Asahi Group Holdings, Japan's largest brewing company, experienced a significant cyberattack that resulted in a system failure affecting its domestic operations. The company announced that the attack forced the suspension of order and shipment operations at its group companies within Japan, directly impacting its ability to distribute products and fulfill customer orders. In addition to halting logistics, Asahi also suspended its call center and customer service desk operations, leaving customers and business partners unable to access support or place new orders. The company emphasized that, as of the latest updates, there was no evidence of personal information or customer data being leaked to external parties. Asahi's international operations, including those in Europe and other regions, remained unaffected by the incident, with the disruption limited strictly to its Japanese business units. The company, which owns a portfolio of well-known beverage brands such as Peroni and Grolsch, reported over $9 billion in revenue for the first half of 2025, highlighting the potential scale of the operational impact. Asahi stated that it is actively investigating the cause of the system failure and working to restore normal operations, but it has not provided an estimated timeline for recovery. No ransomware group or cybercriminal organization has publicly claimed responsibility for the attack, and Asahi has not confirmed whether ransomware was involved. The incident comes amid a broader trend of cyberattacks targeting beverage and food manufacturing companies globally, with several high-profile breweries and distributors in other countries having faced similar disruptions in recent years. The domestic Japanese market is particularly significant for Asahi, accounting for approximately half of the company's profits, which underscores the seriousness of the operational shutdown. The company has issued public apologies for the inconvenience caused to customers and business partners and continues to provide updates as the investigation progresses. Industry observers note that the attack on Asahi is part of a growing pattern of cybercriminals targeting large, high-profile companies in the food and beverage sector. The company has not disclosed specific technical details about the nature of the attack or the vulnerabilities exploited. Asahi's swift action to suspend affected systems is seen as a precautionary measure to contain the incident and prevent further damage. The ongoing investigation will determine whether any additional security measures or disclosures are necessary as more information becomes available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting identified the cyberattack as ransomware, marking a clearer characterization of the intrusion than earlier disclosures. This represented an attribution update to the nature of the attack rather than just a generic systems failure.
As the disruption continued, reports said Asahi delayed product launches and halted deliveries, raising concerns about an impending beer shortage in Japan. The prolonged outage showed the incident was having broader supply-chain and market effects beyond the initial operational shutdown.
Following the attack, Asahi shut down domestic distribution and shipping systems and took its call center system offline while investigating the incident. The company said it was working to restore operations but did not provide a recovery timeline.
Asahi Group Holdings reported that a cyberattack caused a systems failure affecting its operations in Japan. The company said domestic production was interrupted and that the impact was limited to Japan, with no evidence of theft of customer personal data or commercial information.
15 references tracked. Mallory keeps watching after this page renders.
bbc.com
Open sourcebleepingcomputer.com
Open sourcesecurityboulevard.com
Open sourcebitdefender.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcego.theregister.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.