Ransomware attacks against organizations in Japan climbed 4.7% year over year during the first half of 2026, according to new threat intelligence research. The report identifies The Gentlemen as the most active ransomware group operating against Japanese targets, while a rival operation called Qilin appears to be incorporating artificial intelligence into its attack workflow. Small and medium enterprises absorbed the overwhelming majority of the damage, a pattern that continues to reshape who needs to worry about ransomware and why.

The Gentlemen's Rapid Rise on Leak Sites

The research singles out The Gentlemen as the single most prolific ransomware group targeting Japanese organizations in the first half of 2026, with 14 documented incidents tied to the group. What stands out is the pace of growth: listings on the group's dark web leak site more than doubled between January and July. Leak sites are where ransomware operators post stolen data from victims who refuse to pay, both as proof of a breach and as pressure to extract payment. A rapid increase in listings suggests The Gentlemen expanded its target list, improved its intrusion techniques, or both over a relatively short window.

Investigators looked closely at the infrastructure behind The Gentlemen's operations, a step that matters because understanding how a group hosts its leak sites, manages command-and-control servers, and negotiates with victims often reveals patterns that help defenders anticipate future attacks rather than simply react to them after the fact.

Qilin's Second Place Finish and Signs of AI Assistance

Qilin ranked as the second most active group targeting Japanese organizations, but the more notable finding is evidence that the group may be using AI tools somewhere in its operations. The original research does not specify exactly which stage of the attack chain involves AI, but the broader implication is significant. Ransomware groups have historically relied on manual reconnaissance, custom scripting, and human negotiators. If AI is now assisting with any part of that process, whether it's identifying valuable targets, crafting more convincing phishing lures, or automating negotiation chatter, it could allow smaller criminal crews to operate with the efficiency once reserved for well-resourced groups.

This mirrors a trend already covered in Cisco Talos' broader analysis of Japan's ransomware surge, which found that overall attack volume rose even as the number of active groups shifted. AI-assisted operations, if confirmed, would help explain how attackers sustain high output without a proportional increase in headcount.

Small Businesses Remain the Primary Target

Perhaps the most consequential statistic in the report is that organizations with capital under JPY 1 billion, roughly the threshold Japan uses to classify small and medium enterprises, accounted for 80% of all ransomware victims in the first half of 2026. That figure underscores a trend security researchers have flagged for years: attackers increasingly favor smaller organizations that often lack dedicated security teams, mature backup practices, or the budget for advanced monitoring tools.

SMEs are attractive targets precisely because they can be just as lucrative as larger firms, especially if they hold sensitive customer data or serve as suppliers to bigger companies, while offering far less resistance. The same coverage of Japan's H1 2026 ransomware data notes that this imbalance places a disproportionate burden on businesses least equipped to absorb it.

What This Means For You

If you run or work for a smaller business in Japan, or anywhere with a similar SME landscape, this report is a direct signal that ransomware groups see you as a viable target, not an afterthought. The Japan ransomware attacks documented in this period were not isolated incidents; they reflect an active, evolving criminal ecosystem that is scaling its operations, potentially with AI assistance, while continuing to prioritize organizations with limited defenses.

For individual employees and customers of affected organizations, the risk extends beyond the business itself. Leaked data from ransomware incidents frequently includes personal information, financial records, and internal communications, all of which can fuel identity theft or follow-on phishing campaigns long after the initial breach fades from headlines.

Actionable Takeaways

A few practical steps can meaningfully reduce exposure to the kind of activity described in this report:

  • Maintain offline or immutable backups that ransomware cannot reach or encrypt, and test restoration regularly.
  • Apply multi-factor authentication across email, remote access, and administrative accounts, since compromised credentials remain a common entry point.
  • Monitor for unusual account activity or data transfers, particularly around off-hours periods when intrusions are harder to detect.
  • If your organization has been named on a ransomware leak site, assume any associated personal or financial data may be exposed and take steps like credit monitoring or password resets accordingly.

Ransomware groups like The Gentlemen and Qilin are not slowing down, and the growing use of automation and AI in their operations suggests the volume of attacks could keep climbing. Staying informed about how these groups operate, and who they target, remains one of the most practical defenses available to businesses and individuals alike.