Japan’s record ransomware half-year is a supplier problem, and the two counts of it disagree
Police recorded 123 cases; Cisco Talos recorded 90 organisations. Both show the same shift: the victims are small manufacturers, and most of them sit outside every reporting regime built to make incidents visible.

Two counts, one direction
Japan's National Police Agency recorded 123 ransomware cases in the first half of 2026, the highest half-year figure on record [1]. The breakdown matters more than the total: 79 cases at small and medium enterprises, 31 at large corporations and 13 at other organisations, with manufacturing the most affected sector at 37 cases [1]. The NPA identified virtual private network equipment as the most common infection pathway, and reported 13,687 suspicious access attempts per IP address per day, over four thousand more than the previous year [1]. The agency's own decryption tooling recovered 20.11 million files [1].
Cisco Talos published a separate count on 17 September 2026, recording 90 organisations affected between January and July 2026, up about 4.7% from 86 in the equivalent 2025 period [2]. Roughly 80% of those victims were companies with capital under one billion yen, up from 69% a year earlier, and 48% had capital under one hundred million yen [2]. Manufacturing accounted for 34%, information and communications 11% and services 9% [2].
The two figures are not reconcilable and should not be averaged. The NPA counts cases reported to police over January to June; Talos counts organisations it observed over January to July, including 13.3% of cases involving overseas entities [1][2]. One measures what victims told the authorities. The other measures what researchers could see. That they move in the same direction, and agree on the victim profile, is the useful part.
The victims are in the supplier tier
Both datasets say the same thing about who is being hit. Japanese ransomware in 2026 is concentrated in small manufacturers — the companies that supply larger manufacturers. Talos records the shift year on year: the share of victims below one billion yen in capital rose by roughly thirteen points in twelve months [2]. That is not a change in criminal intent so much as a change in where the reachable attack surface is, and the NPA's identification of VPN equipment as the leading pathway is consistent with it [1].
Sophos's 2026 survey of 2,158 security and IT leaders across seventeen countries, covering organisations of 100 to 5,000 employees, found only about one in three smaller organisations stopped an attack before encryption, against 56% of attacks succeeding in encrypting data overall, with a median ransom payment of US$769,000 and average recovery cost of US$1.7 million [3]. Those are survey figures from a vendor's customer-adjacent sample, not population statistics, but the size effect they describe matches what the Japanese counts show.
Mandiant's M-Trends 2026, drawn from over 500,000 hours of investigation in 2025, gives the mechanism that makes a supplier tier attractive: prior compromise accounted for 10% of initial infections overall and 30% in ransomware cases specifically, and the median window between initial access and hand-off to a second group fell from more than eight hours in 2022 to 22 seconds in 2025 [4]. Access to a small supplier is inventory. It is sold, and it is sold quickly.
The group in the Japanese data, and the problem with counting it
Talos names The Gentlemen as the most active group in its Japanese set with 14 confirmed incidents, ahead of Qilin and SafePay at 7 each, and records the group's leak-site listings rising from 48 in January to 105 in July, roughly a 2.2-fold increase [2]. Talos observed the group using the AdaptixC2 framework alongside RustHound, Responder, Ligolo-ng, Chisel and Rclone, with exfiltration to cloud storage, and assesses on the basis of Cyrillic artefacts in scripts that a Russian-speaking individual was involved [2]. Talos separately assesses with medium-to-high confidence that several Qilin scripts show indicators of AI generation, including structured workflow comments and a reference to an LLM tool in command history [2]. Both are the researchers' assessments and are reported here as such.
Totals for the group diverge sharply between vendors. Unit 42 recorded 580 claimed victims across 77 countries to 7 July 2026, including 103 in manufacturing, a sixfold increase between the second half of 2025 and the first half of 2026, and a June 2026 peak of 117 claimed victims [5]. Halcyon, publishing in April 2026, recorded close to 300 organisations across more than 66 countries since mid-2025, with 48 attacks in January 2026 and 91 in February [6]. The gap is mostly window and method, but it is a reminder that leak-site totals measure posting behaviour. Microsoft's May 2026 analysis of the group's encryptor describes aggressive parallel lateral movement — 21 remote execution operations per target host across multiple APIs and privilege levels — with backup services and hypervisor processes terminated and shadow copies deleted before encryption [7]. Unit 42 dates the operation's emergence to July 2025, with operators likely active earlier as an affiliate of Qilin, and notes an unusually high affiliate payout [5].
