Overview: Rising Ransomware Activity Targets Japanese SMEs
Ransomware incidents in Japan saw a notable increase of approximately 4.7% in the first half of 2026 compared to the same period last year, indicating that ransomware continues to pose a significant and evolving threat to organizations. Analysis by Cisco Talos reveals that small- and medium-sized enterprises (SMEs) are disproportionately affected, with organizations capitalized at less than JPY 1 billion accounting for nearly 80% of all incidents. This represents a substantial increase of 13% from 2025, underscoring a concentrated shift in attacker focus towards smaller entities.
The most active ransomware group observed in Japan during this period was The Gentlemen, followed closely by Qilin. These groups, among others, contribute to the rapid changes in the threat landscape, with many previously active groups showing reduced presence.
Technical Analysis of Active Ransomware Groups and Targeting Trends
The Gentlemen Ransomware Activity in Japan
The Gentlemen ransomware group, active since approximately July 2025, has rapidly expanded its operations, leveraging a Ransomware-as-a-Service (RaaS) model. The group employs a double-extortion strategy, encrypting victim data and threatening publication of stolen information if the ransom is not paid. Worldwide, The Gentlemen’s activity has intensified, with listings on their data leak site surging from 48 in January 2026 to 105 by July 2026, marking a 2.2-fold increase. In Japan specifically, The Gentlemen was responsible for 14 incidents during the first half of 2026. Evidence also suggests potential involvement of Russian-speaking individuals in their attacks.
Qilin Ransomware’s Use of AI for Operational Efficiency
Qilin, which recorded the second-highest number of observed incidents in Japan with seven confirmed cases, distinguishes itself by reportedly leveraging artificial intelligence (AI) to enhance the efficiency of its operations. While specific details on how AI is integrated are not provided, this development suggests a potential trend of advanced adversary tactics aimed at streamlining reconnaissance, evasion, or negotiation processes. Security professionals should be aware of this evolving capability when assessing Qilin ransomware AI operational efficiency.
Other active ransomware groups identified include SafePay, NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock.
Key Victim Demographics and Sectorial Impact
The shift in targeting towards SMEs is a critical finding. Organizations with capital under JPY 100 million accounted for 48% of incidents, and those between JPY 100 million and JPY 1 billion for 30%, cumulatively comprising 78% of all victims. This trend emphasizes that smaller organizations, often with fewer cybersecurity resources, are increasingly perceived as lucrative targets by ransomware operators.
Sector-wise, manufacturing continued to be the most affected industry, accounting for 34% of incidents. This was followed by the information and communications sector at 11% and the services sector at 9%. Additionally, 13.3% of incidents involved overseas offices or subsidiaries of Japanese companies, with Taiwan, the United States, and the Philippines being the most impacted foreign locations. The average monthly incident rate was approximately 13, peaking at 19 incidents in April. This data highlights the widespread impact and the international reach of these ransomware campaigns.
Actionable Recommendations and Mitigations for SME Ransomware Protection Japan
Given the heightened activity of groups like The Gentlemen and Qilin, and their focus on SMEs, organizations must prioritize comprehensive ransomware defenses:
- Implement a 3-2-1 Backup Strategy: Regularly back up all critical data to isolated, offline locations. This is fundamental for recovery without paying a ransom.
- Patch and Update Systems Promptly: Ensure all operating systems, applications, and network devices are kept up-to-date with the latest security patches to close known vulnerabilities.
- Enhance Endpoint Detection and Response (EDR): Deploy and configure EDR solutions to monitor for suspicious activity, detect early signs of compromise, and prevent ransomware execution.
- Strengthen Email and Web Security: Implement advanced email filtering and web gateways to block phishing attempts and malicious downloads, which are common initial access vectors for ransomware.
- Conduct Regular Security Awareness Training: Educate employees about common social engineering tactics, identifying phishing emails, and the dangers of suspicious links or attachments. This reduces the risk of initial infection.
- Implement Network Segmentation: Divide networks into smaller, isolated segments to limit the lateral movement of ransomware in the event of a breach.
- Develop and Test an Incident Response Plan: Have a clear, well-rehearsed plan for responding to a ransomware attack, including containment, eradication, recovery, and post-incident analysis.
- Review and Harden Remote Access Services: Securely configure remote desktop protocol (RDP) and VPNs with strong authentication, including multi-factor authentication (MFA), and monitor for brute-force attempts.
By focusing on these proactive measures, organizations, particularly SMEs in Japan, can significantly improve their resilience against evolving ransomware threats.
Related: PAN-OS GlobalProtect Authentication Bypass Exploited by Qilin, Ransomware Attack Freezes Japanese Food Supply Chain Operations