MalwareTips News Japan ransomware rise hits smaller firms as gangs expand tooling

Does your workplace require an extra verification step when you sign in remotely?

  • Yes, always

    Votes: 2 100.0%
  • Only for some services

    Votes: 0 0.0%
  • No

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%
  • I do not work remotely

    Votes: 0 0.0%

  • Total voters
    2

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
24
59
1
Ransomware incidents affecting Japanese organizations rose slightly in the first seven months of 2026, with 90 victims recorded. Smaller businesses faced most of the impact, while manufacturing remained the hardest-hit sector.

Smaller organizations bear most of the impact​

Cisco Talos counted 90 affected organizations from January through July, up 4.7% from 86 in the same period last year. April was the busiest month, with 19 incidents.

Organizations capitalized at less than JPY 1 billion made up 78% of known victims, an increase from 69% in 2025. Manufacturing accounted for 34% of incidents, ahead of information and communications at 11%.

  • Inventory internet-facing VPN, remote desktop and network devices, then disable services that are no longer needed.
  • Apply security updates promptly and plan replacements for devices that no longer receive vendor support.
  • Use multi-factor authentication for VPNs, cloud services, remote desktop access and administrator accounts.

The Gentlemen becomes the most observed group​

The Gentlemen was the most frequently observed ransomware group in Japan during the period, with 14 incidents. Qilin and SafePay followed with seven each.

The Gentlemen operates as ransomware-as-a-service, in which affiliates use a provider's ransomware and infrastructure. It practices double extortion by encrypting files and threatening to publish stolen information.

Its worldwide leak-site listings climbed from 48 in January to 105 in July. Listings are claims made by the gang and are not the same as independently verified incidents, but the increase indicates substantially higher activity.

Exposed infrastructure reveals attack methods​

Talos found an open directory believed to be connected to The Gentlemen. It contained ransomware for Windows and VMware ESXi systems, along with tools for finding systems, stealing credentials, moving through networks and transferring files.

Investigators also saw exploitation attempts involving CVE-2025-24799, an unauthenticated SQL injection flaw in the GLPI IT management platform. Evidence showed attackers examining backup shares, extracting credential data and transferring large VHDX backup files to cloud storage.


Qilin scripts show signs of AI assistance​

Talos assessed with medium-to-high confidence that several Python scripts in an open directory used by Qilin may have been generated with artificial intelligence. The clues included highly structured steps, consistent comments, documentation-style instructions and command history referencing a directory named “llm_chatbot.”

The scripts were designed for harmful tasks including distributing a wiper through Windows Group Policy, destroying Veeam backups and deploying ransomware across multiple computers. AI may have helped organize or produce the code, but the evidence does not establish that every part was AI-generated.