A ransomware attack against a SoftBank-owned cloud provider in Japan has affected 495 companies and local governments, and the impact is expanding beyond the original infrastructure outage.
JR East has now disclosed approximately 6.09 million potentially exposed customer records across its group. Nissui, which operates major U.S. seafood businesses including Gorton’s, has confirmed disruptions to its Japanese logistics subsidiary. No direct U.S. disruption has been established.
The next development to watch is which additional customers disclose incidents as investigations continue.
John Watters, Founder & CEO, iCOUNTER | Former President & COO, Mandiant Said This:
“One ransomware attack against a cloud provider in Japan has put 495 companies and local governments at risk, with JR East already reporting approximately 6.09 million potentially exposed customer records. And this story is far from over. As more organizations investigate their exposure, we should expect additional disclosures that reveal just how far a single attack can reach.
This isn’t just a Japan problem. It’s a warning to American businesses about the dependencies hiding inside their supply chains. Nissui, one of the affected organizations, has significant U.S. operations, illustrating how interconnected these ecosystems have become, even though no impact on its American operations has been confirmed.
What concerns me most is that many organizations won’t know they’re exposed until a vendor tells them. By then, critical decisions about data protection, business continuity, and recovery may already be overdue.
Every CISO should be asking three questions right now: Which of our vendors and their suppliers depend on the affected infrastructure? Is our data exposed? And what is our response plan if those services go down?
Traditional third-party risk assessments tell you whether a vendor met security requirements at a point in time. They don’t tell you when that vendor, or a supplier behind it, is actively under attack.
The next breach notification shouldn’t be the first time you discover your organization was at risk. Security teams need to identify threats across their extended ecosystem, determine what matters to their business, and act before a supplier’s incident becomes their own.”
With everything being interdependent on everything else, you’re only as secure as the guy next to you. Thus need to make sure that the guy next to you is secure to your standards and not theirs.
Related
This entry was posted on October 9, 2026 at 2:00 pm and is filed under Commentary with tags Japan. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
From a Japanese cloud outage to Gorton’s parent company: the hidden supply chain risk for U.S. firms
A ransomware attack against a SoftBank-owned cloud provider in Japan has affected 495 companies and local governments, and the impact is expanding beyond the original infrastructure outage.
JR East has now disclosed approximately 6.09 million potentially exposed customer records across its group. Nissui, which operates major U.S. seafood businesses including Gorton’s, has confirmed disruptions to its Japanese logistics subsidiary. No direct U.S. disruption has been established.
The next development to watch is which additional customers disclose incidents as investigations continue.
John Watters, Founder & CEO, iCOUNTER | Former President & COO, Mandiant Said This:
“One ransomware attack against a cloud provider in Japan has put 495 companies and local governments at risk, with JR East already reporting approximately 6.09 million potentially exposed customer records. And this story is far from over. As more organizations investigate their exposure, we should expect additional disclosures that reveal just how far a single attack can reach.
This isn’t just a Japan problem. It’s a warning to American businesses about the dependencies hiding inside their supply chains. Nissui, one of the affected organizations, has significant U.S. operations, illustrating how interconnected these ecosystems have become, even though no impact on its American operations has been confirmed.
What concerns me most is that many organizations won’t know they’re exposed until a vendor tells them. By then, critical decisions about data protection, business continuity, and recovery may already be overdue.
Every CISO should be asking three questions right now: Which of our vendors and their suppliers depend on the affected infrastructure? Is our data exposed? And what is our response plan if those services go down?
Traditional third-party risk assessments tell you whether a vendor met security requirements at a point in time. They don’t tell you when that vendor, or a supplier behind it, is actively under attack.
The next breach notification shouldn’t be the first time you discover your organization was at risk. Security teams need to identify threats across their extended ecosystem, determine what matters to their business, and act before a supplier’s incident becomes their own.”
With everything being interdependent on everything else, you’re only as secure as the guy next to you. Thus need to make sure that the guy next to you is secure to your standards and not theirs.
Share this:
Like this:
Related
This entry was posted on October 9, 2026 at 2:00 pm and is filed under Commentary with tags Japan. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.