[Incident] Major Japanese Cloud Provider IDC Frontier Hit by Ransomware: East-1 Wiped
Grab your popcorn 🍿 — we have an absolute textbook cloud disaster unfolding in Japan right now.
Over the past few days, IDC Frontier (IDCF Cloud) — a prominent Japanese enterprise cloud provider (SoftBank group affiliate) — went from claiming "routine physical hardware issues" to having their flagship Tokyo availability zones completely nuked by ransomware, dragging the entire platform down with them.
Here is a full breakdown and timeline of what happened based on their official customer incident reports.
TL;DR
- The Setup (Oct 2–6): Management portal starts glitching (DNS, DB provisioning, Red Hat repos down). IDCF sends 4 updates insisting: "This is strictly physical hardware failure on management infra, definitely NOT a cyberattack". ETA given: Oct 7, 09:00 AM.
- The Crash (Oct 7, 03:40 AM): Instead of recovery, the entire East Japan Region 1 (
tesla,henry,pascal,joulezones) drops offline simultaneously. VMs across all four zones power off. - The Admission (Oct 7, afternoon): IDCF confirms they were hit by ransomware. Management infra automatically shut down hosts.
- The Death Sentence (Oct 7, evening): Official notice admits East-1 VMs and cloud-side snapshots are virtually unrecoverable and cannot be extracted. Customers are told to restore elsewhere using their own offline backups — and IDCF explicitly warns: "Do NOT rebuild in our other regions for now".
- The Panic Button: To stop lateral spread, IDCF shut down the web console and API across the entire platform (East-2/3, West Japan). Running VMs in other regions are now unmanageable black boxes; automated snapshots, Veeam backups, and DB failovers are completely dead.
- Current Status (Oct 9): Tokyo Metropolitan Police Department (Keishicho) is officially on site. Ticket portal is down (emergency email queue backed up). IDCF is urging all users to reset passwords if reused elsewhere.
Incident Timeline
Act 1: The "Hardware Glitch" (Ticket: SC20261002_0002)
- Oct 2, 01:50 JST: Red Hat repository mirror stops responding.
- Oct 3, 20:00 JST: Cloud console operations fail (DNS, RDB creation, template cloning, billing exports all error out).
- Oct 5 – Oct 6: IDCF issues Update #1 through #4. In every report, they boldly reassure customers: "This is due to hardware faults in operational infrastructure. There is NO unauthorized access, external attack, or cyberattack." Promised resolution: Oct 7, 09:00 JST.
Act 2: Black Wednesday (Ticket: SC20261007_0004)
- Oct 7, 03:40 JST: Massive outage hits East Japan Region 1 (
tesla,henry,pascal,joule). VMs across all four zones power off. - Oct 7, 04:18 – 09:36 JST (Updates 1–5): Support scrambles. The 09:00 recovery ETA silently disappears; status changes to "investigating, no ETA."
- Oct 7, 13:23 JST (Update 6): The shoe drops. Confirmed external ransomware attack. Management layer triggered automated shutdowns. IDCF isolates East-1 networks.
- Oct 7, 14:21 JST: IDCF pulls the plug on the entire cloud console/API platform-wide to contain infection.
- Oct 7, 17:13 JST (Update 7): The worst news a customer can get: Recovery of East-1 instances and storage is deemed extremely unlikely. Cloud-side volume snapshots cannot be extracted. Customers must redeploy from scratch on external infra using local backups. IDCF advises against redeploying in other IDCF regions.
- Oct 7, 17:54 JST: Non-East-1 customers are told to "prepare for the worst" and manually dump their own data from running OS instances.
Act 3: Complete Lockdown & Fallout
- Oct 8, 11:29 JST: With the ticket system dead, IDCF sets up an emergency inbox (
[email protected]) and notifies government regulatory bodies. - Oct 8, 20:59 JST: Offers temporary migration paths to isolated legacy stacks (Type S / Cloud PF Type A).
- Oct 8, 22:39 JST: Releases manual in-guest backup instructions for surviving regions. Details everything that is broken: auto-snapshots, Veeam, auto-scaling, DB backups, DNS management, ILB, and CDN config.
- Oct 9, 11:44 JST: Manual support requests completely overwhelmed. A dedicated team is formed to figure out if/how they can safely extract volume data for surviving regions.
- Oct 9, 15:23 JST (Update 12): Public advisory published. Tokyo Metropolitan Police Department (Keishicho) is brought in. Customers warned to rotate any reused console credentials immediately.
Current Damage Assessment
East Japan Region 1 (
tesla/henry/pascal/joule):- Instance Status: Completely offline / isolated
- Data & Snapshots: Effectively total loss. Platform snapshots unrecoverable
- IDCF Advice: Rebuild on third-party providers using external offline backups
All Other Regions (East-2/3, West Japan):
- Instance Status: Running blind (console and API shut down platform-wide)
- Data & Snapshots: Auto-snapshots and Veeam dead; dedicated team investigating export options
- IDCF Advice: SSH into instances immediately and take manual off-site dumps
The Big Takeaways
- Cloud provider snapshots are NOT backups: If the hypervisor control plane or storage metadata pool gets compromised or encrypted, provider-level snapshots burn down with the ship.
- Follow 3-2-1 religiously: Keep at least one independent, immutable, off-provider cold copy (S3 Glacier, Wasabi, or an off-site NAS).
- Beware of the "hardware failure" PR dance: When a provider announces that their entire control plane and image mirrors are down, yet goes out of their way to repeat "definitely not an attack" multiple times... don't wait for the next update. Start dumping your databases immediately.
Tagged:

Comments
I didn't just write this post to serve popcorn... I am literally the clown inside the circus 🤡
Yes, my own box was sitting right in the East-1
henryzone. It has been completely dead as a doornail since Wednesday morning.And like a true low-end optimist, when IDCF sent those 4 emails promising "it's just routine physical hardware maintenance, definitely NOT a cyberattack, will be fixed by 9 AM", I actually took a sip of coffee and believed them. No panic dump, no emergency off-site rsync. Just pure trust and vibes.
Fast forward to today: my instance is vaporized, platform snapshots are completely gone, and Tokyo Metropolitan Police are currently investigating the crime scene of my dead VPS.
Pour one out for my Henry node, boys. Laughing outside, crying inside.
Someone is having a really bad day.
Someone is wishing they just skipped university and worked in their dad's ramen shop.
I feel bad for them this sort out of thing is horrendous and I fear becoming more common.
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
Seppuku livestream?
export SIGNATURE="just_a_product_of_the_${ENV:-/}"