Japanese companies, including major manufacturers and retailers such as Asahi Holdings and Askul, have experienced prolonged operational disruptions following ransomware attacks. Asahi Holdings continues to face back-office issues and has acknowledged a potential data breach affecting 1.9 million individuals, while Askul only recently resumed partial operations after more than six weeks of downtime, with ongoing shipment delays. These incidents highlight the extended recovery periods for Japanese firms, especially when ransoms are not paid, and the broader impact on supply chains, as seen with Muji's halted sales due to Askul's outage.
Globally, the manufacturing sector has shown some improvement in defending against ransomware, with only 40% of attacks resulting in data encryption compared to 74% the previous year. However, data theft remains a significant risk, with 39% of affected manufacturers suffering data loss, and more than half still paying ransoms despite better defenses. The sector continues to face challenges such as skilled labor shortages, unknown vulnerabilities, and increased stress on IT and security teams, with nearly half reporting heightened pressure and a notable proportion experiencing leadership changes after attacks.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Online retailer Askul experienced a prolonged outage from a ransomware attack that disrupted its own business and also impacted other companies, including Muji. The incident illustrated the downstream operational effects of ransomware on Japanese supply chains.
Following the ransomware incident, Asahi Holdings acknowledged that personal data may have been compromised. The company said the potential breach could affect about 1.9 million people.
Asahi Holdings, a major Japanese food and beverage company, suffered a ransomware attack that disrupted operations. More than two months later, the company was still dealing with back-office system issues, indicating the attack likely occurred around early October 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.