. Shipments were resuming gradually, but reporting indicated logistics might not be fully restored until February.
In a detailed impact assessment published on November 27, Asahi said the ransomware incident likely exposed personal data associated with roughly 1.5 million to nearly 2 million people, including customer-service contacts, message recipients, employees, retirees, and employees' family members. The company said exposed data included contact and limited demographic information, but not credit card data.
The ransomware incident disrupted accounting systems badly enough that Asahi's full-year earnings report for the fiscal period ending December 31 was delayed by more than 50 days. The delay reflected the continuing business impact of the September attack.
After the attack, the Qilin ransomware group claimed responsibility, alleging it stole 27GB of data and published samples on its Tor leak site. Asahi said it had not confirmed publication of certain server-stored personal data, though some reports said stolen data was later found online.
Asahi publicly confirmed on October 3 that the September incident was a ransomware attack. The company began disclosing the operational impact and recovery efforts tied to the breach.
Following the September 29 incident, Asahi suspended operations at its Japanese branch and shifted some processes to manual handling. Ordering, shipping, call center, production, logistics, and accounting functions were disrupted.
In late September 2025, attackers accessed Asahi's environment through compromised network equipment at a group site in Japan and deployed ransomware across multiple servers and some PCs the same day. The intrusion affected Japan-managed systems and disrupted core business operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetechrepublic.com
Open sourcetherecord.media
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.