Nidec Corporation disclosed that its Taiwanese subsidiary, Nidec Chaun Choung Technology Corporation, was hit by a ransomware attack that compromised and damaged servers, forcing the shutdown of affected systems and networks. The company said the incident was confirmed on 22 June and that investigators are assessing the impact on production, shipping, business operations, and whether personal or confidential information was exposed. Nidec added that the subsidiary operates on an independent network and said the attack did not affect Nidec Corporation or other Nidec Group companies.
A previously unknown ransomware group calling itself BlackField claimed responsibility and said it stole 2TB of data from the subsidiary’s IT environment. The group demanded $2 million to delete the data, offered a $5,000-per-day delay before publication, and advertised the full dataset for sale for $400,000, indicating a double-extortion operation. BlackField also reportedly posted sample file structures and documents as proof of theft, although the authenticity of those materials had not been independently verified.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A previously unknown ransomware group calling itself BlackField claimed responsibility for the intrusion, saying it stole 2 TB of data from the subsidiary's IT network. The group demanded $2 million to avoid publication, offered a $5,000-per-day delay option, advertised the full dataset for sale at $400,000, and published sample file structures and documents as proof of theft.
Nidec Corporation confirmed that its Taiwanese subsidiary, Nidec Chaun Choung Technology Corporation, suffered a ransomware attack that compromised and damaged servers, prompting emergency shutdowns of affected servers and networks. The company began investigating possible impacts on production, shipping, business operations, and whether personal or confidential information was exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.