Unit 42's 2026 incident response data adds the timing that determines whether any of this is survivable: the fastest quarter of intrusions reached data exfiltration in roughly 72 minutes, against 285 minutes in 2024, identity weaknesses featured in close to 90% of investigations, and encryption appeared in 78% of extortion cases, down from over 90% [8].
The regional reading
Malaysia's exposure is structurally similar and considerably less visible. The Cyber Security Act 2024 came into force on 26 August 2024 and places duties on designated national critical information infrastructure entities and their sector leads [9]. Electrical and electronics suppliers, contract manufacturers and logistics firms in the same tier as Japan's affected companies are, for the most part, not NCII entities, so an incident there generates no statutory report and no national statistic. The Cybercrime Bill tabled on 22 June 2026, which repeals the Computer Crimes Act 1997 and carries 61 clauses covering ransomware and AI-related offences, is a prosecution instrument rather than a reporting instrument [10]. PwC's Malaysian threat assessment recorded 16 Malaysian victims posted to leak sites between January and May 2025 against 19 for the whole of 2024 [11] — a low number, from the one source that captures victims who never report anything.
What to do
- Treat a supplier's ransomware event as your own availability incident and plan for it explicitly. Single-source components and sole-supplier tooling are where the outage lands [2][4].
- In supplier assurance, ask for two specific things rather than a certification: evidence of a patching cadence for internet-facing VPN and edge devices, and evidence that backups are isolated from the production directory [1][7].
- Assume prior compromise. Where a supplier has had an incident, credential reuse and retained access are the follow-on risk, not the encryptor [4].
- Stop reading leak-site counts as incidence. Use them for relative activity between groups, and use police or regulator figures for scale, saying which you used [5][6].
- Measure your own detection against the exfiltration window rather than the encryption event. Seventy-two minutes is the planning figure for the fastest quartile [8].
- If you are a small manufacturer, the two controls that change the outcome are edge device patching and an offline restore you have actually tested [1][3].
The domain point
The reporting instruments built over the last three years — NCII duties, sector regulators, national CERT statistics — point at large organisations, because that is where systemic risk was assumed to sit. The Japanese data says the volume has moved below that line, into a supplier base that has no reporting duty, no security function and, in many cases, no way to restore. Malaysia and the wider region have the same industrial structure and less measurement of it. Anyone building a threat picture for ASEAN manufacturing should assume the published numbers are a floor set by who is obliged to speak, and should source the rest from their own supplier base directly.
Sources
Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.
- Ransomware attacks in Japan hit record 123 cases in 1st half of 2026 (National Police Agency data) Japan Today · 2026-09-14
- Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen's infrastructure and evidence of Qilin's AI use Cisco Talos · 2026-09-17
- The State of Ransomware 2026 Sophos · 2026
- M-Trends 2026: Data, Insights, and Strategies From the Frontlines Mandiant / Google Cloud · 2026-03-23
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomware Unit 42, Palo Alto Networks · 2026-07-10
- Threat Assessment: The Gentlemen Ransomware Group Halcyon · 2026-04
- The Gentlemen ransomware: Dissecting a self-propagating Go encryptor Microsoft Threat Intelligence · 2026-05-28
- 2026 Unit 42 Global Incident Response Report Unit 42, Palo Alto Networks · 2026-02
- Cyber Security Act 2024 (Act 854) National Cyber Security Agency (NACSA), Malaysia · 2024-08-26
- Govt tables Cybercrime Bill in Parliament to replace outdated computer crimes law, cover AI offences Malay Mail · 2026-06-22
- Charting cyber threats: A strategic outlook for businesses in Malaysia PwC Malaysia · 2025-07-03
Researched and written by the R3KONX analysis desk from the primary material cited below. The two Japanese counts compared here use different collection methods, units and reporting windows and are presented as such rather than reconciled. Leak-site victim counts are claims made by criminal groups and are treated as a measure of posting behaviour, not of incidence. Attribution statements are reported as the named researchers' assessments. Corrections to event@r3konx.asia.
