Japanese police reported 226 ransomware incidents in 2025, the second-highest annual total on record and four more than the previous year, with roughly 60% of victims identified as small and midsize businesses. The National Police Agency said prolonged disruption was associated with higher recovery costs, while major enterprises were also affected, including Asahi Group Holdings and Askul. Among the 149 cases where malware families were identified, Qilin was the most common with 32 cases, followed by LockBit with 19; 8Base appeared only once, reflecting the impact of international law-enforcement action and the availability of a recovery tool.
Regional reporting also showed Qilin active outside Japan, including attacks on a South Korean dermatology clinic and the Korean branch of a global advertising company, underscoring the group’s continued presence in East Asia. One other article in the set describes a dramatic “printer” compromise at an unnamed business, but it appears to be a standalone blog narrative about a different and unverified incident rather than the same reported ransomware trend. Overall, the relevant reporting points to sustained ransomware pressure on both SMBs and larger organizations, with Qilin remaining a prominent threat actor/toolset in the region.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Talos published a report on ransomware threats in Japan during 2025, identifying Qilin as the most active group in its dataset and estimating ransomware execution occurred about six days after initial compromise on average. The report also released 12 Sigma rules, YARA rules, ClamAV signatures, Snort detections, and IOCs to help defenders detect and disrupt Qilin activity before deployment.
ASEC reported that root access to a South Korean government server was being advertised for sale on BreachForums in its Week 2 March 2026 dark web monitoring summary.
ASEC reported that an elevator manufacturer in South Korea was targeted in an Everest ransomware attack highlighted in its Week 2 March 2026 roundup.
ASEC's Week 2 March 2026 report described a KillSec ransomware attack affecting a South Korean exhibition management platform.
ASEC reported that the Korean branch of a global advertising company was targeted in a Qilin ransomware incident noted in its Week 2 March 2026 report.
ASEC reported that a well-known dermatology clinic in South Korea was listed as a victim of the Qilin ransomware group in its Week 2 March 2026 roundup.
A Nippon.com report stated that 226 ransomware attacks were reported in Japan in 2025, marking the scale of ransomware activity disclosed for that year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcenippon.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.