As cited
Copy frozen at (site build).
ransomware
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ransomware incidents in Japan grew 4.7% in the first half of 2026, with The Gentlemen emerging as the most active group and nearly doubling their leak site listings from 48 in January to 105 in July. Investigation of The Gentlemen's infrastructure revealed a multi-phase attack workflow targeting small and medium-sized enterprises through vulnerable VPNs, unpatched systems, and credential abuse, with evidence suggesting Russian-speaking threat actors. Qilin, the second most active group, deployed artificial intelligence (AI) to automate ransomware distribution and backup destruction across compromised networks.
Why it matters: Organizations in Japan with capital under JPY 1 billion are 80% of victims and must prioritize patching internet-facing VPNs and remote access systems, enforcing multifactor authentication (MFA), and monitoring for suspicious logins and lateral movement; practitioners should implement endpoint detection and response (EDR) monitoring for backup disabling and large-scale file modifications to detect attacks early.
- Source published
- First seen by Cybersecurity Tracker