Skip to content
Residential technology help and small-business ITOwner-led. Clearly scoped. Salem County based. 609-202-2208
Cyber News

Talos report finds ransomware activity still high in Japan

Cisco Talos reported 90 organizations in Japan affected by ransomware from January through July 2026. Smaller organizations made up most of the observed victims, with remote access and stolen accounts among the concerns.

Published September 17, 2026 Updated September 20, 2026 7 min read
Talos report finds ransomware activity still high in Japan

Cisco Talos reported 90 organizations in Japan affected by ransomware from January through July 2026. Smaller organizations made up most of the observed victims, with remote access and stolen accounts among the concerns.

In 60 seconds

  • Organizations in Japan and businesses linked to Japanese offices should review remote access and important accounts.
  • Talos reported 90 Japanese organizations affected from January through July 2026 and compared that with 86 reported incidents in 2025.
  • Organizations with capital below JPY 1 billion represented about 78% of observed victims, excluding unknown-size organizations.
  • Today, list outside entry points and turn on multifactor sign-in for remote and administrator accounts.

Who should care and what to do today

The report is most relevant to organizations in Japan and to businesses with Japanese offices, subsidiaries, vendors, or cloud connections. Manufacturing companies were the largest industry group in the study, but Talos also observed affected organizations in services, education, health care, finance, retail, construction, and other fields.

If you manage a small business, school, library, or local office, ask which virtual private network (VPN), remote desktop service, cloud account, and internet-facing management page your organization uses. A VPN is a protected connection that lets someone reach a private network from outside. Your technology provider or administrator should be able to show which services are exposed to the internet.

Make one useful check today: list every outside entry point and the accounts that control it. Then turn on multifactor authentication, which adds a second sign-in step such as an app code, for VPN, cloud, remote desktop, and administrator accounts where available.

Do not download random security tools, run unfamiliar commands, or shut down business systems based only on this report. Talos did not identify one product that every reader needs to replace.

What Cisco Talos reported

Cisco Talos reported 90 organizations in Japan affected by ransomware from January through July 2026. The source compares that figure with 86 reported incidents during the same period in 2025 and describes the change as an increase of about 4.7%. Because the source uses organizations in one figure and incidents in the comparison, those terms should not be treated as identical.

Talos recorded about 13 observed cases per month on average, with April the highest month at 19. Organizations with capital below JPY 1 billion represented about 78% of observed victims when organizations of unknown size were excluded. The largest single group had capital below JPY 100 million, at 48%.

Manufacturing accounted for 34% of the observed cases. Information and communications accounted for 11%, while services accounted for 9%. These figures describe Talos’s observations. They are not a count of every ransomware attack in Japan or a prediction about one company’s risk.

The groups and techniques described in the report

Talos identified The Gentlemen as the most active ransomware group in Japan during the period, with 14 observed incidents. Qilin and SafePay each had seven. Talos also listed NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock among the groups it observed.

Ransomware is malicious software that can lock an organization’s files while attackers demand payment. Talos said The Gentlemen used a double-extortion approach: stealing information as well as encrypting data, then threatening to publish the stolen information. Listings on the group’s leak site rose from 48 in January to 105 in July, about 2.2 times as many.

Talos’s investigation found signs of attacks aimed at Windows and ESXi environments. ESXi is software used to run several virtual computers on one physical server. The investigation also found activity involving exposed services, VPNs, remote access, stolen credentials, and weaknesses in internet-facing systems.

The report says scripts found in an environment linked to Qilin showed signs, with medium-to-high confidence, of being made with artificial intelligence. That finding concerns tools in the investigated environment. It does not mean ordinary artificial-intelligence software is itself a ransomware infection.

Account, access, and backup checks

Talos recommends keeping an inventory of internet-accessible devices and services, including VPN and remote desktop systems. Unused services should be disabled, supported systems should be patched promptly, and unsupported equipment should be replaced through a planned process.

Review unused and shared accounts, separate everyday work accounts from administrator accounts, and give administrative access only where needed. Limit vendor access to the smallest necessary scope and, where possible, to a defined time period. Keep connection records so unusual access can be investigated.

The report contains two separate backup-related findings. In its investigation of The Gentlemen’s infrastructure, Talos described an actor inspecting VHDX backup files. In a separate section about Qilin, it found code designed to stop, disable, and destroy Veeam backups. The findings should not be treated as one operation or as proof that every organization using these backup tools was affected.

Talos also recommends watching for suspicious remote access, new administrator privileges, disabled backups, and large-scale file changes. These are general safeguards from the report, not instructions to install a particular product.

Does this affect me?

Who may be affected
Organizations in Japan, and businesses connected to Japanese offices, subsidiaries, vendors, or cloud services, should care most. Small and midsize organizations are especially relevant because they represented about 78% of observed victims in Talos’s data. Home users are not shown to be directly affected by this report.
How to check
Ask your technology provider or administrator for a current list of VPN, remote desktop, cloud, and internet-facing management services, plus the accounts that can reach backups and important files.
What to do
Turn on multifactor authentication for VPN, cloud, remote desktop, and administrator accounts, then remove unused or shared accounts where practical.
What to avoid
Do not assume the report names a product you must replace, and do not run unverified commands or install unfamiliar tools in response to the research.

Common questions

Does this mean my home computer has ransomware?

No. Talos reported organizations affected in Japan, not infections on every home computer. If your device shows locked files, ransom notes, or unusual access, disconnect it from shared networks and contact a trusted technician or your organization’s support team rather than experimenting with tools.

Why are small businesses a focus of this report?

Organizations with capital below JPY 1 billion made up about 78% of the observed victims, excluding organizations of unknown size. That does not show that company size caused the attacks, but it does show that smaller organizations appeared often in Talos’s data.

Which accounts should use multifactor authentication first?

Start with accounts that can enter the network or reach important data: VPN, cloud administration, remote desktop, email administration, and backup management. Talos specifically recommends multifactor authentication for VPN, cloud, remote desktop, and administrator accounts.

Did Talos name a software flaw that every reader needs to patch?

No. The report describes several tools and attempted exploits seen during its investigations, but it does not name one product or version that applies to every reader. Check the security notices for the products your organization actually exposes, and have the person who manages them apply needed updates.

Primary source

This article is based only on Cisco Talos, “Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use,” published September 17, 2026: https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/. The article reports 90 affected organizations and separately compares the period with 86 reported incidents in the same period of 2025. Read the complete original source.

Need help deciding what this means for your business?

Leon can help identify the affected systems and a proportionate next step.

Explore small-business IT help

Article history: Published Sep 17, 2026 at 6:21 am EDT. Updates and corrections are noted here when material facts change.