Japan's National Police Agency (NPA) has confirmed 123 ransomware cases between January and June 2026, the highest half-year total the agency has recorded. The figure is up seven cases from the same period a year earlier, and of the total, 31 incidents struck major companies. Fraud-related losses tied to these attacks reportedly jumped 45%, reaching roughly 176 billion yen. For a country long considered a secondary target compared to the United States and Western Europe, the numbers mark a clear turning point.
A Deliberate Shift, Not a Statistical Blip
According to analysis from security firm Forescout, Japan climbed from the 28th most-targeted country for ransomware to 14th in a matter of months. A jump of that magnitude rarely happens by accident. Ransomware groups operate like businesses: they follow the money and gravitate toward soft targets, and reallocating criminal attention on this scale usually reflects a strategic decision rather than random noise in the data.
Forescout's research identifies several groups as the most active against Japanese organizations during the January-to-April 2026 window: Qilin, The Gentlemen, Everest, Night Spire, and Inc Ransom. These are largely the same double-extortion crews that have been causing disruption across other regions, suggesting that Japan has become the newest stop on a broader campaign rather than the target of a uniquely Japan-focused operation. Double-extortion tactics, in which attackers both encrypt data and threaten to leak it, have become the default playbook for groups that want to maximize pressure on victims to pay.
Why Japanese Organizations Became Attractive Targets
Several structural factors likely make Japanese enterprises appealing right now. Many organizations, particularly small and mid-sized manufacturers and suppliers embedded in global supply chains, run legacy infrastructure that has not kept pace with modern threat detection. Regulatory and compliance frameworks in Japan have also historically emphasized different risk categories than the ransomware-specific defenses (like rapid detection and segmentation) that matter most today. Combine that with a corporate culture in some sectors that has been slower to invest in continuous security monitoring, and you get an environment where attackers can move with less resistance.
This pattern fits into a broader trend across the region. Ransomware operators have increasingly moved away from painstakingly researching a single high-value target and toward what one recent industry report described as "area suppression" of small and mid-sized business networks: casting a wide net across SME networks rather than pursuing one company at a time. That shift in tactics helps explain why the number of Japanese cases jumped so sharply in a single half-year period. Attackers are not necessarily working harder on each target; they are hitting more targets at once, and Japan's mix of large exposed supply chains and less-hardened smaller firms makes it a productive hunting ground.
What This Means For You
If you work for or run a business with any operational ties to Japan, whether as a supplier, subsidiary, or partner, this data should prompt a review of your own exposure, not panic. The same double-extortion groups named in Forescout's analysis have targeted organizations well beyond Japan, so the practical defenses that matter are the same ones security professionals have recommended for years: they just need to actually be implemented.
Start with network segmentation so that a single compromised endpoint cannot cascade into a company-wide encryption event. Maintain offline, tested backups that are not accessible from the same network as production systems, since ransomware groups increasingly target backup infrastructure directly. Monitor for unusual authentication activity and lateral movement rather than relying solely on perimeter defenses. And if your organization has any presence in the Asia-Pacific region, treat threat intelligence feeds tracking groups like Qilin, Everest, and Inc Ransom as operationally relevant, not just background reading.
The Bigger Picture for Asia-Pacific Security
Japan's record half-year is unlikely to be an isolated data point. Ransomware crews rotate their attention based on which regions offer the best combination of valuable data, willingness to pay, and weak defenses. As Western targets harden their infrastructure and law enforcement cooperation improves, attackers have every incentive to test less-prepared markets. Japan's jump from 28th to 14th in target rankings should be read as a signal that other Asia-Pacific economies with similar characteristics, aging infrastructure, dense supply chains, and uneven compliance enforcement, could see comparable spikes in the coming quarters.
The practical takeaway is straightforward: ransomware defense is not a one-time project but an ongoing commitment. Organizations that treat backups, segmentation, and monitoring as continuous priorities rather than checkbox exercises will be far better positioned to withstand this next wave, wherever it lands next.
Actionable takeaways:
- Audit backup systems to confirm they are offline, encrypted, and regularly tested for recovery, not just for storage.
- Review network segmentation to limit how far an attacker can move after an initial breach.
- Subscribe to threat intelligence covering active groups like Qilin, Everest, Night Spire, and Inc Ransom if your organization operates in or with Asia-Pacific partners.
- Treat any sudden increase in regional targeting data as a prompt to reassess your own risk posture, not just a headline to skim past.




