216.73.217.98

Ransomware incidents in Japan during the first half of 2025

· Published 19/08/2025 18:06 · Modified 19/08/2025 21:53

Export JSON

Essential information

Published
19/08/2025 18:06
Modified
19/08/2025 21:53
Tags
2025-08-19 double-extortion encryption japan kawa4096 kawalocker kawalocker 2.0 manufacturing ransomware salsa20 small-medium-enterprises
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 2 malware, 5 others

Description

The first half of 2025 saw a 1.4-fold increase in attacks in compared to the previous year, with 68 confirmed cases. Small and medium-sized enterprises remained the primary targets, with being the most affected industry. The group Qilin emerged as the most active threat, responsible for eight incidents. A new group, , appeared in late June, targeting Japanese companies. The analysis also details the , including its configuration, methods, and the emergence of with enhanced features. The continued evolution and intensification of activities in highlight the need for increased cybersecurity measures across various industries.

External references