Japanese e-commerce company Askul Corporation suffered a ransomware attack attributed to the RansomHouse group, resulting in the theft of approximately 740,000 customer, business partner, and employee records. The breach, discovered in October, led to significant IT system failures, disrupting shipments to customers including major retailers. Askul confirmed that the attackers exploited compromised credentials for an outsourced partner’s administrator account, which lacked multi-factor authentication, to gain initial access. The company has notified affected individuals and Japan’s Personal Information Protection Commission, and is implementing long-term monitoring to prevent misuse of the stolen data.
The stolen data includes around 590,000 records from business customers, 132,000 from individual customers, 15,000 from business partners, and 2,700 from executives and employees. Askul stated that no credit card information was confirmed to be leaked and that no ransom was paid. The RansomHouse group publicly claimed responsibility, adding Askul to its leak site and releasing data in multiple stages. As of mid-December, Askul’s order shipping operations remain impacted while system restoration efforts continue.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Following its disclosure, Askul said it notified affected individuals and organizations and reported the incident to the Personal Information Protection Commission. The company also said it was implementing stronger security controls, long-term monitoring, and business continuity improvements.
Askul stated that Lohaco's payment system was not affected because it does not store credit card information, and that no individual customers' credit card data was leaked. The company also said it had not paid a ransom to the attackers.
By mid-December 2025, Askul disclosed that approximately 740,000 data sets were compromised, including about 590,000 tied to its corporate office supplies service and around 130,000 linked to its Lohaco consumer e-commerce service. The exposed data affected customers, corporate clients, employees, partners, and executives.
In November 2025, RansomHouse added Askul to its dark web leak site and began publishing evidence packs, with additional leaked material released in December. The group claimed to have stolen about 1 TB of sensitive data after failed negotiations or non-payment.
The October attack caused major IT and logistics failures at Askul, including disruption to automated logistics and order systems and shipment delays affecting customers such as Muji. Askul's systems remained under restoration afterward, with some shipping delays and financial reporting impacts continuing into December.
On 2025-10-19, attackers attributed to RansomHouse accessed Askul's environment through an outsourced partner's administrator account that lacked multi-factor authentication. They conducted reconnaissance, harvested additional credentials, disabled security tools, deleted backups, and deployed ransomware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcebleepingcomputer.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.