deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Ransomware took down IDCF Cloud for 495 organizations, and off-platform backups decided who recovered

A ransomware attack knocked IDCF Cloud offline for 495 contracted organizations, and recovery came down to one question: did a usable backup exist outside the provider's own infrastructure?

Ransomware took down IDCF Cloud for 495 organizations, and off-platform backups decided who recovered

Ransomware took IDCF Cloud offline

In the early hours of October 7, 2026, monitoring alerts flagged trouble in IDCF Cloud's East Japan Region 1: a third party had gained unauthorized access to part of the platform. According to a write-up on dev.to that reconstructs the incident from IDC Frontier announcements and Japanese media coverage, servers at the affected data center lost power around 4:00 a.m., SoftBank had notified Ibaraki Prefecture by 8:00 a.m., and a first public notice went out at 1:52 p.m. acknowledging unauthorized access. A second statement at 8:18 p.m. identified the cause as ransomware and put the number of affected customers, contracted companies and local governments, at 495.

IDCF Cloud is operated by IDC Frontier, a subsidiary of SoftBank. The company said it had cut the network and deactivated systems while working to identify the intrusion path and determine whether personal information leaked. As of the afternoon of October 8, per the dev.to post, services had not been restored, no recovery timeline existed, and several government sites were still returning 503 errors. Images claiming to come from the attackers spread on social media, asserting that data had been encrypted and snapshots destroyed. IDC Frontier said it was still verifying those claims, and any figures in them remain unverified attacker assertions rather than confirmed damage.

The blast radius

Because many unrelated organizations shared one segment of one cloud, a single attack stopped services across industries and regions simultaneously. Among public institutions, the dev.to write-up lists the websites of Ibaraki Prefecture, the Ibaraki Prefectural Police and the Ibaraki Prefectural Assembly, the Tochigi Prefecture event calendar, the entire Kodaira City site in Tokyo, and three food-related Shiga Prefecture sites operated through contractors. Residents could no longer download forms needed for prefectural procedures, and staff had to handle requests individually by phone. The mechanisms local government relied on to reach residents were broken by an attack on a private provider.

On the corporate side, reported effects included Nissui Logistics halting shipping and receiving at 17 facilities; Six Apart losing connection to 31 servers running the cloud edition of Movable Type; Soliton's SecureDesktop Center going down along with backup servers hosted on the same infrastructure; and UD Talk's public features and management tools stopping, with data recovery described as difficult. Disruptions were also reported at Poppins (reservations and staff scheduling), Fibergate (resident Wi-Fi authentication, email and a management site), Media Link (phone forwarding and incoming calls) and the Japan Badminton Association's official site. Further outages, including at Tagajo City, Tokyo University of Agriculture and Technology, Holy Mary University Hospital, Shimizu Pulse, Kyoto Sanga F.C. and Tobu Animal Park, occurred around the same time, though the write-up notes it has not been confirmed whether those organizations used IDCF Cloud.

What separated the recoverable from the rest

The sharpest contrast in the aftermath, the dev.to post argues, is between organizations that kept a copy of their data outside the provider and those that did not. Six Apart had backups on Google Cloud and used them to migrate its 31 machines to Sakura Cloud. Soliton, whose backup servers sat on the same foundation as its production systems, lost both at once. UD Talk, facing data that is hard to recover, is rebuilding on a different cloud entirely.

The mechanism matters. Snapshots stored inside the same infrastructure are often managed under the same administrative privileges as the primary data, so an attacker who seizes those credentials can delete originals and backups together. That matches how modern ransomware typically operates: initial access through a VPN vulnerability, stolen password or phishing; privilege escalation; destruction of backups before anything else; then encryption, often paired with double extortion threats to publish stolen data. IDC Frontier has not yet confirmed the entry point or tactics used in this specific incident.

Why it matters

Cloud convenience is built on sharing, and sharing means correlated failure: when the platform goes, everyone on that segment goes with it, including prefectures, police and logistics operations whose obligations do not pause. The practical lesson for anyone running systems on managed infrastructure is to assume the provider itself can become unavailable, through attack or accident. A backup that lives in the same account, region or administrative domain as production is not a backup against this class of threat. What counts is a copy somewhere else, under separate credentials, that someone has actually tested restoring from.

  • #ransomware
  • #cloud
  • #backups
  • #outage
  • #security

Related posts