Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply
![]()

![]()
Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving malware infection in the early morning hours of Saturday, July 11. The company immediately shut down systems as an emergency measure to contain the damage. As a result, its online car hire reservation system, telephone-based taxi dispatch service, and several internal systems are currently unavailable.
The company’s public notice was direct about the sequence of events.
“We have recently discovered that our internal systems were subjected to unauthorized external access (malware infection). We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved.” reads the company’s notice. “Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage. As a result, our hire car web order and reservation management system, telephone-based taxi dispatch service, and some internal systems are currently temporarily unavailable.”
The company took systems offline to contain the threat, but it caused operational disruption.
With the telephone dispatch service down, customers who need a Nihon Kotsu taxi are being directed to use the GO taxi app and select Nihon Kotsu as the company when requesting a ride, or to find a nearby taxi stand or flag one down on the street. It’s a significant operational gap for a company that runs one of Tokyo’s most recognizable fleets, but the manual workaround is functional. The hire car reservation system, which handles advance bookings, remains offline.
Nihon Kotsu confirmed it’s working with external security experts to determine the scope of the securty incident, identify the cause, and analyze logs. The internal network has been isolated to prevent further spread. On the question of personal data exposure, the company said: “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law.”
That’s a carefully worded statement: confirmed is doing real work there, and the investigation is still open.
Nihon Kotsu said no data leak has been confirmed. If the investigation finds customer data was exposed, it will notify affected individuals and publicly disclose the incident as required by Japan’s Act on the Protection of Personal Information.
The Japanese firm is prioritizing secure system recovery and will provide updates as the investigation progresses. The company also warned customers to ignore suspicious emails or messages impersonating the firm.
“We are prioritizing the security of our system and the recovery process in a safe environment. We will publish updates on the investigation and recovery status on this website as soon as they become available.” concludes the notice. “Please be careful not to open any attachments or click on any links if you receive any suspicious emails or communications impersonating our company.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)

![]()
Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic.
Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas operations, or third-party infrastructure.
The affected organizations include Aflac Japan, KDDI, Sapporo Holdings, and Nidec, each of which reported separate cyber incidents during the second half of June 2026. Although the attacks involved different circumstances, the disclosures point to an expanding attack surface that extends well beyond an organization's primary network.
Aflac Japan disclosed on June 30 that attackers accessed its Japanese operations between June 15 and June 25. According to the company, approximately 4.38 million customers and agents were affected, with a subset of records including bank account information used for insurance premium payments.
The insurer stated that the incident was limited to its Japanese business and did not affect its U.S. operations.
While the company has not attributed the attack to any specific threat group, the reported tactics resemble social engineering techniques previously associated with Scattered Spider.
Telecommunications provider KDDI reported unauthorized access involving an email platform used by multiple Japanese internet service providers.
The company said the incident stemmed from a vulnerability in third-party software, potentially exposing up to 14.22 million email account records across six ISPs.
The breach demonstrates how a single vulnerability within shared infrastructure can affect multiple organizations simultaneously.
Sapporo Holdings disclosed suspected unauthorized access involving two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman. The company detected suspicious activity, shut down affected systems, and launched an investigation to determine whether any information had been accessed or stolen.
Meanwhile, manufacturing company Nidec confirmed a ransomware attack targeting its Taiwanese subsidiary, Nidec Chaun Choung Technology.
The BlackField ransomware group claimed responsibility for the attack, alleging it had stolen more than two terabytes of company data, including employee, financial, procurement, manufacturing, legal, and IT records. The group reportedly demanded a $2 million ransom.
Despite involving different industries and attack methods, the four Japan cyberattacks reveal a similar point of compromise.
Aflac's breach was limited to its Japanese business. KDDI's exposure originated from a shared email platform relying on vulnerable third-party software. Sapporo's investigation centers on overseas subsidiaries, while Nidec's ransomware incident affected its Taiwan-based operation rather than its headquarters.
These cases suggest attackers are increasingly targeting subsidiaries, shared services, overseas business units, and technology partners instead of attempting to breach an organization's primary corporate network.
The incidents highlight the importance of treating subsidiaries and external partners as part of the organization's overall security perimeter.
Organizations that rely on overseas offices, acquired businesses, vendors, or shared platforms may inherit additional cybersecurity risks if those environments are not protected to the same standard as corporate headquarters.
The KDDI incident illustrates how third-party dependencies can significantly increase the scale of a breach, while the Nidec cyberattack demonstrates how ransomware groups continue to combine data theft with extortion demands.
The reported tactics observed in the Aflac incident also reinforce the continued effectiveness of social engineering as an initial access method.
While investigations into several of the incidents remain ongoing, the recent disclosures underscore a broader trend. As enterprise environments become increasingly interconnected, subsidiaries, shared infrastructure, and external technology providers are becoming attractive targets for attackers seeking indirect access to larger organizations.
Aflac says a data breach in Japan may affect 4.38 million customers and agents, exposing personal, policy, and some banking information.
The post Aflac Data Breach: Over 4M Customers in Japan May Be at Risk appeared first on TechRepublic.
Microsoft and Trend Micro found hotel phishing attacks using fake guest complaints and photo links to target staff in Japan.
The post Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan appeared first on TechRepublic.
Japan’s election last month and the rise of the country’s newest and most innovative political party, Team Mirai, illustrates the viability of a different way to do politics.
In this model, technology is used to make democratic processes stronger, instead of undermining them. It is harnessed to root out corruption, instead of serving as a cash cow for campaign donations.
Imagine an election where every voter has the opportunity to opine directly to politicians on precisely the issues they care about. They’re not expected to spend hours becoming policy experts. Instead, an ...
The post Team Mirai and Democracy appeared first on Security Boulevard.